Retry Logic That Recovers Rebills Without Triggering Network Fines

11 min read

Reviewed by

Daily Intel Research Team

Evidence base

VSLs, ads, funnels, UTMs, transcripts, and market pattern review

Coverage

14+ languages · blackhat, greyhat, and whitehat patterns

8,226+

Videos & Ads

+50-100

Fresh Daily

$29.90

Per Month

Full Access

12.5 TB database · 72+ niches · cancel anytime

How many reattempts do Visa and Mastercard allow on a declined transaction?

Visa allows a maximum of 15 reattempts within a rolling 30-day window for the same card, amount and currency combination, per CardPointe's compilation of Visa's compliance documentation and the Retries.com decline categories guide. Any attempt beyond that count, or any reattempt of a permanently declined transaction, triggers an excessive-reattempt fee rather than a second shot at approval.

Mastercard's structure works differently. Instead of a flat count over 30 days, its Transaction Processing Excellence program fines each authorization attempt after a threshold number of prior declines on the same card within a 24-hour window — Merchant Cost Consulting's write-up cites 10 prior declines as the trigger, while other secondary summaries put it at 20, so the exact number needs confirming against a current acquirer bulletin before you rely on it operationally.

Both networks count reattempts per card, not per customer account, so a customer with two cards on file effectively gives your CRM two separate reattempt budgets. Treat that as capacity, not license — spreading retries across cards to multiply attempts invites the fraud and dispute scrutiny built into Visa's newer acquirer monitoring rules rather than solving the underlying decline.

Which decline categories may never be retried at all?

Category 1 declines may never be retried. Visa's own sorting defines this category as one "the issuer will never approve," per CardPointe's breakdown of Visa's decline codes, and codes 04, 07, 41 and 43 fall into it; reattempting any of them counts as a rule violation regardless of how few total attempts you've made that month.

Category 2 covers temporary problems the issuer "cannot approve at this time" — insufficient funds is the classic example — and these are worth retrying on a delay. Category 3 declines need the transaction data corrected before a retry has any chance, and Category 4 is a generic refusal Visa still permits you to reattempt within the 15-in-30-days limit; response code 05, "Do Not Honor," is understood, per Retries.com's breakdown of Visa decline categories, to sit here.

Stripe's decline-code documentation draws a similar line from the processor side: expired_card, insufficient_funds, invalid_account, lost_card and stolen_card are all cases where Stripe states that retrying will not work and the customer needs another payment method entirely. Stripe also instructs merchants never to surface a lost_card or stolen_card result to the buyer directly, presenting it instead as a generic decline — a rule that matters as much for your decline-page copy as for your retry cadence.

What are the per-attempt fees for exceeding the reattempt caps?

Exceeding Visa's cap costs $0.10 per domestic attempt and $0.15 per cross-border attempt, assessed on every reattempt past the 15-in-30-days ceiling or on any retry of a Category 1 decline. Mastercard's equivalent penalty, the Transaction Processing Excellence Excessive Authorizations fee, is reported by Merchant Cost Consulting to have reached around $0.50 per excess authorization in January 2025, after a steep multi-year ramp.

Mastercard layers a second fee on top: the Merchant Advice Code fee, reported at around $0.03 per transaction, applies to declined card-not-present charges carrying MAC 03 (closed or fraudulent account) or MAC 21 (cardholder cancelled the agreement). These fees look small individually, but a CRM retrying a dead card several times a month across a subscriber base in the thousands turns pennies into a real line item.

YearMastercard TPE excessive-authorization fee (reported)
2022around $0.10
2023around $0.15
2024around $0.30
January 2025around $0.50

What changed in Mastercard's excessive authorization policy in 2026?

The biggest 2026 change is not the authorization fee itself but its scope. From January 2026, Mastercard's Merchant Advice Code fee applies to every declined card-not-present transaction carrying MAC 03 or MAC 21 — not only to retry attempts — so a single undifferentiated charge against a cancelled subscriber's account now costs money even if your system never reattempts it.

That extension punishes exactly the dunning pattern most subscription-billing vendors recommend by default: fire the charge first, sort out the decline reason after. If your CRM cannot distinguish a cancelled-account decline from a temporary insufficient-funds decline before it authorizes, every cancelled subscriber left in an active billing cycle now generates a fee on the first attempt, not just the fifth.

Mastercard's new Scam Merchant Monitoring Program adds a second 2026 pressure point, becoming enforceable 24 July 2026. It triggers when combined refunds and chargebacks exceed 5% of a merchant's transactions over a rolling 30-day period with at least 500 transactions in that window, and it explicitly treats an authorization-approval-rate collapse as a scam signal — a pattern aggressive, undifferentiated retry cadences can produce on their own.

What retry timing actually recovers a failed rebill versus wasting attempts?

Timing that matches the decline reason recovers a rebill; timing on a fixed interval regardless of reason wastes attempts on cards that were never going to clear. A Category 2 decline like insufficient funds genuinely improves with a delay of a few days, timed around typical payroll or benefit deposit cycles, while a Category 1 or Category 3 decline needs corrected data, not patience.

Stripe's Smart Retries default schedule for failed subscription invoices runs 8 attempts across 2 weeks, though custom schedules are capped at three retries. Stripe does not publish a recovery-rate figure for that default, so treat the eight-over-two-weeks shape as a reasonable starting cadence rather than a proven optimum for a high-risk nutraceutical subscriber file.

Recurly's data on initial-versus-recurring approval rates argues for spending retry effort differently depending on where a card sits in its lifecycle: debit cards declined at 14.4% on the first charge against 13.1% on later recurring charges, while credit cards performed best of all on recurring transactions at a 6.0% decline rate. A card that already survived several rebill cycles is a better retry candidate than one failing its very first charge.

Should retry amounts ever be altered, and what do the rules say about that?

Altering the retry amount is not addressed by an explicit ban the way retrying a Category 1 decline is. Visa's 15-in-30-days cap is defined specifically for reattempts of the same card, amount and currency, which means a materially different amount arguably counts as a new original transaction rather than a counted reattempt — most operators in this niche avoid touching the retry amount on principle, but the stricter reading of the rule text does not actually forbid it.

That said, exploiting the gap is a poor trade. Splitting a rebill into a smaller authorization to dodge the reattempt counter still produces a transaction the issuer sees as unusual behavior on a card that just failed, and it does nothing to address whichever decline category caused the failure in the first place; a Category 1 decline stays uncollectable no matter what number you charge.

The more durable risk sits outside the reattempt cap entirely. A pattern of varied-amount authorizations against declining cards is exactly the kind of authorization-approval-rate anomaly Mastercard's Scam Merchant Monitoring Program watches for, and it offers no protection against Visa's dispute-ratio thresholds once the customer disputes whichever amount finally clears.

How do dunning emails and SMS change recovery beyond the retry itself?

Dunning messages recover rebills a retry alone cannot, because they reach a channel the card network doesn't touch. A retry can only resubmit the same expired card; a message that gets the customer to type in a new one converts what Stripe's own documentation calls an unrecoverable decline — expired_card, invalid_account, lost_card, stolen_card — into a normal transaction on a valid instrument.

Account-updater services do part of this job automatically, before a message is ever needed. Industry vendor guides put roughly 30% of cards replaced annually, with 60-70% of those changes captured by Visa's or Mastercard's updater services and 3-5% of otherwise-lost recurring revenue recovered as a result, though these figures come from payments vendors rather than Visa or Mastercard directly and should be read as approximate. Running an updater pass before a scheduled retry, rather than after, is what turns that recovery rate into revenue instead of a second failed attempt.

The message itself carries its own compliance exposure once it repeats anything from the original offer's marketing. A dunning email that restates a VSL's earnings or results claim to win the subscriber back is making the same advertising claim the original ad made, and it inherits the same disclosure obligations, a gap covered in FTC and EU Ad Rules CIS Buyers Break Without Knowing.

How do I audit my CRM's retry schedule against current network rules?

Start by pulling a full decline-code export from your gateway for the last billing cycle and sorting it against both networks' category systems before touching the retry schedule itself. A schedule that looks reasonable in aggregate can still be retrying dead cards dozens of times if the underlying decline-code mapping was never built.

If your offer runs through a retailer-of-record network rather than your own merchant account, the retry cadence you can actually control is smaller than it looks — the network sets its own dunning schedule inside its processing stack. That division of responsibility is closely related to the questions covered in Affiliate Network Rules on Cloaking: ClickBank to BuyGoods, where the same platform choice determines who is legally the seller of record.

Re-run the audit quarterly, not annually. Mastercard's per-attempt fee moved every year from 2022 through 2025, and its Merchant Advice Code scope changed again in January 2026, so a retry schedule that was compliant twelve months ago is not a safe assumption today.

  • Confirm no code in your retry logic ever resubmits Visa Category 1 declines (codes including 04, 07, 41, 43) or Stripe's non-retryable set (expired_card, invalid_account, lost_card, stolen_card).
  • Count reattempts per card, amount and currency over a rolling 30 days and flag any sequence approaching Visa's 15-attempt ceiling.
  • Cap same-card authorization attempts within any 24-hour window well under the 10-to-20 range reported for Mastercard's threshold until you confirm the current figure with your acquirer.
  • Tag every decline carrying Mastercard's MAC 03 or MAC 21 codes separately from temporary declines, since both now carry a fee on the first attempt as well as on retry.
  • Route retries through an account-updater pass first, so the CRM isn't spending its cap resubmitting a card number the update already replaced.

Quick decision checklist

Use this page as a decision aid, not a generic blog post. The practical question is whether the reader needs faster evidence about what is already working in VSL-driven direct response, especially across nutra, supplements, GLP-1, weight loss, blood sugar, and adjacent high-intent health markets.

Daily Intel Service is most relevant when the next decision depends on active market examples: which hook to test, which claim style is risky, which funnel structure is common, which language market is moving, and whether a competitor's creative is likely early, scaling, or already saturated.

  • Start with the TL;DR if you need the direct answer.
  • Use the table to compare trade-offs quickly.
  • Use the FAQ for answer-engine-ready summaries.
  • Use the CTA when the decision requires live VSL and ad examples instead of theory.

Daily Intel's coverage advantage

Daily Intel Service is positioned around category-leading variety and actionability: one of the broadest direct-response catalogs of VSLs and ad creatives across blackhat, greyhat, and whitehat advertising patterns, with enough context to understand what the advertiser is doing beyond the visible creative. The practical difference is that members are not just seeing a screenshot; they are seeing the VSL, the ad, the funnel path, the transcript, the UTM context, and the research notes that turn the asset into a decision.

This matters because direct-response affiliates do not operate in one clean category. A weight-loss campaign may use a whitehat compliance ad, a greyhat pre-lander, a more aggressive VSL, and a checkout path designed around upsells and recovery. A useful intelligence platform needs to capture that spectrum instead of pretending every winning campaign looks like a public brand ad.

Blackhat, whitehat, and multilingual signal coverage

Daily Intel tracks patterns across both blackhat-style and whitehat-style campaigns so operators can understand the market without blindly copying risk. Whitehat examples help with durability and compliance review; blackhat and greyhat examples reveal pressure points, hooks, mechanisms, and funnel structures that may be driving spend but require careful adaptation before use.

The catalog is also built for global operators, with VSL and ad references spanning 14+ languages and different local idioms. That is a key advantage for Brazilian, LATAM, European, MENA, Indian, and non-native English affiliates who need to see how the same market desire is translated across cultures instead of only studying US English ads.

Research needGeneric ad archiveDaily Intel Service
Creative volumeLarge raw databases with mixed relevanceCurated VSL and ad examples selected for direct-response usefulness
Blackhat and whitehat awarenessOften flattened into screenshots or URLsExplicit attention to compliance spectrum, cloaking risk, and claim style
Post-click contextUsually limited or inconsistentVSL, transcript, funnel path, checkout, upsell, UTM, and recovery notes where available
Language coverageSearch filters may exist, but context is thin14+ language and international idiom coverage for global affiliate research
Best use caseBroad browsing and historical lookupNutra, supplement, GLP-1, VSL, and direct-response campaign decisions

How to use the intelligence responsibly

The goal is modeling, not copying. Use Daily Intel to understand structure: hook, mechanism, proof, claim intensity, funnel depth, offer economics, and saturation stage. Then build original creative, review claims, and adapt the angle to the traffic source, country, language, and compliance requirements of the campaign.

A strong workflow compares multiple examples before acting. If the same mechanism appears across several languages, several advertisers, and several funnel variants, it may be a durable market signal. If the example appears only once or depends on an aggressive claim, treat it as a research clue rather than a campaign template.

  • Model structure, not protected creative assets.
  • Separate whitehat durability from blackhat persuasion pressure.
  • Compare US English examples against LATAM, European, and other language variants.
  • Use transcripts and funnel notes to build original briefs.
  • Keep compliance review separate from market research.

Methodology and source context

Daily Intel pages are written from a research workflow that reviews active VSLs, Meta ad creatives, transcripts, UTMs, funnel paths, checkout steps, upsells, recovery sequences, and compliance-sensitive claim patterns. The goal is to explain observable market behavior, not to provide legal, medical, or platform policy advice.

When the topic touches health claims, platform policy, or GLP-1 market research, validate the observable campaign signals against primary references such as Meta advertising standards, FTC health claims guidance, and Google helpful content guidance. Daily Intel adds the proprietary direct-response layer by mapping how those rules show up in active VSLs, Meta creatives, funnels, transcripts, UTMs, and checkout paths.

For deeper evaluation, continue through Daily Intel compliance and legal disclaimer, Conta de Anúncios Bloqueada no Facebook: Como Recorrer, Advertorial vs White Page: How Analysts Tell Them Apart, Agency Ad Account Providers: 9 Red Flags Before You Pay, Destination Mismatch in Google Ads: Causes and Fixes, and What is a VSL?. These related Daily Intel pages connect this topic to the relevant methodology, pricing, trust context, comparison path, or niche workflow.

Founding rate — locked forever

Access curated VSL intelligence for $29.90/mo

  • 50–100 manually validated VSLs every day at 11PM EST
  • major niches niches, 14+ languages, blackhat-to-whitehat pattern coverage
  • live catalog VSL/ad catalog, transcripts, UTMs, full funnel maps
  • Cancel anytime — founding rate stays yours forever

Daily Intel Service delivers manually curated research around active-scaling VSLs, Meta creatives, UTMs, funnels, and nutra market movement.

$29.90/mo

$299/mo

Coupon LIFETIME-269-OFF auto-applied

Claim the rate

Secure checkout · Stripe

Frequently asked questions

  • What is the maximum number of times I can retry a declined subscription payment?

    Visa's rule allows up to 15 reattempts within a rolling 30-day period for the same card, amount and currency, after which every additional attempt is assessed an excessive-reattempt fee. Mastercard uses a 24-hour decline-count threshold instead of a 30-day count, and that exact number needs confirming against a current acquirer bulletin.
  • Can I ever retry a "Do Not Honor" decline?

    Yes — Visa response code 05, "Do Not Honor," is generally classified as Category 4, a generic refusal that is retryable within the normal 15-in-30-days limit. That differs from Category 1 codes such as 04, 07, 41 and 43, which the issuer will never approve and which must never be reattempted regardless of how few retries you've used.
  • Does 3-D Secure protect recurring rebill charges from fraud disputes?

    No — Stripe's documentation states that off-session merchant-initiated transactions, which cover the entire recurring rebill leg of a subscription, do not support 3DS authentication at all. The liability shift 3DS provides on an initial, customer-present charge never applies to the rebill, so fraud chargebacks on recurring charges stay with the merchant.
  • Will changing the retry amount help me get around Visa's reattempt cap?

    It might technically sidestep the specific counter, since Visa defines the 15-in-30-days cap for reattempts of the same card, amount and currency. But it does nothing to fix the underlying decline reason, and a pattern of varied authorization amounts against a failing card is the kind of anomaly Mastercard's newer scam-monitoring program is built to flag.
  • What's the single biggest 2026 change operators need to know about?

    Mastercard's Merchant Advice Code fee now applies to every declined card-not-present transaction carrying MAC 03 or MAC 21 as of January 2026, not only to retries of those declines. That means charging a cancelled subscriber even once, with no retry attempt at all, now carries a cost it didn't carry in 2025.
  • Do dunning emails actually matter if my retry logic is already compliant?

    Yes — a compliant retry schedule can still recover nothing on a genuinely dead card, and dunning messages are the only channel that gets a customer to supply a new one. Card-network rules govern how many times you may resubmit the same card; they say nothing about the email or SMS that gets the customer to change it.

Continue the research path

Related pages

Next in complianceRolling Reserves on High-Risk Accounts: How Much They Hold, For How LongRolling, capped, and upfront reserves decoded for supplement sellers: typical percentages, release schedules, how reserves interact with rebill cash flow

Lock $29.90/mo forever

Coupon LIFETIME-269-OFF · Cancel anytime

Get Access