Merchant Fraud Guide Sections

CVV Check Failed: What It Means

A failed CVV check is a warning sign, not a verdict. Here is how to read it and what to do next.

The order lands. The amount is normal. The basket looks fine. Then the payment result says the CVV check failed.

What the code actually is

The CVC, also called CVV, is the three- or four-digit number printed directly on a card. The check asks the card issuer to confirm that the shopper typed in the number that is printed on the physical card.

The point is simple. Someone who only has a stolen card number, without the card itself, should not know this code.

What a failed CVV check means

A failed check is a signal, not a verdict. Stripe's documentation says a failed CVC or postal code check can indicate the payment is fraudulent. Indicate, not prove.

Treat it as one data point on the order. A fraudster can fail it. So will some honest shoppers, for reasons below. Weigh it against the other details on the order before you make a call.

Why good payments fail it

The check has limits. A shopper can mistype the code.

There is a bigger gap too. Stripe's documentation says CVC verification does not protect against the physical theft of a card. If someone steals the card itself, they have the code printed on it. The check will pass, and the payment is still fraud.

So a pass is not a promise, and a fail is not a confession. The same is true of the address check. Stripe's documentation says AVS checks can fail for legitimate payments. That is why an avs mismatch on a legitimate order is worth planning for.

What to do when you see one

Do not cancel on this signal alone. Put it next to the rest of the order.

Shopify's guide says fraud indicators can include AVS checks and the correct CVV code. That word, indicators, is the right one. Each one is a clue. A pile of them pointing the same way is a reason to hold the order and look closer.

One failed check on an otherwise clean order is usually a reason to review, not to refund and run.

Blocking failed verifications automatically

You can make the call automatic. Stripe's documentation says Radar allows you to block payments that fail the card issuer verification by enabling a rule through the Dashboard.

This is a blunt tool. It will also block the honest shopper who mistyped. Some stores accept that trade. Others let the payment through and review it by hand. Both are fair choices if you make them on purpose and stick to them.

CVV versus AVS

The two checks look at different things. The CVV check looks at the code printed on the card. The address check confirms the billing address matches what the issuer has on file.

Adyen's docs say AVS is a widely used fraud-prevention measure for card not present transactions, such as online payments. Stripe's documentation says most cards issued in the United States, Canada, and the United Kingdom support street address verification. Coverage depends on where the card comes from.

An avs mismatch can happen for reasons that have nothing to do with fraud, so read both results, not just one.

What to collect, and what not to store

You cannot keep these codes for later. Stripe's documentation says businesses can't store the CVC number.

What you can do is collect it fresh every time. Stripe's documentation says to collect the CVC, postal code, and billing address for every payment. That gives the checks something to compare on every order, not just some of them.

The CVV and AVS checks are not the only signals at checkout. A shopper can also be sent through 3-D Secure. When that step goes wrong, you get a 3d secure authentication failed result, which is its own signal with its own meaning.

The address check also returns specific results, not just pass or fail. Learning to read avs response codes tells you how much of the address matched, which is more useful than a single yes or no.

None of these checks is a wall. Each one is a question the issuer answers. Your job is to ask enough of them, and to read the answers together.

Sources

The rest of AVS and CVV checks