Text Message Scams: How to Read a Smishing Message

Unpaid tolls, held packages, bank alerts, wrong numbers. How to read a scam text, check a link safely, and report it to your carrier in under a minute.

STOPTHESCAM Team6 min read
  • scam recognition
  • phishing
  • text scams
  • prevention

Text message fraud, sometimes called smishing, has become the highest-volume scam channel in the United States for a simple reason: it is cheap, it arrives on the device people trust most, and it strips away nearly every clue you would normally use to judge a message. No letterhead. No voice. No return address you recognize. Just a sentence, a deadline, and a link.

That constraint works in your favor. A text is short, so there is nowhere for a scammer to hide. Once you know what to look at, most scam texts identify themselves in a few seconds.

The five formats that make up most of it

Nearly every scam text you will receive is a variation of one of these:

The unpaid fee. An outstanding toll, a delivery surcharge, a small tax balance. The amount is always small, usually a few dollars, because a small number does not trigger the caution a large one would. The goal is never the fee. It is the card number you type on the page the link opens.

The held package. A parcel cannot be delivered until you confirm your address. Deliberately vague about the sender, because nearly everyone is expecting something.

The bank alert. A charge you do not recognize, with an invitation to "reply NO if this was not you." Replying is the hook. It starts a conversation with a "fraud department" that will eventually ask for a one-time passcode or ask you to move money to a "safe account."

The wrong number. "Hi Jessica, are we still on for Thursday?" Warm, harmless, no link. You reply to say they have the wrong number, and a friendly conversation begins. Weeks later there is an investment opportunity. This is the long-game format, and it is the one that costs victims the most.

The job offer. Remote work, flexible hours, generous daily pay for simple tasks like rating products. The early tasks pay real money. Then a deposit is required to unlock higher-paying work.

What to look at, in order

1. Did you start this?

If you did not sign up for delivery alerts, you do not receive delivery alerts. The U.S. Postal Service does not send unsolicited texts with tracking links. Toll authorities bill through accounts and mailed notices. This one question eliminates most messages before you read another word.

2. Read the domain from right to left

This is the single highest-value skill in this article, so it is worth doing slowly.

In a web address, the part that determines who actually owns the site is the two labels immediately before the first single slash. Everything to the left of that is decoration the sender controls.

https://usps.delivery-update.com/track

Read backward from the slash: com, then delivery-update. The real owner is delivery-update.com, a domain anyone can register for a few dollars. usps at the front is a subdomain the scammer chose to reassure you. Compare:

https://tools.usps.com/go/TrackConfirmAction

Backward from the slash: com, then usps. This one is the Postal Service.

Scammers rely on people scanning left to right and stopping at the first familiar word. Train yourself to jump to the first single slash and read backward from it.

3. Watch for near-miss spellings

Hyphens inserted into real brand names, .top or .icu or .rest endings instead of .com, an extra word like "secure" or "verify" bolted on, a lowercase L standing in for a capital I. A brand with a real marketing budget does not send you to paypa1-secure-billing.com.

4. Notice the shape of the sender

Legitimate bulk senders use short codes, the five- and six-digit numbers your bank or pharmacy texts from, or a registered alphanumeric sender name. A message claiming to be from a national bank that arrives from a twelve-digit international number or a random Gmail address is finished before it starts.

Sender numbers can be spoofed, so a plausible-looking sender proves nothing. An implausible one disproves plenty.

5. Check the grammar of the urgency, not the grammar of the sentence

The old advice about typos is out of date; scam texts are well written now. The tell is not spelling, it is the logic. Ask what the stated consequence actually is, and whether an organization could plausibly impose it. Twelve hours until a package is destroyed? Arrest for a $6.99 toll? Account closure over an unclicked link? Real institutions have appeals processes, not countdowns.

The reflex to "just look and see" is what these messages are built to trigger. Better options, in order of safety:

  1. Do not open it at all. Go to the organization yourself: the app you already have installed, or the address you type by hand. Your bank's app shows real alerts. The carrier's site shows real tracking.
  2. Long-press to preview. On both iOS and Android, holding a link shows the full destination without loading it. Read the domain right to left as above.
  3. Use link analysis. When the link ends up in a browser on your computer, our Chrome extension previews where it goes as you hover and analyzes the destination before the page loads. Vision is free on the Chrome Web Store, and on the App Store for iPhone.

If a page does open, the rule is simple: never type anything into it. Looking at a phishing page is usually harmless. Filling it in is the entire attack.

Never reply, not even "STOP"

Replying to a scam text confirms that a human reads this number, which raises its resale value on the lists these messages are sent from. The official STOP keyword is an obligation for legitimate marketers, not for criminals.

Do this instead:

  1. Forward the message to 7726 (it spells SPAM). This reports it to your mobile carrier at no cost. Forward the sender's number too if your phone prompts for it.
  2. Report it to the Federal Trade Commission at reportfraud.ftc.gov, and to the FBI's Internet Crime Complaint Center at ic3.gov if it involved a link or a payment.
  3. Block and delete. On iPhone, you can also turn on filtering for messages from unknown senders in Settings, which moves them to a separate list.

If you already tapped

Tapping alone is rarely the disaster people fear. Take these steps in order:

  • If you only opened the page and closed it: you are almost certainly fine. Do not enter anything if it reopens.
  • If you entered a card number: call the number on the back of the card, report it, and ask for a replacement. Do not wait to see whether a charge appears.
  • If you entered a password: change it on the real site immediately, and change it anywhere else you reused it. Turn on two-factor authentication while you are there.
  • If you read a one-time passcode to someone: treat the account as compromised. Change the password, sign out of all sessions, and call the institution using a number you look up yourself.
  • If money moved: move fast, and follow what to do in the first 24 hours.

The pattern behind the format

Every item in this article is a specific case of the general machinery described in the seven signals that show up in almost every scam: unrequested contact, an artificial deadline, and a payment or credential request through a channel the sender controls. When a new text format appears next month that is not on this page, that framework will still classify it correctly.

And when a text tries to move you onto a phone call, the follow-up matters just as much. Caller ID is not evidence covers what happens next.

  • 5 min read

    Caller ID Is Not Evidence: How Phone Scams Actually Work

    Caller ID can be forged, voices can be cloned, and a familiar number proves nothing. How phone scams are built, and the callback rule that defeats all of them.

    • scam recognition
    • phone scams
    • prevention
    • fundamentals