# Drive address and security code results

[Choose what to test in the sandbox](https://devportal.qa.winkpg.io/docs/decide/choose-what-to-test.md): Which sandbox scenario proves the part of your integration you're about to ship, and the blueprint that runs it.

Make the sandbox return a match, a mismatch, and an issuer that can't check, for the address and for the security code.

**Your answers so far**

- What are you testing next? What my code does when a payment is refused or comes back.
- Which refusal do you need to see? An address or security code that doesn't match.

**What to build**

Run the AVS blueprint and the CVV blueprint. Each sends the three cases side by side, so you can compare the codes your integration reads and confirm it doesn't assume a check passed because the payment was approved.

**Worth knowing**

- A merchant's own verification rules can refuse an approved payment. That arrives as a policy rejection, which is never retried unchanged.

**Where to go next**

- [Test AVS responses](https://devportal.qa.winkpg.io/docs/blueprints/test-avs-responses.md)
- [Handle a CVV mismatch](https://devportal.qa.winkpg.io/docs/blueprints/test-cvv-mismatch-handling.md)
- [Understanding declines and rejections](https://devportal.qa.winkpg.io/docs/guides/understanding-declines-and-rejections.md)

- [Start over](https://devportal.qa.winkpg.io/docs/decide/choose-what-to-test.md): go back to the first question.

## See also

- [All documentation](https://devportal.qa.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
