The product is the string
A digital gift card has no physical existence and no additional security layer. There is an account in the issuer’s system with a balance, and there is a code that unlocks it. Whoever holds the code holds the money. There is no ownership record, no registration tying it to your name, and nothing to prove it was ever yours.
This is the same bearer model as a plastic card, but stripped of the friction that made plastic mildly safer. A physical card has to be handed over. A code can be forwarded, screenshotted, pasted into a chat, and copied by anyone with momentary access to an inbox — all without leaving any trace that it happened.
Delivery is the part that actually fails
The load almost always succeeds. Delivery is where digital cards break. Codes go to mistyped addresses and are effectively gone, because someone else now has a working credential and no reason to mention it. They land in spam filters. They are held by the retailer’s fraud screening, sometimes for a day or more, while an unfamiliar order is reviewed.
That last one undermines the main reason people buy digital. "Instant" is a marketing claim, not a service commitment, and the orders most likely to be queued are exactly the ones bought in a hurry: a first purchase from that retailer, a large amount, a delivery address that does not match billing. If a gift has a fixed deadline, do not leave an e-card to the final hour.
Why forwarding the email is the wrong move
The instinct on receiving a code you want to pass on is to forward the email. This leaves a live credential sitting in two mailboxes and every server between them, indefinitely, in plain text. Email archives are searched during account compromises precisely because they are full of things like this.
Better: redeem the code into an account immediately, so the value moves from a bearer string to a balance attached to a login with a password behind it. If you must pass a code to someone else, use the retailer’s own resend-to-recipient function where it exists, and delete the message afterwards rather than leaving it archived.
The recovery position is weak
If a code is used by someone else, you are relying on the issuer’s discretion rather than any right. From their side the transaction looks entirely legitimate: a valid code was presented and honoured. There is no unauthorised-transaction process here comparable to a debit card dispute, because gift products sit outside those rules.
What occasionally works is speed and documentation. The original order confirmation, the delivery timestamp, and the redemption time can sometimes support a goodwill reissue, particularly where redemption happened somewhere implausible. Keep the order confirmation — for a digital card it is the entire evidentiary record.
Handling codes sensibly
Redeem on arrival rather than on need. A code sitting unredeemed in an inbox for three months is exposure with no benefit; the same value inside an account is protected by that account’s security. This one habit removes most digital gift card risk.
Never store codes in notes apps synced without a passcode, in photo libraries, or in chat threads. And if a code arrives from someone you were not expecting a gift from, treat it as a phishing lure rather than good fortune — unsolicited codes are a standard opening move.