Address Verification Systems
Last updated July 28, 2026 with current fraud and false decline data, refreshed sources, and updated Wyllo links.
An address verification system (AVS) is a service from the major card networks that compares the billing address a customer enters at checkout against the address on file with their card issuer. It was originally developed by Mastercard to combat rising card-not-present fraud, and the other major card networks have since adopted the address validation process. AVS became one of the most commonly used fraud checks in ecommerce, and it still plays a role today. But as fraud has grown more sophisticated, AVS on its own does not effectively prevent fraud, though it can block revenue from legitimate customers. Juniper Research projects that fraudulent ecommerce transactions will grow from $56 billion in 2025 to more than $131 billion by 2030, which is a strong signal that a single address check was never going to carry the load alone.
What Are Address Verification Systems?
An address verification system (AVS) is a service offered by major credit card processors to help merchants verify a customer’s credit or debit card ownership. The AVS check runs when a merchant requests authorization for a card-not-present transaction. The credit card company or bank automatically compares the billing address provided by the customer to the billing address in its records and reports the result to the merchant. The ultimate responsibility for deciding whether to proceed with the transaction lies with the merchant. AVS is typically used alongside other card security features, such as the CVV2 number, for verification.
How Address Verification Systems Work
AVS helps reduce the risk of fraudulent transactions by comparing the address information provided by the customer with the address on file with the credit card issuer or the bank. Here’s how AVS typically works:
- Customer input: During an online transaction, a customer enters their billing address as part of the payment process. This includes the street address, city, state or province, and postal/ZIP code.
- Verification request: The merchant’s payment processing system sends the provided address information to the cardholder’s issuing bank or payment processor, along with the transaction details.
- Address comparison: The card issuer or payment processor checks the provided address against the address on file for the cardholder’s account.
- Response: The issuer or processor sends a response code back to the merchant, indicating whether the provided address matches the one on file.
The response codes can vary, but they typically fall into one of several categories:
- Match: The provided address matches the address on file. This is a positive result.
- Partial match: Some part of the provided address matches the address on file, but not all. This result may still be acceptable, depending on the merchant’s policies.
- No match: The provided address does not match the address on file. This could be due to a typographical error, fraud, or a legitimate change of address.
Merchants can use these response codes to decide whether to proceed with a transaction or take additional precautions, such as contacting the customer for further verification. AVS is one layer of a fraud program, and it works best in conjunction with other signals like CVV (Card Verification Value) checks and broader risk intelligence.
Keep in mind that AVS primarily verifies the billing address associated with a credit card, and it may not verify the shipping address. Merchants should use additional verification signals to ensure both billing and shipping addresses are accurate and legitimate, especially for high-value transactions.
Address Verification System Response Codes
AVS response codes are single-letter codes that follow a request from a merchant for address verification. The meaning of the codes varies between credit card processors. These codes indicate the degree of address matching during the authorization process and help determine the next action, either an approval or a decline on the transaction.
| Code | Visa | Mastercard | Discover | American Express |
|---|---|---|---|---|
| A | Street address matches, ZIP does not | Street address matches, ZIP does not | Street address matches, ZIP does not | Street address matches, ZIP does not |
| B | Street address matches, but ZIP not verified. | Not applicable | Not applicable | Not applicable |
| C | Street address and ZIP not verified | Not applicable | Not applicable | Not applicable |
| D | Street address and ZIP match (International Only) | Not applicable | Not applicable | Not applicable |
| E | AVS data is invalid or AVS is not allowed for this card type. | Not applicable | Not applicable | Not applicable |
| F | Street address and postal code match (UK Only) | Not applicable | Not applicable | Street address matches, card member name does not match |
| G | Non-U.S. issuing bank does not support AVS. | Not applicable | Not applicable | Not applicable |
| I | Address information not verified for international transaction | Not applicable | Not applicable | Not applicable |
| K | Not applicable | Not applicable | Not applicable | Card member name matches |
| L | Not applicable | Not applicable | Not applicable | Card member name and ZIP match |
| M | Street address and postal code match (International Only) | Not applicable | Not applicable | Card member name, street address, and ZIP code match |
| N | Street address and ZIP code do not match | Street address and ZIP code do not match | Street address and ZIP code do not match | Street address and ZIP code do not match |
| O | Not applicable | Not applicable | Not applicable | Card member name and street address match |
| P | Zip code matches, street address unverifiable due to incompatible formats (International Only) | Not applicable | Not applicable | Not applicable |
| R | System unavailable, retry | System unavailable, retry | System unavailable, retry | System unavailable, retry |
| S | AVS not supported | AVS not supported | AVS not supported | AVS not supported |
| T | Not applicable | Not applicable | 9-Digit ZIP matches, street address does not | Not applicable |
| U | Address information unavailable. Returned if the U.S. bank does not support non-U.S. AVS or if the AVS in a U.S. bank is not functioning properly. | Address information unavailable | Address information unavailable | Address information unavailable |
| W | 9-Digit ZIP matches, street address does not | 9-Digit ZIP matches, street address does not | 9-Digit ZIP matches, street address does not | Card member name, ZIP, and street address do NOT match |
| X | 9-Digit ZIP and street address match | 9-Digit ZIP and street address match | 9-Digit ZIP and street address match | Not applicable |
| Y | 5-Digit ZIP and street address match | 5-Digit ZIP and street address match | 5-Digit ZIP and street address match | 5-Digit ZIP and street address match |
| Z | 5-Digit ZIP matches, street address does not | 5-Digit ZIP matches, street address does not | 5-Digit ZIP matches, street address does not | 5-Digit ZIP matches, street address does not |
AVS Fraud Prevention Limitations
It’s important to note that AVS is not universally available across all credit card providers or countries. Currently, it is available in the United States, Canada, and the United Kingdom. Typically, it’s not available for foreign credit cards, meaning those issued in a country other than where they are being used. While AVS can help verify card ownership through billing address matching, it isn’t a foolproof system and leaves plenty of room for error and the potential of false declines, which block good sales and revenue. The billing address provided by a legitimate customer may not always match the address on record at the card issuer.
Card companies may have different checks in place, but generally, AVS only verifies the numerical portions of a cardholder’s billing address. If the customer recently moved, makes a small typo like leaving off an apartment number, or the address on record is incorrect, AVS checks will return codes that might cause a merchant to reject a legitimate transaction.
Experiencing a false decline can cause a great deal of inconvenience and financial stress for legitimate customers. When a transaction is declined due to an AVS mismatch, the bank may put a hold on the authorized funds, which can remain on the customer’s card until the issuing bank allows it to expire. This is typically seven days for most businesses, except for hotels and car rental companies, which can keep the hold for up to 30 days. The held funds are subtracted from the customer’s available balance and can create chaos in their personal finances.
False declines also hurt conversion for ecommerce stores. According to Baymard Institute’s 2025 checkout research, 9% of shoppers who abandon at checkout do so because their card was declined, which adds up to significant lost revenue for merchants.
How to Prevent Address Verification System False Declines
Preventing address verification system false declines matters for both merchants and customers. PYMNTS Intelligence’s 2023 research on fraud management and false declines estimated that false declines put $157 billion in US ecommerce sales at risk in a single year, with $81 billion ultimately lost. False declines occur when a legitimate transaction is rejected due to an AVS mismatch or errors in the address verification process. To minimize false declines while maintaining security, consider the following strategies:
Use a Flexible AVS Policy
- Adjust your AVS settings to be more flexible. For example, you can consider a partial address match as acceptable, especially for online transactions where typos are common.
- Allow for variations in abbreviations (e.g., “St.” vs. “Street,” “NY” vs. “New York”) and case sensitivity (e.g., “123 Main St” vs. “123 MAIN ST”).
Implement Manual Review Processes
- Set up a proactive manual review process for transactions that trigger AVS mismatches. Have trained personnel review these transactions to determine their legitimacy.
- Contact the customer for address verification or additional information if needed before rejecting the transaction. Set up trigger emails that are sent out as soon as you receive an AVS mismatch, giving customers a chance to correct any mistakes.
Use Multiple Verification Methods
- Combine AVS with other verification methods such as CVV checks, 3D Secure, or device intelligence to enhance security without relying solely on AVS.
- Incorporate geolocation data to help verify the customer’s location. This can be particularly useful for online transactions where the customer’s physical presence is not required.
Implement Risk-Based Decisioning
- Employ risk-based decisioning that assesses each transaction on its full context. Low-risk transactions can bypass strict AVS checks, while high-risk transactions undergo more stringent verification.
Balancing security and a positive customer experience is essential when dealing with AVS. While it’s crucial to minimize fraudulent transactions, it’s equally important to avoid frustrating legitimate customers with false declines. Implementing a combination of these strategies can help strike that balance.
How Wyllo Helps
Wyllo, the risk intelligence platform for commerce, treats an AVS response as one signal among hundreds rather than a verdict. Intent-aware decisioning weighs the full context of an order, so a typo in an apartment number doesn’t cost you a good customer.
- Wyllo Payment Fraud Protection combines AI decisioning with expert human review of flagged orders, so AVS mismatches on legitimate orders get a second look instead of an automatic decline.
- Wyllo Chargeback Management handles the disputes that slip through, from response through representment.
Precision over paranoia.
Frequently Asked Questions
What is an address verification system (AVS)?
An address verification system (AVS) is a card network service that compares the billing address a customer provides during a card-not-present transaction with the billing address on file at the issuing bank. The issuer returns a single-letter response code indicating a full match, partial match, or no match, and the merchant decides how to act on it.
What does an AVS mismatch mean?
An AVS mismatch means the billing address the customer entered doesn’t match the address the card issuer has on record. It can indicate fraud, but it often reflects something benign: a recent move, a typo, or an outdated address on file. That ambiguity is why treating every mismatch as fraud produces false declines.
Does an AVS decline mean the transaction was fraudulent?
No. AVS only verifies the numerical portions of a billing address, and legitimate customers frequently trigger mismatches. According to Baymard Institute’s checkout research, declined cards drive 9% of checkout abandonment, and some share of those declines lands on legitimate customers.
Is AVS enough to prevent ecommerce fraud?
No. AVS is a useful signal, but it was designed decades ago for a simpler threat landscape. It only works in a handful of countries, only checks billing addresses, and can’t evaluate the intent behind an order. Modern fraud programs layer AVS with CVV checks, device intelligence, behavioral signals, and risk-based decisioning.