A flight reservation for a visa costs little, which is exactly why scammers like this corner of the internet. The sums are small enough that people pay without thinking, and the buyers are often anxious about an appointment date. This guide is about protecting your money: how to judge a checkout before you pay, the warning signs official bodies describe, and what to do, in what order, if a payment goes wrong. Everything here comes from the Reserve Bank of India (RBI), the Ministry of Home Affairs' cybercrime centre, Razorpay's own guidance for customers, and Visa. If you want to know which payment methods we accept and how each one works on our checkout, that's in our separate payment methods guide.
Paying safely: key facts
| Question | Official answer |
|---|---|
| Do you ever need a PIN or QR code to receive money? | No. RBI says receiving money does not require scanning QR codes or entering m-PIN or passwords.[4] |
| Unauthorised debit, not your fault, reported within 3 working days | Zero liability for you under RBI's customer protection rules.[3] |
| Reported in 4 to 7 working days | Liability capped at the transaction value or the limit in RBI's table, whichever is lower.[3] |
| When must the bank credit the money back? | A shadow reversal within 10 working days of your report.[3] |
| Where to report cyber fraud in India | Helpline 1930, or the National Cyber Crime Reporting Portal at cybercrime.gov.in.[6][7] |
| If your bank doesn't resolve it | A complaint under the RBI Integrated Ombudsman Scheme, 2026, at cms.rbi.org.in; contact centre 14448.[5] |
How can you tell a checkout is safe before you pay?
Look at where the money is going and how you're being asked to send it. A genuine seller lets you pay on its own website, through a regulated payment gateway, with your bank confirming the payment. A risky one pushes you off the website and into chat, a personal UPI ID or a QR code sent as an image.
Razorpay's guidance for customers is short and practical. Only enter your details on secure sites with an HTTPS connection and valid certificates. Keep your browser and antivirus updated. Don't enter card details on suspicious websites. Read the business's terms, return, cancellation and refund policies before paying. Watch your bank messages and the spam warnings in your UPI app.[1] RBI's fraud booklet adds that phishing sites are built to look like real ones and are spread through SMS, social media, email and messengers, so check the full web address, spelling included, before entering anything sensitive.[4]
A quick five-point check we'd run on any reservation seller, including us:
- Did you type the address yourself, or arrive from a link someone sent you?
- Does the payment page show the seller's own business name and the amount you expect?
- Are there published terms, a privacy policy and a refund policy you can read before paying?
- Is a gateway handling the payment, with your bank's own approval step, rather than a transfer to a phone number?
- Does anything feel rushed? "Pay in five minutes or lose the seat" is pressure, not service.
Which red flags should stop you paying?
| Warning sign | Why it matters | Source |
|---|---|---|
| You're asked to "approve a request" or enter your UPI PIN to get a refund | Entering a PIN sends money. RBI says no PIN or password is ever needed to receive money. | RBI[4] |
| A QR code arrives in chat "for your refund" | Scanning it can authorise a payment out of your account. | RBI[4] |
| "Request money" links by SMS or email from someone you don't know | RBI's complaint portal warns never to respond to them. | RBI CMS[5] |
| Support "executive" asks you to install a screen-sharing app | The app lets them watch or control your phone and see your banking details. | RBI[4] |
| Customer care number is a mobile number found via search results | RBI notes customer care numbers are never mobile numbers and search listings can be faked. | RBI[4] |
| Anyone asks for OTP, PIN, CVV or passwords | RBI lists these among the details imposters pressure people to share. | RBI[4] |
| Payment only to a personal UPI ID or bank account, no website checkout | No gateway, no merchant vetting, and fewer routes to dispute the charge. | Our view |
The last row is our opinion rather than a quoted rule, but it follows from the others. Razorpay says it vets every company using its products and follows KYC norms.[1] A transfer to a stranger's phone number skips all of that.
What protects a card or UPI payment on a proper checkout?
Several layers, none of which you have to set up yourself.
Your bank's own check. Visa explains that when you pay online, your card issuer may ask you to confirm the purchase with a one-time passcode or biometrics, and that sometimes the check runs in the background with only a spinning wheel on screen.[8] The screen asking for that code belongs to your bank. That is why you enter it there, and nowhere else.
The gateway's handling of card data. Razorpay states it does not save sensitive card details, only tokens, and that payment information does not reach a business's servers unless that business is PCI DSS certified.[1] In plain terms, the seller sees that you paid; it does not see your card number.
Monitoring. Razorpay says its fraud detection flags suspicious charges for review and that it monitors payment and refund patterns.[1]
Your right to dispute. Razorpay tells customers they have the right to dispute suspicious charges, and to report fraud to its support team with the transaction details.[1] Its documentation defines a dispute as a customer or issuing bank questioning a payment, for reasons such as unauthorised charges or non-delivery.[2]
Control over saved cards. If you chose to save a card at a Razorpay checkout, Razorpay says you can manage and delete the card details it stores as tokens.[1] For a one-off purchase like a visa reservation, there is little reason to save a card at all.
None of these layers can help if you hand over the key yourself. Sharing an OTP with a caller turns an unauthorised payment into one that looks authorised, and that changes who bears the loss, as the next section shows.
Book on our own checkout
Reservation with a live PNR, paid through Razorpay on our booking page. ₹699 / $9 per passenger.
If money leaves your account without your approval, who pays?
It depends on whose fault it was and how fast you tell your bank. RBI's circular of 6 July 2017 on limiting customer liability sets the framework for unauthorised electronic banking transactions.[3]
| Situation | Your liability under RBI's circular |
|---|---|
| Fraud, negligence or deficiency on the bank's side | Zero, whether or not you reported it[3] |
| Breach elsewhere in the system (not you, not the bank), reported within 3 working days | Zero[3] |
| Same, reported within 4 to 7 working days | Transaction value or the cap in RBI's Table 1, whichever is lower[3] |
| Same, reported after 7 working days | As per your bank's Board-approved policy[3] |
| Loss caused by your negligence, such as sharing payment credentials | The entire loss until you report it; the bank bears losses after the report[3] |
Two further rules help. Once you report, the bank must credit the amount to your account (a "shadow reversal") within 10 working days, without waiting for any insurance claim. And the complaint must be resolved, with your liability established, within the period in the bank's policy and no later than 90 days.[3] The same circular requires banks to have customers register for SMS alerts, which is how most people first spot a debit they don't recognise.[3]
The lesson in the table is speed. Say you notice an unknown ₹4,000 debit on a Friday evening. Reporting it that night, not on Wednesday, can be the difference between zero liability and a capped loss.
What to do if you paid a scammer or see a debit you didn't make
- Call your bank first, using the number on your card or the bank's official website, and block the card or UPI access. Ask for a complaint reference.
- Report to the cybercrime helpline. India's Indian Cybercrime Coordination Centre lists 1930 for reporting cybercrime, alongside the online portal.[6]
- File on the portal. The National Cyber Crime Reporting Portal has a financial fraud complaint route and lets you register and track complaints.[7] You can also use its "Check Suspect" tools to look up a website, mobile number or email before you deal with it.[7]
- Raise a dispute if the payment went through a gateway. Contact the gateway's support with your transaction details, as Razorpay advises for fraud or suspicious activity.[1]
- Keep everything: screenshots of chats, the payment reference, the website address, and the time you reported each step.
- Escalate if needed. If your bank does not resolve the complaint, you can complain under the RBI Integrated Ombudsman Scheme, 2026, through cms.rbi.org.in. RBI's contact centre on 14448 runs an automated line around the clock.[5]
If you are paying from outside India, your own card issuer's dispute process is the starting point. Call the number on the back of your card.
Scams that are specific to visa reservations
Payment fraud is only half the risk. The other half is paying a real amount for a worthless document. Three patterns are worth knowing, and a fourth follows the list:
- PDFs with invented booking references. They look tidy but open nothing on the airline's website. Submitting one can do real damage to a visa file. See why "free ticket generators" are risky.
- "Confirmed ticket" claims at reservation prices. A paid, issued ticket costs a fare. Anyone selling one for the price of a reservation is describing something else.
- Sellers who vanish after payment. No website, no policies, just a chat account. Our guide on avoiding reservation scams lists more signs, and the provider checklist gives questions to ask first.
A fourth pattern borrows trust from people you know. RBI describes fraudsters creating fake social media profiles and messaging a user's friends for urgent payments; its advice is to confirm any such request by phone or in person, and not to pay unknown people online.[4] In visa season that can look like a message from a "friend" or "agent" who says they'll book your reservation if you send money to their UPI ID right now. Call the person on a number you already have before sending anything.
The protection here is simple. Whoever you buy from, check the booking reference yourself on the airline's "Manage booking" page before you submit it. Our verification guide shows the steps, and the sample reservations page shows what a genuine one from us looks like.

How paying us works, briefly
You place the order on our booking page and pay on the Razorpay checkout that opens there, by UPI, card or netbanking. Nobody, us included, needs your OTP, PIN or CVV over chat or a phone call; if someone claiming to be us asks for them, stop and message our listed WhatsApp number or email instead. The reservation is emailed in about 10 minutes, and you can follow an order on the tracking page.
Prices are per passenger, one way or round trip (see the price page). A reservation stays valid for up to two weeks, and the airline decides the exact period, so pay close to your appointment rather than weeks ahead. For what a reservation is and isn't, read flight reservation for visa; for destination rules, see requirements by country, the Schengen guide and onward tickets. Failed payments and refunds are covered in the payment methods guide, and data handling in our privacy guide.
Payment safety questions
Is it safe to pay for a dummy ticket online?
It can be, if you pay on the seller's own HTTPS website through a recognised payment gateway, with your bank's approval step, and never share an OTP or PIN with anyone. The risk lies with sellers who ask for transfers to personal UPI IDs, send QR codes in chat, or sell documents whose booking reference doesn't open on the airline's site.
Someone asked me to enter my UPI PIN to receive a refund. Is that normal?
No. RBI states that receiving money never requires entering a PIN or password or scanning a QR code. If an app asks for your PIN, you are sending money, not receiving it. Decline the request, don't scan anything, and contact the seller only through details on its official website.
What should I do first if I've been scammed?
Call your bank on its official number and block the card or UPI access, then report on 1930 or cybercrime.gov.in. Speed matters: under RBI's rules, reporting a third-party breach within three working days of the bank's alert means zero liability, while delays can leave you bearing part of the loss.
Will my bank refund an unauthorised transaction?
Under RBI's 2017 circular, the bank must shadow-credit the amount within 10 working days of your report and settle the complaint within 90 days. Whether you bear any loss depends on fault and reporting speed. If you shared your OTP or credentials, you carry the loss until you report it.
Does a seller see my card number when I pay?
Not on a checkout like Razorpay's. Razorpay says it doesn't save sensitive card details, only tokens, and that payment information doesn't reach a business's servers unless that business is PCI DSS certified. Your bank's verification screen, with OTP or biometrics, is shown by the issuer, not the seller.
How can I check a website before paying?
Type the address yourself, look for HTTPS and the correct spelling, read the published policies, and check that payment runs through a gateway. India's National Cyber Crime Reporting Portal also offers a "Check Suspect" tool for websites, phone numbers and email addresses that have been reported.
Where can I complain if my bank doesn't help?
Through the RBI Integrated Ombudsman Scheme, 2026, at cms.rbi.org.in, after raising it with your bank. RBI's contact centre on 14448 has a 24-hour automated line, with staff available Monday to Saturday, except national holidays, from 8 am to 10 pm.
Honesty note: a reservation is not a paid ticket and cannot be flown. No seller can promise that a visa will be granted; the consulate decides.
Sources
All sources last checked: October 2026.
- Razorpay Docs, Security for customers.
- Razorpay Docs, About disputes.
- Reserve Bank of India, Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions. Circular RBI/2017-18/15, 6 July 2017
- Reserve Bank of India, Office of the RBI Ombudsman, BE(A)WARE: a booklet on the modus operandi of financial fraudsters (PDF).
- Reserve Bank of India, Complaint Management System: Reserve Bank Integrated Ombudsman Scheme, 2026.
- Indian Cybercrime Coordination Centre (I4C), Ministry of Home Affairs, I4C home page (report a cybercrime on 1930).
- Ministry of Home Affairs, National Cyber Crime Reporting Portal.
- Visa, Visa Secure.
Related: flight reservation for visa · dummy ticket price · requirements by country · how to verify a PNR.