Visa reason code 10.4: "fraudulent" (card-not-present) — the evidence that wins
Visa reason code 10.4 covers other fraud in a card-absent environment: the cardholder says "I never made or authorized this purchase." Mastercard's fraud family (for example, reason code 4837, no cardholder authorization) works the same way. The cardholder may be a victim of real fraud — or the buyer themselves disputing a purchase they made. Either way, your packet has to answer one question: what ties this transaction to the cardholder?
The exhibits that carry the case
Fraud disputes are won on identity linkage: independent records that connect the cardholder to the transaction. No single item proves it; the pattern does. Gather everything you have from this list:
- Exhibit A — AVS and CVV results. The address-verification and card-security-code check results from the original transaction (full or partial AVS match, CVV match) as recorded by your processor at checkout time.
- Exhibit B — IP and device match. The checkout IP address, device fingerprint, or browser/session data — especially when the same IP or device appears on prior, non-disputed orders from this customer.
- Exhibit C — Account, login, and download logs. For digital goods: account creation, login timestamps, license-key activation, download or streaming logs tied to the buyer's account or email.
- Exhibit D — Prior non-disputed orders. Earlier purchases by the same customer, email, address, or device that were never disputed. A history of accepted orders is some of the strongest evidence an issuer sees.
- Exhibit E — Acknowledgment messages. Any email, chat, or support message where the buyer acknowledges the purchase: asking about delivery, requesting a feature, using the product, or disputing the price (not the purchase itself).
- Exhibit F — Delivery or usage record. For physical goods, the delivery scan at the cardholder's address; for digital goods, ongoing usage after purchase (logins, downloads, course progress, API calls).
What issuers weigh most
Issuers weigh corroboration across systems: checkout checks (Exhibit A) plus behavioral records (Exhibits B and C) plus history (Exhibit D) are far stronger than any one of them alone. A CVV match by itself proves someone had the card details; a CVV match plus the buyer's own account logging in and downloading the product for two weeks is a pattern a fraud claim can't survive. Lead your summary with the single strongest tie — usually an acknowledgment message or post-purchase usage — and let the exhibits corroborate it.
Digital goods vs. physical goods
Digital goods
You have no carrier scan, so your "delivery proof" is system exhaust: the delivery email to the buyer's address, account activation, login timestamps from the buyer's IP, download or streaming logs, and license-key use. Usage over time matters most — a product used for 19 days before the "fraud" claim was reported is hard to explain away. Export these logs early; many platforms retain them for a limited time.
Physical goods
The delivery scan at the cardholder's billing or checkout address is your anchor exhibit, supported by AVS results from checkout. Add prior delivered orders to the same address where you have them. If the delivery address differs from the billing address, say so plainly and show who chose it — an unexplained mismatch is where these cases are lost.
Structure the response like this
- Summary (3–5 sentences). Name the reason code and the identity tie: "Visa 10.4. Checkout passed AVS and CVV checks (Exhibit A) from the same IP address as the customer's four prior undisputed orders (Exhibits B, D). The buyer logged in and downloaded the product on six dates after purchase (Exhibit C) and emailed support about it on May 12 (Exhibit E)."
- Timeline. Purchase → delivery/access → usage → acknowledgment → dispute filed. Fraud cases are read as a story; make the chronology do the work.
- Exhibits, in reading order. Every claim in the summary points at one exhibit; redact anything not needed (never submit full card numbers).
Mistakes that lose winnable 10.4s
| Mistake | Why it loses |
|---|---|
| Sending only the processor's transaction record | That proves a card was charged — which the cardholder isn't disputing. The dispute is about who used it; answer that question. |
| "The customer is lying" as the rebuttal | Accusations without records persuade no one, and some 10.4s are genuine fraud. Let the logs make the point; stay factual and boring. |
| Letting platform logs age out | Login, download, and session logs may be retained for weeks, not years. Export them the day the dispute lands, not the day the response is due. |
| Omitting prior undisputed orders | A clean purchase history from the same device, email, or address is among the strongest evidence an issuer sees. Leaving it out wastes your best corroboration. |
Other reason codes
- Product not received (Visa 13.1): delivery evidence that wins →
- Not as described (Visa 13.3): listing, specs, and receipt proof →
- Canceled recurring (Visa 13.2): terms, usage, and cancellation records →
- Credit not processed (Visa 13.6/13.7): refund proof and the ARN →
- The full Stripe chargeback evidence checklist, by reason code →
Have a 10.4 open right now?
Parry assembles this packet from your uploads — dispute notice, checkout checks, access logs, order history, customer messages — into a case summary, rebuttal draft, timeline, and labeled exhibits. It's an AI draft: you review every fact and submit it yourself. We never submit in your name, never invent evidence, and the outcome is always the bank's call.
$10 for your first month, then $29/mo. Up to 5 evidence packets/month, dispute deadline alerts, and a saved store/evidence profile. Cancel anytime. No success fee.
Parry is not affiliated with Stripe, Visa, or Mastercard. Reason-code descriptions are general information, not legal advice; your processor's dispute notice controls deadlines and requirements. Last updated: October 10, 2026.