Payments

False declines: the checkout leak nobody measures

A false decline is a good customer with a good card who gets turned away. Fraud losses show up as chargebacks with a fee attached. A false decline shows up as nothing at all: a customer who tried to pay, didn't, and maybe never came back.

What a false decline is

A legitimate payment can be stopped in two places.

  • The issuer declines it. The bank's models look at spending habits, balance, and the card data you sent (expiry, address, CVC) and decide the charge looks wrong.
  • You decline it before the issuer sees it. Your fraud tool, your processor's risk rules, or a guarantee vendor blocks the order. Stripe, for example, doesn't send a payment its Radar rules block to the issuer at all.

The second kind is fully in your hands. The first kind is partly in your hands, because the issuer decides on the data you send it.

Most issuer declines don't say why. Stripe notes that card issuers categorize most declines as generic, and they discuss the reason only with the cardholder. So a false decline usually looks like code 05, do not honor, or 59, suspected fraud, sitting next to real fraud and real insufficient funds in the same report.

Measure your authorization rate first

Your authorization rate is the share of payments you send to issuers that they approve. Visa defines it as approved authorizations divided by total attempts, counting only the first attempt of each unique transaction. That last part matters. If a customer tries the same card three times, counting all three makes your rate look worse than it is, and counting the retry that finally worked makes it look better.

To get a number you can act on:

  1. Pull every card authorization attempt for the last 90 days with its outcome, decline code, card brand, card type, issuing country, and amount.
  2. Group attempts into unique purchases. On Stripe, the card fingerprint lets you exclude repeat attempts on the same card.
  3. Split out payments your own tools blocked before they reached the issuer. They aren't in the issuer's authorization rate, but they are lost orders.
  4. Calculate the rate overall, then by brand, debit versus credit, domestic versus cross-border, and order value band.

The overall number tells you little. The segments tell you where to look. A rate that drops sharply on cross-border cards, on high-value orders, or on one large issuer points at a cause you can work on.

Estimate how many were false

You can't see a false decline directly, but you can bound it. Three checks give you a working estimate.

  • Count the declined customers who paid you anyway, with another card or the same card a few minutes later. Every one of them was legitimate, so this is a floor on your false declines.
  • Sort declines by code. Insufficient funds and invalid card numbers are mostly real. Generic, do-not-honor, and suspected-fraud codes are where false declines hide.
  • Pull a sample of 50 to 100 orders your own rules blocked last month and check them against order history, email age, and shipping address. The share that look like real customers is your rules' false positive rate.

An illustrative example, using the same defaults as our calculator: a $50M brand with $30M in one-time orders and an 8% decline rate has about $2.6M of attempted orders declined a year. If a better setup wins back 15% of that, it's roughly $390K in sales. Your own numbers will differ, which is why it's worth measuring them.

What causes false declines

Issuer risk models

Issuers flag large purchases and bursts of transactions in a short window, according to Stripe. A new customer's first large order can look like the first, and a customer who retries a few times can look like the second.

Fraud rules set tighter than your losses justify

A rule added after a bad week of chargebacks keeps declining orders until someone removes it. Blocking whole countries, card types, or mismatched addresses stops fraud and good customers in the same move. A guarantee vendor that pays for your fraud losses has an incentive to decline anything borderline, which is covered in the chargeback protection guide.

Missing data

The less you send, the less the issuer has to approve on. Stripe recommends collecting CVC and postal code to avoid declines for suspected fraud, and says 3D Secure can lower decline rates in countries that support it. Network tokens replace the stored card number with a token from Visa or Mastercard. Visa reports a 4.6% lift in authorization rates on tokenized card-not-present transactions compared with card numbers, based on its fiscal 2022 data, and says individual merchants' results vary.

Cards that don't fit your business or country

Some cards only work at certain kinds of merchants. FSA and HSA cards, for example, are restricted to eligible businesses, so the issuer declines anything else. Cards issued in a different country from your account also decline more often, according to Stripe, and some issuers don't allow purchases from other countries at all.

Retrying too hard

Stripe warns that card issuers can read extra retries as potential fraud, which raises declines on legitimate charges. Stripe recommends no more than eight retries on a charge that allows them. The decline codes reference shows which codes are worth retrying at all.

How to fix them

  • Review every fraud rule against its results. For each one, count what it blocked last quarter and what share of those were real fraud. Loosen or delete the ones that block mostly good orders.
  • Send review cases to a human queue instead of declining them. On Stripe, a reviewed payment still goes through, and you can refund it if it turns out to be fraud.
  • Ask your processor whether network tokens are switched on for your account, and for which brands.
  • Collect CVC and billing postal code on every card checkout, and pass full address data where you have it.
  • Use 3D Secure selectively on orders your rules would otherwise decline. A customer who passes a challenge is a sale, and authenticated payments can shift fraud liability to the issuer.
  • On a decline in checkout, tell the customer they can try another card or a wallet, so the sale isn't lost on one attempt.
  • Retry only codes that can succeed, and keep within the network limits.

You can do all of this with the tools you already have. What it takes is one person who owns the authorization rate as a number, reviews it monthly, and changes the rules when the data says to.

What the industry numbers say

Most published false-decline figures come from fraud vendors, and many are projections. Two you can check at the source:

  • Stripe says online authorization rates can run 10% lower than in-person rates.
  • A 2020 Aite Group report sponsored by ClearSale, a fraud-screening vendor, surveyed 100 US ecommerce executives at companies with $100M to $1B in revenue. 62% said their false decline rates had risen over the previous two years.

Your own data beats either one, and the checks above will give you a number for your brand.

Put a number on it

Declined checkouts are one of four leaks in the Payments Leak Calculator, with failed renewals, chargebacks, and processing fees. Put in your decline rate and the share you think a better setup could win back, and it shows the profit at stake. Subscription renewals that fail are their own problem, covered in the failed payments guide.

Find your payments leak

Questions

What is a false decline?

A legitimate card payment that gets declined, either by the issuing bank or by the merchant's own fraud rules. It's also called a false positive.

How do you calculate authorization rate?

Approved authorizations divided by total authorization attempts, counting only the first attempt of each unique purchase so retries don't distort it.

What is a good authorization rate for ecommerce?

It depends on your card mix, countries, and order values, so compare yourself against your own history by segment. A drop in one segment is more useful than any published benchmark.

Do network tokens reduce false declines?

Visa reports higher authorization rates on tokenized card-not-present transactions than on card numbers. Ask your processor whether they're on for your account.

Sources: Stripe's documentation on declines, card declines and fraud prevention best practices, Stripe's guide to optimizing authorization rates, Visa's tokenization page (authorization rate definition and token figures), and ClearSale's summary of the Aite Group report. Checked October 2026.