Scams & fraud

How to Spot a Phishing Text or Email

Most phishing messages lean on the same handful of tricks. Once you know them, a suspicious text or email becomes much easier to spot, and to ignore.

Person holding iPhone
Photo: Quilia via Unsplash

Key takeaways

  • Pressure is the biggest red flag. Urgent threats, tight deadlines and unexpected “problems” are designed to make you act before you think.
  • Never use the link, phone number or reply option inside a suspicious message. Go to the company directly through an app or website you already trust.
  • Legitimate companies will not ask you to send them a one-time code, your full password or your Social Security number by text or email.
  • Forward spam texts to 7726, report phishing emails, and then delete the message.

What phishing is, and why it works

Phishing is a message that pretends to come from someone you trust, such as your bank, a delivery company, a streaming service, your employer or a government office, in order to get you to do something that benefits the sender. That something is usually one of three things: click a link to a fake sign-in page, share personal or financial details, or send money. When it arrives as a text message it is often called “smishing,” and as a phone call, “vishing.” The tactics are the same.

Phishing works not because people are careless, but because the messages are built to interrupt careful thinking: they borrow familiar logos and wording and give you a reason to act right now. Nearly all of them rely on the same short list of tricks, and learning that list is one of the best protections there is.

Seven warning signs to look for

1. Urgency or a threat

“Your account will be suspended in 24 hours.” “Unusual sign-in detected.” “Your package cannot be delivered.” “You have an unpaid toll.” Messages like these are written to make you feel that something bad will happen unless you respond immediately. Real organizations do contact people about real problems, but a deadline measured in hours is a classic pressure tactic.

2. A request for information the sender should already have

Your bank already knows your account number. A delivery company does not need your card details to hand over a parcel. Be very wary of any message asking you to “confirm,” “verify” or “update” a password, PIN, Social Security number, card number or one-time security code.

3. A sender that does not quite fit

Look at the full email address, not just the display name. A message signed by a well-known company but sent from a free webmail account, or from a domain with an extra word, a swapped letter or an unusual ending, is a strong sign of a fake.

4. A link that goes somewhere unexpected

On a computer, rest your pointer over a link without clicking to preview where it leads. On many phones, you can press and hold a link to see the address. Find the part of the address just before the first single slash: the name directly in front of “.com,” “.org” or “.gov” is the real destination. An address like “yourbank.account-review.com” belongs to “account-review.com,” not to your bank. Shortened links hide the destination entirely, which is one more reason to go to the company directly instead.

5. An unusual way to pay

Requests to settle a bill, fine or “fee” with gift cards, cryptocurrency, a wire transfer or a payment app are a hallmark of scams. Government agencies and established businesses do not demand payment in gift cards.

6. Something you did not expect

A refund you never requested, a prize for a contest you never entered, or a delivery notice when you are not waiting for anything should all make you pause. So should unexpected attachments, especially ones that ask you to “enable content” or sign in to view a document.

7. Details that feel slightly off

Generic greetings such as “Dear customer,” awkward wording or stretched logos can be clues. But many phishing messages are now polished and error-free, so treat the first six signs as more reliable than spelling mistakes.

Text messages deserve a second look

Texts feel personal and are usually read within minutes, which makes them attractive to scammers. Common themes include delivery problems, unpaid tolls, bank alerts, job offers and friendly “wrong number” chats that later turn to money.

A few habits help. Do not reply to unexpected texts from numbers you do not recognize, because any reply confirms that your number is active. (For a text program you knowingly joined, replying STOP is still the normal way to opt out.) Never share a verification code that was sent to your phone. That code is a key to one of your accounts, and anyone asking you to read it back is almost certainly trying to get in. If a text claims to be from your bank’s fraud team, do not call a number it provides; contact the bank yourself.

What to do if you already clicked

It happens to careful people, and acting quickly helps.

  1. If you entered a password, change it right away on the real site, and on any other account where you used the same password. Turn on two-step verification if it is available.
  2. If you shared card or bank details, call your bank or card issuer using the number on your card or statement. Ask them to watch for fraud or to issue a new card.
  3. If you shared your Social Security number, visit IdentityTheft.gov to report it, and consider placing a free fraud alert or credit freeze.
  4. If you opened an attachment or installed something, update your device’s software and run a security scan. If it is a work device, tell your IT team right away.

How to report a phishing message

Reporting helps carriers, email providers and law enforcement block the same messages for others.

  • Texts: forward the message to 7726 (the digits spell SPAM), a reporting number supported by major U.S. wireless carriers. Many phones also have a built-in “report junk” option.
  • Emails: use your email service’s “report phishing” or “report spam” button. You can also forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, an address the FTC recommends for this purpose.
  • Losses or shared information: report it to the Federal Trade Commission at ReportFraud.ftc.gov. If the message impersonated a specific company, let that company know as well.

After reporting, delete the message so you do not tap it by accident later.

Helpful official resources

These official sites are the best places to confirm current rules and to report problems. IntelliReply is not affiliated with any of them.

This guide is general educational information, not legal or financial advice. Rules can change and may differ by state, so check the official sources above for the latest details. Spotted something that needs correcting? Let us know.

Keep reading

More guides from IntelliReply

All guides

Every guide in one place

Browse all IntelliReply guides, grouped by topic, along with the official resources we rely on.

See all guides