How to spot a scam text or email, and what to do if you replied
Scam messages change their stories all the time, but they need the same few things from you: to act before you think, to keep it to yourself, and to pay or hand over details in a way that cannot be taken back. Learn those, and most scams give themselves away.
The signs that matter most
- A rush. “Within 24 hours”, “final notice”, “or your account will be closed”. Pressure is there so you act before you check.
- Secrecy. “Don't tell anyone”, “keep this between us”. Real banks, employers and relatives do not need you to hide a payment.
- Payment that cannot be undone. Gift cards, cryptocurrency, wire transfers and payment apps. No real business or government office asks to be paid in gift cards.
- Codes and passwords. A verification code sent to your phone is the key to your account. Nobody genuine will ever ask you to read one back.
- Threats. Arrest, a warrant, a fine, legal action or a suspended account — especially when paired with a way to make it go away today.
- A link or number to use instead of the usual way in. The message is only useful to a scammer if you use the contact details in it.
One sign on its own proves little — a real delivery company does send texts. Several together, especially a rush plus an unusual payment or a request for a code, is the pattern to stop at.
How links are disguised
What decides who owns a website is the part of the address just before the ending, not the words at the start. Reading from the right:
- www.paypal.com belongs to paypal.com.
- paypal.com.account-review.help belongs to account-review.help — “paypal.com” is just a word at the front.
- usps.redelivery-check.top belongs to redelivery-check.top, not the US Postal Service.
- paypa1.com and amaz0n-support.net swap a letter for a number that looks like it.
- Shortened links such as bit.ly/… hide the destination completely.
- In an email, the words of a link can show one address while the link itself goes to another. On a computer, rest the pointer on the link (without clicking) to see the real address; on a phone, press and hold it.
The Scam Message Checker does this reading for you: it takes each link apart, and when you paste from an open email it also reads the real addresses hidden behind the words.
The stories they tell
- A parcel that cannot be delivered until you update your address or pay a small fee.
- An unpaid toll or parking fine with a deadline.
- Your bank or account: unusual activity, a locked account, a payment you did not make — with a link to “verify”.
- “Hi Mum” or “Hi Dad”: a child on a new number who needs money today and would rather you did not call.
- Tech support: a virus warning and a number to call, leading to a request to connect to your computer.
- A job that pays well for little work, but needs a fee, equipment or a cheque deposited first.
- An investment with guaranteed returns, often after weeks of friendly chat with someone you met online.
- A tax office or government agency threatening arrest over money owed.
- A prize, refund or rebate you only need to pay a fee or give card details to collect.
The one check that always works
Contact the company or the person yourself, using details you already have — the app, the number on your card or statement, a website you type in, the number saved in your phone. Never use the link or number in the message. If it was real, you will find the same thing waiting when you log in the usual way. A checker can point out warning signs, but a well-written scam can have none of them; this check is the one that cannot be fooled.
If you already replied, clicked or paid
- Paid by card, bank transfer or payment app: call the card issuer, bank or app company straight away, say it was fraud and ask for the payment to be reversed.
- Bought gift cards: contact the company that issued them, say they were used in a scam, and keep the cards and receipts.
- Sent crypto or a wire transfer: contact the exchange or transfer company now. These are hard to reverse, so time matters.
- Gave a password or code: change the password (and anywhere you reused it), turn on two-step verification, and check the account for changes.
- Gave personal details: in the US, IdentityTheft.gov gives a recovery plan; anywhere, watch your accounts and consider a credit freeze.
- Let someone onto your computer: disconnect it, run your security software, and change important passwords from another device.
Reporting
- US: report to the FTC at ReportFraud.ftc.gov, and forward scam texts to 7726.
- UK: forward scam emails to report@phishing.gov.uk and texts to 7726. If you lost money, tell your bank and report it to Report Fraud.
- Elsewhere: your national consumer protection agency or the police, and the Report option in whichever app the message arrived in.
Sources
- FTC — What To Do if You Were Scammed
Supports: what to do after paying by card, bank transfer, payment app, gift card, wire or crypto; after giving a password, personal details or remote access; recovery scams. - FTC — How To Recognize and Report Spam Text Messages
Supports: common text scam stories and forwarding texts to 7726. - UK National Cyber Security Centre — Phishing
Supports: the UK reporting addresses for scam emails and texts.
General information, not legal or financial advice.