Scam texts — the trade calls them smishing, SMS phishing — work because a text feels personal and lands in the same inbox as your dentist and your delivery updates. The good news is that they nearly all follow the same script, and once you can see the script you can spot the con in a few seconds without any tools. You don't need to know whether one specific message is fake; you need a repeatable read.
The one rule that settles most cases
Never verify a message using the message itself. If a text claims to be your bank, a courier, or a government office, don't tap its link or call its number — reach the organization on a channel it didn't give you.
USPS: your package is on hold. Update your details: usps.delivery-confirm.info/track
The real owner of that link is delivery-confirm.info, not USPS. Instead of tapping, open the courier's official app or type its address yourself. The scammer's whole plan depends on you walking their path — so take your own.
Six red flags in a scam text
It's about something you never started
The classic 2026 setup is a delivery notice for a package you didn't order — "USPS: your parcel is held, confirm your address here." Same shape for a bank alert on an account you don't have, a toll you never drove through, a refund you didn't request, or a prize you didn't enter. Scammers blast these to millions of numbers knowing a slice of people are genuinely waiting on a delivery or a refund. If a text references something you didn't initiate, that mismatch alone is enough to slow down.
It's rushing you
"Action required within 24 hours." "Your account will be suspended." "Final notice." Urgency is the engine of almost every scam text because panic short-circuits the checks you'd normally run. Real institutions move slowly and give you real channels to respond through — they don't threaten to close your account in an hour over SMS. When a message's main feature is a ticking clock, treat the clock as the tell.
The sender and the link don't match the brand
Legitimate business texts arrive from a 5- or 6-digit short code or a clearly branded sender ID — not a random personal-looking 10-digit number or an international one. Look at the link the same way: the real owner of a web address is the two words right before the first single slash. usps.com is the postal service; usps.delivery-confirm.info is not. A brand name buried in a subdomain or padded with extra words (amazon-verify.net) is a look-alike, not the real thing.
It wants a code, password, or payment detail
This is the line no legitimate organization crosses. Your bank, a courier, and any real platform will never text you asking to read back a one-time verification code, a PIN, a full card number, or a password. A very common version: the scammer triggers a real login code to your phone, then texts pretending to be "fraud prevention" and asks you to confirm the code — handing them your account. If a message asks for the code you just received, it is the attack.
The details are subtly off
Odd greetings ("Dear customer"), small grammar slips, a logo that's slightly wrong, or a tone that doesn't match how the company usually talks to you. Brand SMS is heavily reviewed and rarely ships with typos or screaming punctuation. None of these on their own proves a scam, but stacked together they're a strong signal — especially alongside any of the flags above.
It steers you toward an untraceable payment
Gift cards, cryptocurrency, wire transfers, or "verify your identity" by prepaid card are the payment methods of choice for scammers precisely because they can't be reversed. No government agency, utility, or real business collects a debt or a fee this way. The moment a text pushes you toward an irreversible payment, the conversation is over.
What to do with a text you don't trust
The safest response is mostly about what you don't do:
- Don't tap the link, and don't call any number in the text. Both lead straight to the scammer. If the message claims to be your bank or a courier, use the official app, or the number printed on the back of your card or on a receipt.
- Don't reply — not even "STOP." Any reply confirms your number is live and reaches a real person, which usually means more scam texts, not fewer.
- Report it, then delete it. In the US and UK you can forward the message to 7726 (it spells SPAM) to flag it to carriers, and report scams to your national fraud body — the FTC at reportfraud.ftc.gov in the US. Then delete the text so you don't tap it later by accident.
If you're unsure whether a wider claim in the message is real — a "recall," a "new government payment," a viral warning being forwarded around — you can search it against fact-checkers before you act on it or pass it along.
Why texts are the scammer's favorite channel
Email spam filters have decades of training behind them; SMS has far less, so a scam text is more likely to reach you unflagged and get read within minutes. That's exactly why the checks above lean on judgment rather than technology — the fake delivery notice, the "confirm your code" message, and the too-good refund all share a shape, and the shape doesn't change even as the wording does. As CISA's phishing guidance puts it, the durable defense is to slow down, distrust the framing of an urgent message, and verify the destination yourself.
Not sure a claim in the message is real?
FAXTR searches 100+ fact-checking organizations in one query — free, no login required. Check a viral warning or "alert" before you act on it or forward it.