
An AVS mismatch means the billing address a customer typed at checkout doesn't match the address the card issuer has on file. The Address Verification Service compares the numbers in the street address and the ZIP code and sends back a one-letter result code. A mismatch is not a decline by the bank: the issuer approves or declines the sale separately, and your payment gateway's AVS settings decide whether a mismatched order goes through.
What Does AVS Mismatch Mean?
Visa defines the Address Verification Service as a service through which a merchant verifies a cardholder's billing address. The request carries the street address, the ZIP code, or both, and it can ride along with an authorization or be sent on its own as a zero-amount account verification.
"AVS mismatch" is the everyday name for any result other than a full match: street only, ZIP only, or nothing.
What does AVS actually check?
Mostly numbers. Processor TabaPay's developer documentation says only the numerical portion of the address is verified, typically the street number and the ZIP code. A misspelled street name usually won't cause a mismatch. A wrong house number or ZIP will.
Some issuers check only the ZIP. Visa's current rules require US issuers to verify the postal code and say they "may optionally verify street address."
Is AVS only for online orders?
Yes, with one exception. Visa's rules let merchants use AVS on transactions in the card-absent environment: online orders, phone orders and mail orders. It's a core card-not-present fraud tool. The US exception is unattended terminals at fuel pumps (MCC 5542) and commuter and passenger rail (MCC 4111 and 4112), which is why a gas pump asks for your ZIP code.
AVS Response Codes and What They Mean
AVS code sets differ by network and by gateway. The table below follows the AVS result code list Visa publishes in its merchant guide "Visa Payment Acceptance for U.S. Quick-Service Restaurants" (2017). Visa notes that your acquirer may relabel the letters, for example showing a Y as "exact match."
| Code | Visa's definition, shortened | Group |
| Y | Street address and ZIP code match (domestic) | Full match |
| D or M | Street address and postal code match (international) | Full match |
| F | Street address and postal code match (UK only) | Full match |
| A | Street address matches, ZIP code does not | Partial match |
| Z | ZIP matches; street doesn't match or wasn't sent | Partial match |
| B | Street matches; postal code not verified (incompatible formats) | Partial match |
| P | Postal code matches; street not verified (incompatible formats) | Partial match |
| N | No match | No match |
| R | Retry: the issuer's system was unavailable or timed out | Unavailable |
| U | Not verified, domestic: issuer doesn't take part in AVS, returned no result, or has no address on file | Unavailable |
| G | Not verified, international: same reasons as U | Unavailable |
| C | Street and postal code not verified (incompatible formats) | Unavailable |
| I | Address information not verified | Unavailable |
Issuers can also send S, W and X, but Visa converts those to U or G, Z and Y before the response reaches you.
Why your gateway's AVS codes may not match this table
In Authorize.Net's list, for example, B means address information wasn't submitted, E means the AVS data was invalid or AVS isn't allowed for the card type, S means the US issuer doesn't support AVS, and W means the 9-digit ZIP matched but the street didn't. Adyen translates raw results into its own numbered codes. Read your own gateway's list before writing a filter rule.
Worked example: one address, four AVS results
A fictional customer, Dana, has a US-issued Visa card. Her issuer has her billing address as 1450 Oak Street, Apt 3B, Dallas, TX 75201. The merchant sends both street and ZIP. The codes below are what Visa's definitions predict; the issuer returns the actual letter.
| What Dana types at checkout | Numbers compared | Visa AVS result |
| 1450 Oak St, Apt 3B, 75201 | 1450 matches, 75201 matches | Y (full match) |
| 1450 Oak Street, 75210 (ZIP typo) | 1450 matches, 75210 doesn't | A (street only) |
| 1540 Oak Street, 75201 (digits swapped) | 1540 doesn't match, 75201 matches | Z (ZIP only) |
| 300 Main Street, 75202 (her office, the shipping address) | Neither matches | N (no match) |
If her issuer's system times out, she gets R. If the issuer returns no result, U.
"St" didn't matter in the first row because the street name isn't compared. How issuers handle the "3B" unit number isn't spelled out in the network documents we reviewed. Adyen tells merchants to send the unit as part of the street line, so keep it there rather than dropping it into a separate field your gateway may ignore.
Is an AVS Mismatch the Same as a Decline?
No. Visa's merchant guide says the issuer makes its authorization decision separately from the AVS check and returns both: an approval or decline, plus the one-letter AVS result. Visa also says the authorization response always takes precedence over AVS, and you should never accept a declined transaction because the address matched.
The reverse happens all the time. Authorize.Net states that a card can be authorized at the issuing bank and then declined by the merchant's AVS settings. The sale won't settle and the customer isn't charged, but the approval can still leave a hold on the card. When a shopper sees "AVS mismatch," it usually means the merchant's gateway rule rejected an order the bank would have approved.
Stripe notes that AVS checks can fail for legitimate payments, such as a customer who mistyped the address or moved. For the codes that do come from the issuer, see our guide to credit card decline codes.
Saw "AVS Mismatch" as a Customer?
If a store declined your card with this message, the address you entered didn't match the billing address your card issuer has on file. The usual causes:
- You moved and haven't updated the address with your bank.
- You typed the shipping address, or a work address, in the billing fields.
- A typo in the house number or ZIP code.
- A prepaid or gift card with no address registered. GiftCards.com, Blackhawk Network's gift card site, says registering a Visa gift card links a name and billing address to it and matters if you plan to shop online, because sites look for an AVS match. Register the card at the website printed on its back, then enter that exact address at checkout.
Seeing a pending charge? The bank may have approved the purchase and placed a hold even though the store rejected it. Authorize.Net says most issuers remove unclaimed authorizations within 3 to 7 days. The store can ask your bank to release it sooner, but the bank decides. The rest of this guide is written for merchants.
How to Set Your Gateway's AVS Filter
Most gateways let you choose what happens for each code. Authorize.Net, for example, offers four actions for AVS results: allow, process and report the triggered filter, authorize and hold for review, or decline. Its default settings reject B, E, G, N, R, S and U. Stripe's Radar can block payments that fail the postal code check.
Visa doesn't prescribe a policy; its guide says to weigh the AVS code against everything else about the order. A sensible starting point for a US payment gateway:
- Collect and send both street and ZIP. A ZIP-only request can't catch a wrong street number. Visa's guide says that unless you sent only a ZIP and it matched, you may want to follow up on a Z before shipping.
- Decline or review N. Visa's guide says no-match responses generally lead to further merchant investigation.
- Review A and Z instead of auto-declining. Visa lists an out-of-date issuer file, a typing error and fraud as possible causes.
- Treat R and U differently from N. R means the issuer's system didn't answer. Visa's guide suggests a zero-amount account verification when you get a "try again later" response.
- Decide deliberately about G. Authorize.Net's default rejects G, which turns away cards from issuers that return no AVS result for international transactions. If you sell abroad, look at the next section before keeping that default.
- Never fill the billing fields yourself. Effective July 25, 2026, Visa requires acquirers to ensure AVS data is genuine cardholder address data the merchant got directly from the cardholder. Don't copy the shipping address or a placeholder into them.
If your ecommerce processing provider set up your gateway, ask which codes it declines by default.
Worked example: what a strict AVS filter costs
This example is hypothetical. Every number in it is an assumption chosen to show the arithmetic.
An online store takes 2,000 orders a month at an average of $80. Say 6% come back with A, Z or N, which is 2,000 x 0.06 = 120 orders, and 10 of those 120 are fraud.
- Strict rule, decline A, Z and N: stops all 10 fraudulent orders, worth 10 x $80 = $800. It also turns away 110 real customers, worth 110 x $80 = $8,800 in sales.
- Middle rule, decline N and review A and Z: say 40 of the 120 are N, including 7 of the fraud orders. Declining them stops 7 x $80 = $560 in fraud and loses 33 good orders. Staff review the other 80 orders and catch the remaining 3 fraudulent ones, if the review works.
At a 40% gross margin, the strict rule gives up $8,800 x 0.40 = $3,520 in profit to avoid $800 of fraudulent orders and the chargebacks that would follow. Pull a month of AVS results from your gateway and run the same math before tightening anything.
AVS vs CVV2: What's the Difference?
AVS and CVV2 answer different questions, and card-not-present merchants usually use both.
| AVS | CVV2 | |
| What it checks | Numbers in the billing address and ZIP | The 3- or 4-digit code printed on the card |
| What a match suggests | The buyer knows the cardholder's address | The buyer has the card details, not just the number |
| Can the issuer decline on it? | The issuer decides the authorization separately | Visa's decline codes include N7, "Decline for CVV2 failure" |
| Keeping it | Save the result code as dispute evidence | Stripe notes businesses can't store the CVC |
A stolen card with its address attached passes AVS; a card number without the code fails CVV2. Use both.
Does an AVS Match Protect You From Chargebacks?
Not automatically. A full match is evidence, not a guarantee. Under Visa's rules (April 2026 edition):
- Y or M plus delivery to that address is compelling evidence. For a card-absent fraud dispute (Dispute Condition 10.4), proof that the goods went to the same physical address that got an AVS match of Y or M is allowable compelling evidence at pre-arbitration. The issuer then has to explain why its system returned the Y.
- A U can make the fraud dispute invalid. For a domestic transaction in the US or Canada where the acquirer attempted AVS and got U because the issuer wasn't taking part, a 10.4 dispute is invalid. That doesn't apply if the issuer was simply unable to respond.
- A mismatch you accepted is your call. Visa's 2017 guide warned that for an international address returning G, you're liable for chargebacks if you accept the sale, even if the issuer approved it.
Authorize.Net says AVS isn't meant to be absolute protection. For the full card-not-present defense stack, including 3-D Secure, see our fraud prevention guide, and if a dispute does land, how to win a chargeback.
AVS on International Cards
Coverage is wider than it used to be. Visa's 2017 merchant guide said AVS could only confirm addresses in the US and Canada. Visa's April 2026 rules extend issuer AVS participation and postal-code checks to Europe, Australia, New Zealand and Singapore, with Argentina, Brazil, Mexico, Paraguay, Peru, Puerto Rico and Uruguay phased in on later effective dates. Visa's own summary and rule text list different start dates for some of those countries, so ask your processor what applies before relying on AVS for a foreign card.
Stripe says most cards issued in the US, Canada and the UK support street address verification, and some countries don't use postal codes at all. On foreign cards, expect more G, B, P and C results, and don't treat them as N.
What to Do When a Good Customer Gets an AVS Mismatch
A repeat customer's order failed with an AVS mismatch, and her bank shows a pending charge.
- Check the authorization result, not just the AVS code. If the issuer approved and your gateway declined, there's a live hold on her card.
- Void it. Visa requires merchants to reverse an approved authorization within 24 hours when the sale isn't completed. A void or reversal tells the issuer to release the hold. Otherwise the hold sits until the issuer drops it, 3 to 7 days at most banks according to Authorize.Net. Our guide to the authorization hold covers reversals in detail.
- Ask for the billing address exactly as it appears on her card statement. Not the shipping address.
- Don't let her retry five times. Each attempt the issuer approves and your filter rejects can leave another hold. Check the address with a zero-amount account verification first, which Visa's guide describes as an AVS request sent without an authorization.
- If you override the filter, keep the record. Save the AVS and CVV2 results, and ship to the billing address when you can. That's what builds the Y-or-M delivery evidence described above.
This is general information, not legal advice. Card network rules change, and your acquirer's agreement may add requirements on top of them.
If AVS-related declines are costing you orders, or you're not sure what your gateway is filtering, send us a recent statement for a free statement review.
Sources
- Visa, "Visa Core Rules and Visa Product and Service Rules," 18 April 2026 edition (sections 5.7.3.6, 7.3.10.2, 10.11.1, 11.5.1 and 11.7.5.3; Table 11-6; Address Verification Service glossary entry), observed September 2026.
- Visa, "Visa Payment Acceptance for U.S. Quick-Service Restaurants" (2017), Billing Address Verification with AVS and Address Verification Result Codes, observed September 2026.
- Authorize.Net, "Address Verification Service (AVS)" Merchant Interface help.htm), observed September 2026.
- Authorize.Net, "Enhanced AVS Handling Filter", observed September 2026.
- Authorize.Net Support Center, "What is Address Verification Service (AVS) and how to use and configure it?", observed September 2026.
- Authorize.Net Support Center, "Why was my customer charged even though the transaction declined?", observed September 2026.
- Stripe, "Card verification checks", observed September 2026.
- Adyen, "Address Verification System (AVS)", observed September 2026.
- TabaPay Developers, "Address Verification Service (AVS)", observed September 2026.
- GiftCards.com, "How to Use Visa Gift Cards Online", observed September 2026.
Frequently Asked Questions
What does AVS mismatch mean?
It means the billing address entered at checkout didn't match the address the card issuer has on file. The Address Verification Service compares the street number and ZIP code and returns a one-letter code. A mismatch is not a bank decline; the merchant's gateway settings decide whether to accept the order.
Why does my gift card say AVS mismatch?
Prepaid and gift cards often have no billing address registered, so there is nothing for the address check to match. Register the card at the website on its back, add your name and address, then enter that exact address at checkout.
What is the difference between AVS code A and Z?
Under Visa's AVS codes, A means the street address matched but the ZIP code did not. Z means the ZIP code matched but the street address did not, or no street address was sent. Both are partial matches that many merchants review rather than decline automatically.
Will an AVS mismatch still put a hold on the customer's card?
It can. The issuer may approve the authorization even though the merchant's AVS filter rejects the order, which leaves a hold. Visa requires the merchant to reverse an approved authorization within 24 hours when the sale isn't completed; otherwise the hold stays until the issuer releases it.
Does a full AVS match protect me from fraud chargebacks?
No. Under Visa's rules, delivery to an address that returned a Y or M match counts as compelling evidence in a card-absent fraud dispute, but it doesn't make the dispute invalid on its own. Treat a match as evidence, not a guarantee.
About Payment USAโs Founder
Published by Payment USA, a merchant services provider. Our guides and comparisons reflect that commercial perspective.

Chase James
CEO, Payment USA
Chase James is the founder and CEO of Payment USA, a merchant services company built on transparency and fair pricing. With over 15 years in the payments industry, Chase has helped thousands of businesses uncover hidden processing fees and switch to honest, interchange-plus pricing.
Contact Chase โ