UPI's New Safety Rules in 2026 — What Protects You Now, and What Still Doesn't
UPI moves more money in India than any payment system in history — and fraudsters moved with it. Official figures show UPI-related frauds of about ₹805 crore across 10.6 lakh incidents in just April–November 2025. In response, NPCI and RBI have rolled out a series of rule changes through 2025 and 2026 that quietly make everyday payments safer. Here is what changed, and where you still have to protect yourself.
What the new rules do for you
1. You now see the real, bank-verified name before paying
Since 30 June 2025, UPI apps must show only the banking name of the receiver — fetched directly from the bank via NPCI's validation API — on the payment confirmation screen, not a nickname or a name typed by the receiver. A scammer can no longer set their display name to "SBI Refund Desk".
Pause on the confirmation screen and read the verified name. If you're paying "Amit Electronics" and the name shows an unrelated individual, stop. This two-second habit defeats most impersonation payments.
2. Higher limits — but only where they make sense
Person-to-person transfers remain capped at ₹1 lakh per day. But verified merchants in specific categories — tax payments, education fees, healthcare, IPO and RBI retail schemes — can now accept much larger UPI payments, in some categories up to ₹10 lakh. The higher limits apply only to verified, whitelisted merchants, so a fraudster posing as an individual cannot use them against you.
3. Stronger two-factor authentication
From April 2026, UPI transactions must carry two-factor authentication that includes at least one dynamic factor (something generated fresh for that transaction, not just your static PIN). Apps are rolling this out through 2026 — expect device biometrics or on-device checks alongside your PIN, especially for larger payments.
4. Cleaner background traffic, fewer failures
NPCI has also moved recurring payments (autopay for SIPs, subscriptions, EMIs) into off-peak processing windows and limited balance-check API abuse, which means fewer "payment pending" states — the confusion scammers exploit to say "it failed, pay again".
5. Banks are moving to bank.in domains
Under an RBI directive, Indian banks are migrating their websites to the exclusive .bank.in domain (for example, a genuine bank site would end in bank.in). Migration is still uneven, but as it completes, one glance at the address bar will separate real banking sites from phishing clones.
What the rules still can't stop
Every rule above hardens the system. But most UPI fraud never breaks the system — it convinces you to authorise the payment. These still work in 2026:
| Scam | Why rules don't stop it |
|---|---|
| "Wrong payment, please refund" collect request | You genuinely authorise the send — verified name and all |
| QR code to "receive" money | Scanning + PIN always sends; no rule changes that |
| Screen-share apps ("bank support") | The fraudster watches you authenticate legitimately |
| Digital-arrest and fear calls | Payment is voluntary, so every safeguard is bypassed |
| Fake trading app deposits | You are intentionally paying a real (mule) account |
The golden rule survives every rule change: receiving money never requires your PIN, a QR scan, or approving a request. Anyone who says otherwise is running a script.
If something goes wrong
- Call 1930 (Cyber Crime Helpline) immediately — reporting within the first hour gives the best chance of freezing the money mid-transfer.
- File at cybercrime.gov.in and note the acknowledgement number.
- Report in your UPI app and to your bank's fraud helpline; under RBI's zero-liability rules, unauthorised transactions reported within 3 working days can qualify for full protection.
Frequently asked questions
The verified name doesn't match what the seller told me. Should I pay?
No — stop there. The name now shown is the one registered with the bank, not a nickname the recipient chose, so a mismatch is a real signal rather than a display quirk. Some legitimate mismatches exist: a shop trading under a brand name while the account is in the proprietor's name, or a spouse's account. Ask, verify by another route, and only then pay. This screen is the single most useful anti-fraud change in years, and it works only if you actually read it.
Do the higher limits apply to me automatically?
Not to everything. The raised limits attach to specific categories — certain verified merchant payments, tax, insurance and similar — rather than lifting the everyday person-to-person ceiling across the board. Your bank may also set its own limit below the network maximum. If you need to move a large amount, check your bank's UPI limit in the app first, and consider whether RTGS or NEFT is the better instrument.
Should I lower my UPI limit?
For most people, yes. Banking apps let you set a daily UPI limit well under the default, and matching it to what your life actually requires caps the damage of a single bad minute. It costs nothing, takes a couple of minutes, and is the most effective setting available to you — especially worth doing on the phones of elderly parents.
Are the new rules enough to stop UPI fraud?
No, and it is important to be clear about this. The upgrades close technical gaps — payee ambiguity, weak authentication, background traffic — but essentially every large UPI fraud today runs on social engineering: convincing you to approve a payment yourself, or to share a PIN or OTP. No network rule can prevent an authorised transaction. The golden rule still carries most of the weight: your PIN is only ever needed to send money, never to receive it.
What is the bank.in domain change about?
RBI has been moving Indian banks onto a dedicated bank.in domain so that a genuine bank website is identifiable from its address alone. As adoption spreads it will make phishing pages materially harder to pass off, because a convincing lookalike domain will no longer sit alongside the real one. In the meantime, keep reaching your bank through its app or a bookmark rather than through links in messages.
Is UPI Lite safe without a PIN?
Yes, by design — the protection is the cap rather than the PIN. UPI Lite holds a small balance separate from your bank account for low-value payments, so the most anyone can take is that small amount. Use it for everyday spending and keep your main account behind the PIN.
I approved a payment by mistake. Can I reverse it?
Not unilaterally — UPI transfers are designed to be final. Raise a dispute in your UPI app against that transaction, escalate to your bank with the UTR reference, and if it is still unresolved after 30 days go to the RBI Banking Ombudsman at cms.rbi.org.in. If it was fraud rather than an error, call 1930 immediately instead — see our guide to the first 60 minutes.
The bottom line
2025–26 brought the biggest safety upgrade in UPI's history: verified payee names, purposeful limits, and dynamic authentication. Use the verified-name screen religiously, keep the golden rule, and the remaining risk shrinks to almost zero — because in UPI fraud, the last line of defence was never NPCI. It is the three seconds before you press "Pay".
How this guide is made
Written and fact-checked by the Awareness360 editorial team from primary sources — RBI, SEBI, IRDAI, the Income Tax Department and Government of India portals — with links to the originals in the text above. Last reviewed on 1 Jul 2026. This is general educational information for Indian readers, not professional financial, legal or tax advice.
Spotted something out of date? Tell us and we'll correct it — see our editorial policy.