What is the best setup for MaxMind ?
I'm sure the setup is not "best" but it has only let past a couple of problematic customers so far and each of them was only problematic in _what_ he does, not fraudulent payment. If you want to check the "what" too use FraudRecord (but not automatically, it will give too many false positives!)
I can share my current settings for Maxmind though:
- license: standard (configured/paid with Maxmind directly)
- don't verify returning (Disable if you have many customers who get their account hacked and then abused to order fraud sites)
- Don't verify admin order
- Auto-block fraudulent IP
- Reject anonymous proxy
- Maxmind fraud risk to accept: 40%
Other options like "high-risk countries" depends a lot on your business orientation. If you are oriented towards a national service, enable it unless you live in risky countries yourself. Otherwise leave disabled, if a region is considered high-risk it will increase the risk score anyway.
How about Maxmind Phone type checker ?
Every "hassle" you add to a customer will result in about 50% less convenience leads (from ads, search engines, ...). I'm not using it and running fine currently.
Also is anyone using hostbill sms verification plugin ?
See above - it's a hassle. I did use it in a different project a few years ago and it worked rather well if you use a reliable sms provider. BulkSMS standard route is good enough for such services in most countries, but the sms-loss of cheap ( 0.00X Cent/sms) providers such as Dellmont/Betamax is too high for such services.
Note that you can set MaxMInd risk even lower (e.g. 30%) and then manually verify each medium-risk case manually as you'll get a notification.