AVS & CVV Result Codes
Address and security-code check results in plain English, including which ones are fraud signals.
Runs entirely in your browser. Nothing you paste is uploaded, logged or stored.
AVS address verification result
| Code | Meaning |
|---|---|
| Match | |
| Y | Address and 5-digit postal code both matchok |
| X | Address and 9-digit postal code both matchok |
| D | Address and postal code both match (international)ok |
| M | Address and postal code both match (international)ok |
| F | Address and postal code both match (UK)ok |
| Partial | |
| A | Address matches, postal code does notwarn |
| B | Address matches, postal code not verified (international)warn |
| P | Postal code matches, address not verified (international)warn |
| W | 9-digit postal code matches, address does notwarn |
| Z | 5-digit postal code matches, address does notwarn |
| No match | |
| N | Neither address nor postal code matchesbad |
| C | Neither address nor postal code verified (international)bad |
| Not checked | |
| E | AVS data invalid, or not permitted for this card typebad |
| G | Issuer does not participate in AVS (typically non-US) |
| I | Address not verified (international) |
| R | Retry: the AVS system was unavailablewarn |
| S | AVS not supported by the issuer |
| U | Address information unavailable at the issuer |
CVV / CVC / CID result
| Code | Meaning |
|---|---|
| M | CVV matchedokThe security code you sent is correct. |
| N | CVV did not matchbadA strong fraud signal for a card-not-present transaction, even when the authorisation is approved. |
| P | Not processedwarnThe code was sent but the issuer did not check it. |
| S | CVV should be on the card but the merchant said it was absentwarn |
| U | Issuer not certified, or has not supplied keys |
| X | No response from the scheme |
| (empty) | No CVV providedNothing was sent. Not the same as a failed check. |
A CVV mismatch on an approved transaction
This surprises people constantly: an authorisation can come back approved with a CVV result of
N. The two checks are independent. The issuer approved the funds and separately told
you the security code was wrong.
That combination is a strong fraud signal for a card-not-present transaction, and most risk teams treat it as a decline regardless of the authorisation outcome. If you are only reading DE 39 and ignoring the CVV result, you are leaving that signal on the floor. Reverse the authorisation rather than just abandoning it, or you will hold the cardholder's funds.
AVS is mostly a US, Canada and UK signal
Address verification depends on the issuer holding and checking address data, and outside the US,
Canada and the UK many issuers simply do not participate. A result of G,
S or U means "not checked", not "failed". Declining on those will reject
large volumes of perfectly good international traffic.
This is the most common AVS mistake: treating an absence of confirmation as evidence of fraud.
N is a genuine mismatch. U is silence.
Partial matches need a policy
Z (postal code matches, address does not) and A (address matches, postal
code does not) are where judgement lives. Many merchants accept Z and reject A, on the reasoning
that a postal code is harder to guess than a street address and easier to mistype. Whatever you
choose, choose deliberately. The default in most gateways is to accept everything.
Where the results arrive
Usually in ISO 8583 DE 44, additional response data, whose internal layout is processor-specific: the AVS result is often the first character and the CVV result a later one. Modern gateway APIs surface them as named fields instead, which is a mercy. Paste a whole response into the message decoder and DE 44 comes out alongside DE 39, which is the pairing you need to read them together.
One thing to state plainly: never store the CVV after authorisation. Not encrypted, not hashed, not "temporarily". PCI DSS prohibits it outright, and unlike a PAN there is no compliant way to retain it.
More ISO 8583 tools
All ISO 8583 toolsMessage decoder beta
Paste a whole authorisation message and get every data element split out, interpreted and mapped to its bytes.
MTI decoder
Split a 4-digit message type indicator into version, class, function and origin.
Bitmap decoder
Turn a primary and secondary bitmap into the list of data elements present, and back again.
DE reference
All 128 data elements with formats, lengths and the ones processors love to redefine.
Decline codes
DE 39 response codes in plain English, with what to actually do about each one.
POS entry mode
What DE 22 and tag 9F39 mean, from chip to contactless to fallback to e-commerce, and why it changes your interchange.
Which identifier?
Four identifiers, constantly confused. What each one is, who sets it, and when it is unique.