Pay without handing over your card
Know which card details let someone send you money and which let them spend it, check a payment page before you type, and read the one-time code message properly.
TWO KINDS OF DETAILS
Details to receive, details to spend
To send you money, someone needs only your card number or your account number (IBAN). That's it. Everything else on or around your card is for spending: the security code on the back (CVV2), the expiry date, your password and any one-time code. Nobody ever needs those to pay you.
A buyer who says "enter your expiry date and the code we just texted you so I can deposit the money" is asking for spending details. Whatever the story, the answer is no.
Check yourself
Arash is selling his bike on an online marketplace. A buyer agrees the price without haggling and sends a link: "to receive the money, open this and confirm your card." The page asks for his card number, CVV2, expiry and one-time password. What should Arash do?
- Fill it in, but only if the page shows a padlock and his bank's logo
- Fill in the card number and CVV2 but leave the password blank, to be safe
- Close it and send only his card number or IBAN as a text message
- Ask the buyer to call him and read the details out on the phone instead
Show the answer
Close it and send only his card number or IBAN as a text message
Right. Receiving money never needs spending details. A page that asks for them to "receive" a payment is built to take money out, not put it in.
Payment gateway
The page where you actually type your card details when you buy something online. The shop sends you there, the gateway talks to your bank, then sends you back. In Iran, genuine card payment pages are run through Shaparak, and their address ends in shaparak.ir right before the first single slash. Elsewhere, the page usually belongs to the shop, a known payment company or your own bank.
https://sep.shaparak.ir/… ends in shaparak.ir. https://shaparak-pay.com/… and https://shaparak.ir.pay-online.net/… do not: the first ends in shaparak-pay.com, the second in pay-online.net.
Five seconds before you type a card number
- How did you get here?
From a shop you opened yourself: fine so far. From a link in an SMS, a chat or an ad: stop. Open the service yourself instead.
- Read the address, not the logo
Find the part right before the first single slash. For an Iranian card payment it must end in shaparak.ir. Logos and colours are free to copy.
- Check the shop name and amount
A real gateway shows who you are paying and how much. If either is wrong or missing, leave.
- Be careful inside apps
A payment page opened inside a messenger or an app's built-in browser may hide the address bar. If you can't see the address, you can't check it.
Check yourself
Does this Iranian payment address pass the check?
- https://sep.shaparak.ir/payment
- https://shaparak-ir.com/pay
- https://shaparak.ir.pay-online.net/card
- https://pec.shaparak.ir/NewIPG
- https://shaparrak.ir/ipg
- https://my-bank.ir/shaparak.ir/pay
Show the answer
Passes the check: https://sep.shaparak.ir/payment, https://pec.shaparak.ir/NewIPG
Fails the check: https://shaparak-ir.com/pay, https://shaparak.ir.pay-online.net/card, https://shaparrak.ir/ipg, https://my-bank.ir/shaparak.ir/pay
Why one-time codes help, and where they don't
A fixed password
The same every time. If a fake page captures it once, it works again and again until you change it.
A one-time code
Made for one payment and valid for a short time. The message usually says the amount and the shop. It protects you only if you read that message before you type the code.
Check yourself
Mina is buying mobile credit through a link someone sent her. She asks for a one-time code, and the message shows a much bigger amount and a shop she has never heard of. It's safe to type the code, because it came from her own bank.
Show the answer
False
The code is genuine, but the payment it approves isn't hers. The mismatch means someone is using her card details for their own purchase right now. She should not type it, and should call her bank to block the card if she already entered her details.
Everyday payment habits
- Turn on your bank's SMS or app alerts, so you see every payment the moment it happens.
- Keep a separate card with a small balance for online shopping, and move money onto it when you need it.
- Only save your card on sites and apps you use often and trust.
- Open shops and your bank yourself, from a bookmark or the official app, not from links.
- If you think your card details leaked, call your bank and block the card first. Ask questions after.
Check yourself
Hamid's cousin abroad, Laura, wants to send him money for his birthday. She messages: "Send me a photo of both sides of your card so I get the numbers right." What is the best reply?
- Send only the front, since the security code is on the back
- Type out just the card number or IBAN and send that
- Send both sides, because she's family and the chat is private
- Send both sides, then delete the photo from the chat once she has it
Show the answer
Type out just the card number or IBAN and send that
Yes. The card number or IBAN is all she needs. A photo carries more than you mean to share, and a chat can be read by whoever gets into either phone.
Lesson recap
- To pay you, people need only your card number or IBAN. CVV2, expiry, passwords and codes are for spending.
- Before typing card details, read the address: for Iranian card payments it must end in shaparak.ir right before the first slash.
- A padlock means encrypted, not honest.
- Read the one-time code message: if the amount or shop is wrong, don't type it and call your bank.