Skip to main content

Amex F29 - Card Not Present Fraud

This is the Amex code for a customer denying an online or phone order: F29. Looking for Visa 10.4, Mastercard 4837 or Discover UA02?

Read the code off your notice: a dot means Visa, four digits and no dot is Mastercard, two letters at the front is Discover. Get that right first, because Amex gives you 20 days to respond and the others give 30 or 45.

TL;DR
  • F29 is Amex's main fraud code for e-commerce and card-not-present orders. The cardholder says they didn't authorize the charge.
  • SafeKey (Amex's 3D Secure) is the defense that actually works. Full authentication shifts liability to the issuer. The dispute stops being yours.
  • Without SafeKey you're arguing with AVS/CVV results, delivery proof, and device logs. That wins sometimes, not most of the time.
  • You get 20 calendar days to respond. Visa gives 30 and Mastercard gives 45.
  • Amex usually sends an inquiry first. Answer it well and the chargeback doesn't get filed at all.

A cardholder told Amex they didn't place an order you shipped. Online, phone, or mail. That's F29. On Amex it's the code e-commerce merchants see most.

Overview

A cardholder says the charge wasn't theirs, and no card was present. Amex files F29. That's online checkout, phone orders, mail orders, and anything else where the card never physically showed up. There's no chip read to fall back on. Everything you'll argue with is data you captured at checkout.

When This Code Applies

  • Cardholder denies making an online purchase
  • Stolen card credentials used for a CNP transaction
  • Account takeover resulting in unauthorized orders
  • Family member or household user makes purchase without authorization
  • Friendly fraud (cardholder made the purchase but claims otherwise)

Conditions for Valid Dispute

Amex Must Verify

  1. Cardholder didn't authorize the transaction
  2. Transaction happened in a card-not-present environment
  3. Dispute filed within the allowable time frame
  4. Cardholder didn't benefit from the transaction

Transaction Must Be

  • E-commerce (online checkout)
  • Mail order or telephone order (MOTO)
  • Recurring billing without proper SafeKey authentication
  • Any other environment where the card never physically appears

Time Frames

Shorter Than Visa/Mastercard

Amex gives you 20 calendar days to respond. Visa allows 30, Mastercard allows 45. That's a third less than Visa and under half of Mastercard. Miss it and you lose automatically. Doesn't matter how good the evidence was.

StageWindow
Inquiry response20 calendar days
Chargeback response20 calendar days
Documentation request10 calendar days

Amex Inquiry Process

Amex usually sends an inquiry before the chargeback. Treat the inquiry as your real deadline. Ignore it and the chargeback files itself. Then you're fighting, not answering.

SafeKey (3D Secure) Liability Shift

Full Liability Shift (Issuer Liable)

The issuer eats the loss when all three of these are true:

  • SafeKey challenge completed by cardholder
  • ECI 05 = fully authenticated
  • Valid cryptogram/AEVV present

No Liability Shift (Merchant Liable)

ScenarioECIMerchant Liability
Authentication attempted, issuer unavailable06Reduced
Authentication failed or not attempted07Full
SafeKey not implementedN/AFull
Certain excluded MCC categoriesAnyFull
SafeKey Is Your Best Defense

Nobody publishes a clean figure for SafeKey's effect on F29 volume. Anyone quoting you one is guessing. The mechanism is what matters. A fully authenticated transaction (ECI 05) moves fraud liability to the issuer. Those disputes never reach you. Take real Amex volume and it's the highest-value item on this page.

Representment Options

1. SafeKey Authentication

When to use: SafeKey ran and it passed.

Evidence required:

  • ECI value showing full authentication (05)
  • AEVV/cryptogram
  • Authentication timestamp
  • SafeKey transaction ID

2. AVS and CVV Match

When to use: AVS and CVV both matched.

Evidence required:

  • AVS response showing match (full or partial)
  • CVV/CID match confirmation
  • Delivery confirmation to the AVS-verified address

3. Delivery Confirmation

When to use: Physical goods reached the cardholder. You've got tracking.

Evidence required:

  • Carrier tracking showing delivered status
  • Signature confirmation (strongly recommended)
  • Delivery address matching billing or AVS-verified address
  • Photo proof of delivery (if available)

4. Digital Goods Access

When to use: They used it. You've got logs.

Evidence required:

  • IP address at time of download or access
  • Access/usage logs showing activity after purchase
  • Account login history
  • Download confirmation records

5. Prior Transaction History

When to use: They've bought before and never disputed.

Evidence required:

  • Previous undisputed transactions from the same account
  • Matching email, device, or IP across transactions
  • Established customer relationship documentation

6. Cardholder Communication

When to use: You've got the cardholder on record about the order.

Evidence required:

  • Order confirmation sent to cardholder email
  • Customer service correspondence about the order
  • Chat transcripts or call recordings

Required Documentation

Evidence TypeStrength
SafeKey authenticated (ECI 05)Very Strong
AVS match + CVV match + signed deliveryStrong
Tracking delivered + AVS matchMedium-Strong
Prior undisputed transactions + device matchMedium
No authentication or delivery proofVery Weak

Win Rate Expectations

Defense TypeExpected Win Rate
SafeKey authenticated (ECI 05)70-85%
AVS + CVV + delivery proof45-60%
Prior transaction history + device match35-50%
Standard evidence only25-40%
No evidenceUnder 15%

That table is a decision, not trivia. Without SafeKey your best case is a coin flip.

Prevention Strategies

Authentication

  1. Turn on SafeKey (3D Secure 2.0) - Moves the loss to the issuer
  2. Run the frictionless flow - Most customers never see it
  3. Challenge the risky ones - Step up when a signal fires

Verification

  1. Require CVV/CID every time - Amex puts 4 digits on the front
  2. Check AVS on every order - Decline or review mismatches
  3. Verify email addresses - A bounced confirmation is a signal
  4. Call for the big ones - High-value or high-risk orders

Evidence Collection

  1. Log everything - IP, device fingerprint, timestamps, session data
  2. Keep the conversation - Emails, chat logs, call recordings
  3. Require delivery confirmation - Tracking, plus signature on big orders
  4. Track account history - Today's boring order is tomorrow's evidence

Fraud Screening

  1. Real-time scoring - Catch it at checkout, not later
  2. Velocity checks - Flag ordering patterns that aren't normal
  3. Device fingerprinting - Match devices across sessions
  4. Address validation - Cross-check shipping against billing

Common Mistakes

  1. Skipping SafeKey - You're eating avoidable fraud
  2. No delivery confirmation - You can't prove they got it
  3. Ignoring Amex inquiries - They don't go away, they escalate
  4. Missing the 20-day window - Shorter than Visa/MC, easy to blow
  5. Dumping files on Amex - A messy packet reads weak
  • F10 - Missing Imprint
  • F24 - No Cardholder Authorization
  • F30 - EMV Counterfeit
  • F31 - EMV Lost/Stolen/NRI

Next Steps

Got this chargeback?

  1. Check whether SafeKey ran → ECI 05 and you're in good shape
  2. Pull AVS/CVV results → Document the match status
  3. Gather delivery proof → Tracking, signature, address match
  4. Look for prior undisputed orders → Same device, email, or IP?
  5. Respond within 20 daysRepresentment Workflow

Prevent future F29 chargebacks:

  1. Implement 3D Secure / SafeKey for liability shift
  2. Set up dispute alerts to refund before chargeback
  3. Configure fraud detection to catch unauthorized use early

See Also