WolfSellers — Adobe Experience Cloud Partner en México

Article

Ecommerce Checkout for Mexico: Addresses, CFDI and Payments

How to design an ecommerce checkout for Mexico: colonia and postal code, phone numbers, CFDI invoicing, payment methods, shipping and Adobe Commerce setup.

By WolfSellers··15 min read
Ecommerce Checkout for Mexico: Addresses, CFDI and Payments
On this page

In an online store, checkout is where the sale is confirmed or lost: the customer has already chosen and only needs to tell you where to ship and how they'll pay. In Mexico, that last stretch has pieces a US or Canadian form doesn't include: the colonia (the neighborhood or settlement), a postal code that doesn't always pin it down, 10-digit phone numbers, the CFDI (Mexico's mandatory electronic invoice) and payment methods like interest-free installments or cash at convenience stores.

Timing matters. El Buen Fin 2026, Mexico's nationwide sales event, runs November 13–17 according to its official site, and it's when the most traffic reaches the last step. A rejected colonia, a badly validated tax ID or a shipping cost that only appears at the end goes unnoticed in a normal month; at volume, it's lost sales. And any checkout change needs weeks of testing.

At WolfSellers we implement Adobe Commerce (formerly Magento) for brands that sell in Mexico. This guide covers addresses, invoicing, payments, shipping, hosted checkout, what the law requires, the Adobe Commerce setup and what to measure. For the broader picture —platforms, payments and logistics— see our guide to ecommerce in Mexico.


What checkout is and what makes it different in Mexico

Checkout is the process an online store uses to turn a cart into an order: it captures contact details, the delivery address, shipping, payment and, in Mexico, invoicing data when the customer asks for an invoice. It ends when the customer sees their order number.

What changes in Mexico comes down to five pieces:

Piece What the customer expects What it means for the store
Address Colonia, interior number, cross streets and delivery notes, on top of street, postal code and state Fields that US and Canadian forms don't have
Phone Their 10-digit number Validating the national format
Invoice Requesting a CFDI at checkout or later Optional, validated tax fields
Payment Interest-free installments (meses sin intereses), cash at stores, SPEI bank transfers, wallets Orders created before payment and bank-specific promotions
Delivery Home delivery or in-store pickup, with cost and date before paying Cost and delivery promise by postal code

How to capture a Mexican address without errors

The best reference for the form is the Technical Standard on Geographic Addresses (Norma Técnica sobre Domicilios Geográficos) from INEGI, Mexico's national statistics and geography institute, published in the Official Gazette (DOF) on November 22, 2024. It binds government agencies, not businesses, but it sets out the components of an address: street, exterior number, interior number, settlement —colonia, barrio or fraccionamiento—, postal code, locality, municipality (a borough, or alcaldía, in Mexico City) and state. As optional components it adds the cross streets, the street behind the property and a location description: what a checkout calls delivery notes (referencias).

Field Required? How to validate or autocomplete it Typical mistake
Postal code Yes Five digits; fills in state and municipality and lists the colonias Storing it as a number: 06700 becomes 6700
Colonia Yes List of the settlements for that code, plus "my colonia isn't listed" Free text: the same colonia spelled ten ways
Street Yes Free text that accepts accents, ñ and abbreviations Validation that rejects Spanish characters
Exterior number Yes, except addresses with no number Letters and symbols A numeric field that rejects "120-B"
Interior number No Free text: apartment, suite, tower Merging it with the exterior number
Municipality or borough Yes Filled in by the postal code Asking for "city" and getting the colonia
State Yes Filled in by the postal code Matching it to the platform by name instead of by code
Cross streets (entre calles) No Two text fields Making it required
Delivery notes (referencias) No Short text: facade, gate, nearby shop Not printing them on the shipping label

Autocompleting with the postal code catalog

Mexico's postal service, Correos de México, publishes the National Postal Code Catalog for free, in Excel, pipe-delimited text or XML, by state or for the whole country. The page shows its last update —October 6, 2026, as we write this—, so download it again regularly. Each record is a settlement with its postal code, name, type (colonia, barrio, fraccionamiento…), municipality, state, city, urban or rural zone and INEGI codes.

A postal code doesn't identify a colonia. In Correos de México's lookup, Mexico City's 03100 maps to two colonias; Mérida's 97000, to eight settlements; and 29950 in Ocosingo, Chiapas, to 106. The flow we recommend:

  1. The customer enters the postal code.
  2. The store fills in state and municipality and lists the colonias; if there's only one, it's preselected.
  3. If their colonia isn't listed —the catalog can lag behind a new development—, they type it in.
  4. Don't rely on the city field: it's empty for many settlements, such as all 17 under 71230 in Santa Cruz Xoxocotlán, Oaxaca; the municipality is filled in.

State names in the catalog don't match Adobe Commerce's ("Coahuila de Zaragoza" vs. "Coahuila", "México" vs. "Estado de México"), so map them with a code table.

10-digit phone numbers

Since August 3, 2019, every Mexican number, landline or mobile, is dialed with 10 digits, and the 01, 044 and 045 prefixes are gone, according to the Federal Telecommunications Institute (IFT), the regulator at the time. One 10-digit field is enough, with no separate area code, stripping spaces and dashes on save; for SMS or WhatsApp, also store it with +52, Mexico's country code. If someone else receives the order, ask for their name and phone.

Invoicing at checkout: what to ask for a CFDI 4.0

The CFDI is Mexico's electronic invoice, regulated by the tax authority (SAT). To issue one in the customer's name, the Federal Tax Code (Código Fiscal de la Federación, Art. 29-A, sec. IV) requires their RFC (taxpayer ID), name or legal name, tax-address postal code and the intended use of the invoice; the 2026 Miscellaneous Tax Resolution (Resolución Miscelánea Fiscal, RMF, rule 2.7.1.29) adds their tax regime. At checkout:

  1. First, ask whether they want an invoice, with a checkbox that reveals the fields. Asking everyone for an RFC adds friction and data you don't need.
  2. RFC: 13 characters for individuals and 12 for companies, per the SAT's Annex 20 filling guide. Validate structure and length as they type.
  3. Name or legal name, exactly as registered with the RFC; customers find it on their Constancia de Situación Fiscal (the SAT's tax status certificate).
  4. Tax postal code: Annex 20 requires it to match the RFC. Don't copy it from the shipping address.
  5. Tax regime and CFDI use, as lists from the SAT catalogs, with uses filtered by regime, because they must be compatible. If the use is wrong, the SAT says the invoice must be cancelled and replaced.
  6. How it was paid. The CFDI records the payment form with a SAT code (01 cash, 03 transfer, 04 credit card…). For cash or SPEI, invoice once payment is confirmed; before that, you'd have to use code 99 "to be defined" and later issue a payment complement (rule 2.7.1.29).

Offer to save several tax profiles: one person may invoice under their own name and their company's.

If they don't request an invoice, the sale can be covered by a global invoice: RMF 2026 rule 2.7.1.21 allows a daily, weekly or monthly CFDI for sales to the general public, using the generic RFC XAXX010101000 (rule 2.7.1.23), sent to the SAT or the certification provider no later than 24 hours after the period closes.

If they request it later, you need self-invoicing by order number. If the sale already went into a global invoice, the SAT's guide for that document describes two paths: a related credit-type CFDI (egreso) followed by the named invoice, or cancelling the global invoice and reissuing it without that sale; your tax team decides the deadline and the path. In the design we recommend, the store captures and validates, and the ERP issues: see our guide to integrating Adobe Commerce with an ERP.

Abstract layered payment methods flowing through digital interface

Payment methods: how to present them at checkout

Which methods to offer, how interest-free installments work and when to request 3-D Secure are covered in our guide to payment gateways in Mexico. Here's how to present them:

  1. Installments from the product page and cart, and at payment only the terms offered by that card's bank, identified by its first digits (the BIN).
  2. Cash with complete instructions: reference, amount, where to pay (convenience stores such as OXXO) and deadline, on screen and by email, plus a reminder before it expires.
  3. SPEI with a reference or CLABE per order (SPEI is Mexico's real-time interbank transfer system, run by Banco de México; the CLABE is the account number it uses), so reconciliation doesn't depend on the memo the customer types.
  4. The bank challenge, announced: if the issuer requests 3-D Secure, warn that a confirmation may arrive in their banking app or by SMS.
  5. Errors that say what to do: "Your bank declined the charge; try another card or pay in cash."
  6. Saved cards only through the gateway's token, never with the card number in your database.
  7. Most-used methods first, based on your data by device.

Shipping and in-store pickup

Mexico's Federal Consumer Protection Law (LFPC) requires that, in distance sales, the merchant disclose the price, approximate delivery date and insurance and freight costs beforehand (Art. 53, sec. IV), and make sure delivery happens at the customer's address or that the customer is fully identified (sec. I). At checkout:

  • Shipping cost from the cart, calculated with the postal code; if free shipping starts at an amount, say how much is left.
  • Estimated date per method, not just the carrier's name.
  • Real quotes before payment, if your carrier charges certain postal codes differently.
  • In-store pickup as one more delivery method, with the nearest store and real availability; see our click and collect guide. If someone else picks up, ask for their name.
  • Delivery notes and cross streets on the shipping label: if they don't reach the carrier, they're useless.

Own, hosted or hosted-fields checkout: which one fits

There are three ways to capture the card, and each one changes the experience, brand control and your scope under PCI DSS, the card industry's security standard:

Model Experience Brand control Typical PCI scope When it fits
Own checkout with direct API (the card passes through your server) Full Full SAQ D, the most demanding Rarely; requires a mature security program
Own checkout with hosted fields or iframe (the provider captures the card inside your page) Stays on your site High SAQ A or A-EP, depending on the implementation; with an iframe, script protection or the processor's confirmation Our recommendation when experience matters
Hosted (redirect to the provider's page, sometimes "white-label") Leaves your site to pay Whatever the provider allows The smallest; the SAQ A script criterion doesn't apply to redirects To launch fast or with a small security team

A Qualified Security Assessor (QSA) makes the final classification; details are in our note on PCI DSS 4.0.

How to choose a white-label checkout

A white-label checkout is a payment page, or a full checkout, run by a provider under your store's visual identity. There's no single best option; these are the criteria we use to compare them:

  1. Complete Mexican address, if it also captures the address: colonia, interior number and delivery notes.
  2. Invoicing: you can collect tax data before redirecting, or the provider returns it to you. The invoice is issued by your ERP or invoicing provider, not by the payment page.
  3. Local methods: installments by bank, cash with a reference and SPEI.
  4. Approval: whether it processes with a Mexican acquirer, how it handles 3-D Secure and what data it sends to the issuer. Ask for approval rates by issuer and method, and test them with your traffic.
  5. Brand and experience: what you can change and how it looks on mobile.
  6. Measuring each step inside the hosted page.
  7. Adobe Commerce integration: a maintained module for your version or an API, with signed notifications and reconciliation reports.
  8. Peak-season support, with someone who answers on El Buen Fin night.

Abstract transparent layers revealing verified compliance information

What customers must see before paying, under Mexican law

This is what the LFPC, last amended in the DOF on December 12, 2025, and Mexico's data protection law require. It isn't legal advice: validate your checkout with Mexican counsel, especially if you sell from the US or Canada.

  • The total amount, prominent and visible, including taxes, fees, interest, insurance and any other charge (Art. 7 Bis).
  • Price, approximate delivery date and insurance and freight costs (Art. 53, sec. IV).
  • Your physical address, phone numbers and channels for complaints, plus terms, conditions, costs, extra charges and payment methods (Art. 76 Bis, secs. III and V). The returns policy is covered in our reverse logistics guide.
  • Respecting their choice not to receive advertising (Art. 76 Bis, sec. VI): we recommend a separate, unchecked box.
  • Recurring charges, if you sell subscriptions: frequency, amount and charge date, with express and informed consent (Art. 76 Bis, sec. VIII).
  • The short-form privacy notice where data is collected, linking to the full notice (Art. 16 of the LFPDPPP, Mexico's private-sector data protection law); details in our note on data protection.

How to configure checkout in Adobe Commerce

Adobe Commerce ships a two-step checkout —shipping, then review and payments— that allows guest checkout by default. What we adjust for Mexico, per Adobe's documentation:

  1. Guest checkout, under Stores > Settings > Configuration > Sales > Checkout > Checkout Options: we keep it on, and customers can create an account afterward. Terms and conditions are enabled there too.
  2. States. All 32 federal entities (31 states and Mexico City) come as a dropdown; under General > State Options, confirm that the state is required for Mexico.
  3. Colonia, municipality, cross streets and delivery notes. The form includes street, city, state, postal code, country and phone, among others, but no colonia or municipality. They're added as attributes under Stores > Attributes > Customer Address, a feature exclusive to Adobe Commerce (on Magento Open Source, with an extension or custom development). The colonia can be a list fed by the catalog, and the municipality can go in the city field.
  4. Validation. Per the documentation, Alphanumeric and Alpha Only accept letters a–z: test them with names like Coyoacán or Peñón before enabling them. Street, city and phone also have system validation that can't be turned off in the Admin.
  5. Phone and company, required or optional, under Customer Configuration > Name and Address Options.
  6. Address Templates, so the colonia and delivery notes appear on printed order documents.
  7. Shipping by postal code. Table Rates doesn't accept postal code ranges: it's a wildcard per state or one row per code. With many exceptions, integrate your carrier's rate quotes.
  8. Payments. Adobe's Payment Services lists Mexico among its fully supported countries; for cash, SPEI or bank-specific installments you usually need a local gateway.
  9. Edge Delivery Services storefront. Its checkout component supports custom address attributes and has a container that shows the address suggested by a third-party verification service.

What to measure in checkout

Metric What it measures What decision it informs
Step progression Who moves from address to shipping, payment and confirmation Where to focus the next change
Errors by field How often each field fails, and with what message Which validation to fix
Manually typed colonias Orders with a colonia outside the catalog Whether the catalog is current
Invoices requested and rejected How many request a CFDI and how much data fails What to validate earlier
Payment approval Approved payments by method, issuer and device Gateway, 3-D Secure and method order
Paid references Cash and SPEI payments completed on time Reference validity and reminders
Failed deliveries due to address Labels returned for incomplete addresses Which fields to reinforce

Each step and error must be sent to your analytics as an event; see our note on CRO for ecommerce.

Connected nodes with broken pathway connections in abstract 3D

Common mistakes

  1. Copying a US address form, with no colonia or interior number.
  2. Asking for the colonia as free text, or forcing the catalog with no "my colonia isn't listed" option.
  3. Storing the postal code as a number and losing the leading zero.
  4. Requiring an RFC from every customer, or copying the tax postal code from the shipping address.
  5. Showing shipping costs or fees only at the last step.
  6. Offering installments the customer's bank doesn't support.
  7. Redirecting to a hosted checkout without collecting invoicing data first.
  8. Changing checkout during El Buen Fin week, with no time to test at volume.

How we do it at WolfSellers

We start by diagnosing your current checkout: the funnel by step, errors by field, addresses carriers send back and invoices that couldn't be issued. With that we prioritize changes and test them before they reach production.

Then we implement in Adobe Commerce the Mexican address with the postal code catalog, tax data capture connected to the ERP, payments, shipping and measurement of every step. We cover it in our Adobe Commerce, CRO, ERP integration, frontend and UX and QA and testing services. To review your checkout before El Buen Fin, you can contact us; if you're choosing an implementation partner, see how we work as an Adobe partner in Mexico.


Frequently asked questions about checkout for Mexico

What fields should a Mexican address have at checkout?

Street, exterior number, interior number, colonia, postal code, municipality or borough and state, plus two optional fields that help delivery: cross streets and delivery notes. That's the order set out in INEGI's Technical Standard on Geographic Addresses.

Where can I download Mexico's postal code catalog?

From Correos de México's postal code download page, for free, in Excel, text or XML, by state or for the whole country. It lists each settlement with its postal code, type, municipality and state, and shows the date of its last update. Its notice prohibits reselling it.

How is the Correos de México catalog different from the SAT's postal code catalog?

Correos de México's catalog is for addresses: it maps each postal code to its colonias, municipality and state. The SAT's catalog (c_CodigoPostal, from Annex 20) is for invoicing, for example for the place of issue. And the customer's tax postal code must be the one tied to their RFC, not the shipping one.

Do I have to ask for an RFC at checkout in Mexico?

No. Without the customer's RFC, the sale is treated as a transaction with the general public and can be covered by a global invoice, with the generic RFC XAXX010101000. Ask for tax data only from customers who want an invoice: RFC, name or legal name, tax postal code, tax regime and CFDI use.

How many digits does a Mexican phone number have?

Ten, for landlines and mobiles, since August 3, 2019, when the 01, 044 and 045 prefixes were dropped. A single 10-digit field is enough at checkout; for SMS or WhatsApp, also store it with +52.

Which white-label checkout provider is best for an ecommerce business in Mexico?

There's no single best one: it depends on your payment methods, volume and team. Compare them on criteria: complete Mexican address, invoicing data, installments by bank, cash and SPEI, processing with a Mexican acquirer, customization, step-by-step measurement and integration with Adobe Commerce.

Does Adobe Commerce include colonia and municipality fields?

It includes Mexico's 32 federal entities as a dropdown, but no colonia or municipality fields. In Adobe Commerce they're added as address attributes from the Admin; on Magento Open Source, which lacks that feature, with an extension or custom development.

If this topic is relevant to your business, these services from WolfSellers can help you implement it:

Want to dive deeper?

Let's talk.

We're an Adobe Gold Partner in Mexico with experience in Adobe implementations and integrations. If anything in this article applies to your operation, the first consultation is on us.

Or email us at contacto@wolfsellers.com

Keep reading

Chat with us on WhatsApp