Address Verification Service

Address Verification Service (AVS) is a fraud control used in card-not-present payments. The merchant sends the billing address the customer typed at checkout, the card issuer compares it against the address on file for that account, and the response tells the merchant whether the street number and postal code matched. It checks numbers, not names, and it verifies knowledge of an address rather than the identity of the person entering it.

Also called AVS
Used in Card-not-present transactions — ecommerce, phone, mail order
What is compared The numeric portion of the billing street address and the postal code
What is ignored Street name, city, state, apartment designation, and all non-numeric text
Who performs the check The card issuer, during authorization
Output A single-character AVS response code returned with the authorization
Coverage Widely supported for U.S., Canadian and U.K. issued cards; frequently unavailable on cards issued elsewhere
Effect on liability None by itself — AVS is not a liability shift

How it works

AVS runs inside the authorization message. When the merchant submits the transaction, the billing address the shopper entered travels with it. The issuer strips everything but the digits — house number and postal code — and compares them against the cardholder record. The comparison is deliberately crude, because address formatting is inconsistent enough that matching full text would produce constant false mismatches.

The result comes back as a single character. The exact code set varies slightly by network, but the shape is consistent:

Response Meaning Common merchant handling
Full match Street number and postal code both match Approve
Partial — postal code only Postal code matches, street number does not Approve, or review on higher-value orders
Partial — street only Street number matches, postal code does not Review
No match Neither element matches Decline or route to review
Unavailable or not supported The issuer did not perform the check Cannot be read as a signal either way

The last row is the one that causes trouble. An unavailable response is not a soft pass; it is an absence of information. Merchants who treat it as a match effectively disable the control for every international card, which is exactly the population where it matters most.

Why AVS matters, and where it stops

AVS earned its place because it was cheap, ran inside an existing message, and caught a meaningful share of casual card fraud in an era when knowing someone’s billing address required effort. That era ended. Billing addresses are in essentially every consumer data breach, and a full set of stolen credentials — the package sold as fullz — includes the address by definition. A fraudster working from purchased data passes AVS on the first attempt.

This puts AVS in a specific category: a control that still filters unsophisticated attempts and still contributes to a risk score, but which cannot carry weight on its own. It sits alongside CVV checks and 3-D Secure in the layered defenses around card-not-present fraud, and the layering is the point. No single one of them establishes who is transacting.

What does address the underlying question is verifying the person rather than the data they possess. Payment card capture with fraud signals examines the card itself at the point of entry, and where the risk justifies it, identity verification binds the transaction to a real person rather than to a memorized address. For merchants building layered defenses, payment fraud controls work best when the identity layer is available for the transactions that warrant it.

What AVS can’t do

It does not verify identity. It verifies that whoever is at the keyboard knows the billing address associated with the card. Those are different claims, and breached data has made the gap between them wide.

It ignores the street name entirely. Only digits are compared. A transaction giving the correct house number on the wrong street returns a match on that element.

It offers no chargeback protection. A full AVS match does not shift liability. Merchants sometimes assume otherwise and discover the position during a dispute.

Coverage is uneven internationally. Many non-U.S. issuers do not participate, so declining on anything short of a full match rejects legitimate international customers wholesale.

Legitimate mismatches are common. Recent movers, gifts shipped to another address, corporate cards, and simple typing errors all produce mismatches on genuine orders. AVS declines have a real false-positive cost.

Frequently asked questions

Does AVS check the cardholder’s name?

No. AVS compares only the numeric portion of the billing street address and the postal code. The name, street name, city and state are not part of the comparison.

Does passing AVS prevent a chargeback?

No. AVS is a fraud signal, not a liability shift. A transaction can return a full AVS match and still be charged back as fraudulent. Liability protection in card-not-present transactions comes from other mechanisms, such as 3-D Secure authentication.

Why do legitimate customers fail AVS?

Most often because they have recently moved, are shipping to an address other than the billing address, are using a corporate card registered to a company address, or have simply mistyped. International cards frequently return an unavailable response rather than a match.

Is AVS still worth using?

As one layer, yes — it is inexpensive and filters unsophisticated attempts. As a primary control, no. Billing addresses appear in nearly every consumer data breach, so possession of the correct address no longer indicates much about who is transacting.

Related reading

  • Card-not-present fraud — the transaction category AVS was designed for, and how the attack has changed
  • Chargeback — what happens after a fraudulent transaction succeeds, and who absorbs it
  • Fullz — the stolen data package that includes the billing address AVS asks for
  • Card-not-present fraud explained — how layered controls perform against current attack methods

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data