Nothing beats manual verification. People aren't sharing credit card numbers on public forums and mashing them against Stripe. People are paying for fulls, and grabbing a socks5 that's piped within a few miles of the address of the cardholder.
Never trust your processor to protect you against your (potential) customers. Stripe has very little incentive to do so. They'd rather you pay that fat $15 fee when you get hit with a chargeback. They really would.
I'm coming out with a book about Stripe (and a few other processors) and fraud. Trust me it will be good, and this is already a part of it.
Sincerely,
Someone who was once your enemy
PS my favorite part of this? Telling the carder how to defeat their algos:
* "This card has been used from an unusually large number of IP addresses across the Stripe network over the last 24 hours."
* "This email has been linked to an unusually large number of cards across the Stripe network over the last hour."
Thanks for not saying the card was declined. If you wouldn't mind, please hold while I switch socks and make a new email.
Sorry if this is crass, but whoever decided on telling the end-user why a card was declined... complete fucking idiot and should never work in fraud protection or payment processing again.