What a state-restriction block page should actually say
If you block orders to certain jurisdictions, and you should be enforcing that at checkout rather than describing it in a policy page nobody reads, then somebody is going to hit that block. What they see next is a piece of writing most operators never think about.
It is usually terrible. A red error box, a generic “we cannot ship to your location,” and a dead end. The customer has no idea whether they did something wrong, whether the site is broken, or whether they have been accused of something.
This page is worth ten minutes of real attention, for two reasons: it is the only compliance control your customer actually experiences, and it is doing the work at the exact moment they are most likely to conclude you are amateurish.
An important caveat before the copy
This article is about what the page should say. It is deliberately not about which jurisdictions to block.
That list is a legal question, not a product decision, and it moves with every legislative session. The nature of each restriction differs too: a minor-sale restriction is not the same thing as a parental-consent requirement, which is not the same thing as a broader prohibition, and treating them identically produces both over-blocking and under-blocking.
Get the list from qualified counsel, review it on a schedule, and build the page so the list is configuration rather than something baked into the copy. A static rule set written once is the failure mode here.
Five things the page has to do
1. Say what happened, plainly
The reader's first question is whether they broke something. Answer it immediately and in ordinary language. Something in the shape of: we are not able to ship this product to addresses in your state.
Not “transaction declined.” Not an error code. Not a wall of legal citation.
2. Make clear it is not about them
This is the difference between a block page that reads as competent and one that reads as an accusation. The restriction is about where the order is going, not about who is ordering.
One sentence does it: this is based on where the order would ship, not on anything about your account. People are surprisingly rattled by being blocked, and a business that anticipated their reaction reads as a business that knows what it is doing.
3. Explain, briefly, without lecturing
A short clause on why is enough: state requirements for products in this category differ, and you follow them. One sentence. The temptation is to write three paragraphs justifying yourself, which converts a moment of friction into a moment of defensiveness.
What you should not do is imply the customer could get around it. No hints about shipping to a different address, nothing about a friend in another state, no wink. That is not customer service, it is documented evidence that you help people circumvent your own controls.
4. Give them somewhere to go
A dead end is a wasted moment. The page can reasonably offer:
- Products that are not restricted, if some are not
- A way to be notified if the position changes
- A route to support for a genuine mistake, such as a mis-detected location or a wrongly saved address
That last one matters more than it looks. Geolocation is imperfect, and a customer legitimately in an unrestricted state should not be permanently stuck behind a wall with no human to talk to.
5. Look like the rest of your site
An unstyled browser-default error page after a well-designed storefront tells the customer the compliance layer was bolted on by someone else. Same typography, same header, same tone. It should feel like a page you wrote, because you did.
A worked example
Roughly this shape:
We can't ship this order to your state.
Requirements for products in this category vary by state, and we follow them, so we're not able to deliver this item to a [State] address.
This is about the shipping destination, not about you or your account.
If your address is set incorrectly, or you think this is a mistake, contact us and we'll sort it out.
Short. Not defensive. No accusation, no legal citation, and no suggestion that there is a way around it.
The part behind the page
Two operational notes that matter as much as the wording.
Enforce at checkout, not in a policy page. A restriction stated in your terms and not enforced in the cart is not a control. It is a paragraph. Processors and regulators both look for the behaviour, not the promise.
Log the block. Record that the check ran and what it decided, as part of the same per-order audit trail that carries your research-use acknowledgment and age verification. A control you cannot evidence is very close to a control you do not have, and the log is the artifact that demonstrates the rule was applied consistently rather than when convenient.
Done properly, the block page stops being an apology for a limitation and becomes a small, visible piece of evidence that the operation is run by adults. In this category, that is not a bad thing for a customer to conclude at checkout.
The controls underwriters check
Restricted-jurisdiction blocking enforced at checkout is on the list, alongside the rest of the storefront controls that decide a merchant application.
Get the Payment-Approval Checklist (PDF) →Keep reading
→ Research-use-only compliance basics → The three things that trigger an FDA warning letter → The five-element COA every research buyer checks → What your processor needs before they will approve youThis guide is general information, not legal advice, and deliberately does not identify which jurisdictions to restrict. Applicable state requirements differ in kind and change frequently; determine your blocking rules with qualified counsel and review them on a regular schedule. The example copy is illustrative and should be reviewed before use.