Mastercard Payment Decline Code
Mastercard Decline Code 63: Security Violation
Category Fraud or SecurityRetry Guidance Hard Decline (Editorial Classification)By Payment Defender Editorial TeamUpdated July 17, 2026Last reviewed July 17, 2026
What Mastercard Decline Code 63 Means
Mastercard decline code 63 (Security Violation) indicates that the issuer declined the transaction because of a security concern. It is returned during authorization to tell the merchant the payment could not be approved as submitted.
Where the Response May Come From
Mastercard code 63 (Security Violation) is returned by the card issuer during authorization and signals that the issuer's security rules were triggered during authorization. Issuers rarely disclose the precise internal cause, so treat it as a directional signal rather than a full explanation.
Common Reasons for This Response
Common causes include failed security checks, suspected fraud, or a mismatch in verification data. The exact trigger depends on the issuer, the account, and how the transaction was submitted, so the same code can appear in several different situations.
Should the Merchant Retry the Payment?
Because the issuer's security rules were triggered during authorization, resubmitting the same details is unlikely to clear and repeated attempts may be discouraged under network retry rules; resolve the condition or use another payment method instead.
Recommended Merchant Action
Do not resubmit this transaction unchanged, since the issuer's security rules were triggered during authorization; ask the customer for another card or payment method, and review the transaction with your fraud and risk tooling.
What to Tell the Customer
Let the customer know the payment did not go through because the issuer's security rules were triggered during authorization, and suggest contacting their issuing bank or using another card. Keep the wording neutral and avoid asserting issuer details you cannot confirm.
How to Reduce Similar Payment Failures
Segmenting how often the issuer's security rules were triggered during authorization appears by issuer and BIN, tuning fraud screening to reduce security-triggered declines, and submitting clean, correctly formatted authorization data can reduce avoidable occurrences of this decline over time.
Important Limitations
Decline-code meanings vary by processor, gateway, and payment environment, and issuers do not always disclose the specific reason behind a response. The retry classification on this page is Payment Defender editorial guidance, not an official Mastercard rule. Merchants should confirm handling with their processor or gateway.
Related Decline Codes
Sources and Review Information
- PayPal (Braintree): Braintree Processor Response Codes
- Mastercard: Mastercard Rules and Merchant Support
Last reviewed July 17, 2026
Raw network-response codes are supplemental to the complete processor or gateway response. Meanings and recommended actions can vary by issuer, processor, gateway, card network, payment method, region, and merchant configuration.
