Online card payments fail for a small, predictable set of reasons. As of April 2026, the same three causes drive the majority of declines: an issuer fraud lock on a transaction outside your usual pattern, an Address Verification System mismatch on the billing details you typed at checkout, and stale card data such as an expired card, an old CVV, or autofill remembering the prior account number. Once you know which one you're looking at, the fix usually takes under a minute.
The hard part is that most checkout pages give you almost nothing to work with. You see "card declined" or a generic error code, and that is it. So here is how to triage in about 60 seconds, what each cause looks like, and when it's worth picking up the phone.
The 60-Second Triage
Before you do anything else, run three checks in this order. Most readers find the answer inside step one or two.
First, open your issuer's app on your phone. Chase, Amex, Capital One, Citi, and most major banks now push a fraud-confirmation prompt straight to the app and to text. If a prompt is sitting there, tap "yes, this is me" and retry the transaction once. Done.
Second, check the billing address you entered at checkout against the address on file at the issuer. The numeric portion of the street and the ZIP must match. A typo in either field is the single most common cause of a clean card getting declined. Re-enter the ZIP exactly as it appears on your statement.
Third, verify the card details. Pull out the physical card. Confirm the expiration date hasn't passed. Confirm the CVV. Browser autofill loves to plug in last year's CVV after a reissued card, and that alone fails the transaction. If your replacement card is sitting in a junk drawer, every charge against the old one will fail forever.
If those three checks turn up nothing, move to the specific causes below.
How AVS Actually Works
The Address Verification System compares the billing address you typed at checkout with the address on file at your card issuer. The gateway returns a code: full match, partial match (street matches, ZIP doesn't, or vice versa), or no match. Merchants set their own tolerance. A travel site or a high-ticket retailer often declines anything short of a full match, while a small e-commerce store may accept a partial match.
This is why the same card can sail through one merchant and get declined at another five minutes later. It's also why international cards on US merchants frequently fail. Non-US billing addresses can't always be verified through AVS, so the gateway returns "unavailable" and the merchant treats that as a fail. If you moved and never updated your issuer, log in and update the address on file before retrying anywhere.
Soft Decline vs. Hard Decline
Not every decline is permanent, and the difference changes whether retrying makes sense.
A soft decline is a temporary failure: insufficient available credit, a fraud hold awaiting confirmation, a 3D Secure challenge you missed, or a gateway timeout on the merchant's side. These resolve once you fix the trigger (confirm the prompt, free up credit, complete the 3DS push notification on your phone), and the next attempt goes through.
A hard decline is a permanent failure on that card for that transaction: a category the issuer blocks outright (crypto buys, online gambling deposits, some third-party bill-pay services), an expired or canceled card, a closed account, or a stolen-card flag. Retrying does nothing. Switch to a different card or a different payment method.
The practical rule: try once, diagnose, then either fix the underlying issue or switch cards. Do not punch the same card in five times. Three to five rapid failures trigger an automatic fraud lockout on most issuers, and clearing that lockout requires a phone call and an identity check. A 30-second fix turns into a 15-minute fix the moment you start spam-retrying.
When It's Worth Calling the Issuer
Most declines do not need a call. The fraud-prompt flow handles itself in the app, AVS errors get fixed at checkout, and stale-data errors get fixed on the card. Pick up the phone in four cases: when no fraud prompt appeared in the app but the transaction still failed for fraud reasons; when the same card has been blocked twice in a row; when you need to pre-authorize a large or unusual purchase before attempting it (a wire-transfer-sized hotel deposit, a foreign-merchant booking, a single charge well above your normal pattern); or when you have already been locked out by rapid retries.
Use the number on the back of the card, not a number from a search result, since phishing operations target frustrated cardholders. Have the merchant name, dollar amount, and approximate time of the attempt ready. Most issuers will authorize the next transaction in under five minutes once they confirm it's you.
One last fallback worth knowing: if the merchant accepts Apple Pay or Google Pay, paying through the wallet often clears a transaction that keeps failing on manual entry. Wallet payments use a tokenized number and pass device-level authentication, which satisfies 3D Secure automatically and bypasses most AVS strictness. It's the underrated quick fix when you can't tell what's wrong and just need the order to go through.
This article contains affiliate links. If you apply through our links, we may earn a commission at no cost to you, which helps us continue sharing points and miles strategies with the community.
Some of the links in this article are affiliate links. We may receive a small commission at no extra cost to you if you apply through these links. This helps us keep the site running and continue creating free content.


