goJumboGPT

Security Scams: how they work and what to do if you fall for one

Scam texts and emails: the red flags that still work

A practical checklist for judging a suspicious message, including sender domains, link previews and the requests that no real company ever makes.

6 min read How we write

The short answer

  • Check who really sent it, where the link really goes, and whether it matches an account you actually hold.
  • The display name is decoration, the domain after the @ is the fact.
  • Spelling and grammar mistakes are no longer a dependable signal, because writing a clean message is now free.
  • Three requests are always fake: read me your code, pay in gift cards, move your money to a safe account.
  • When a message is about an account you do not have, you can stop reading and delete it.

A suspicious message can usually be settled in about ten seconds, and you do not need to be technical to do it. Three questions decide it: who really sent this, where does the link really go, and does this relate to an account I actually hold? Everything else, including tone, logos, grammar and how urgent it sounds, is presentation that anyone can copy. This page gives you a check you can repeat on autopilot, and the short list of requests that are fake every single time.

The ten second check

Run these in order and stop as soon as one fails.

  1. Read the full sender address, not the name. On a phone, tap the sender to expand it. You are looking at what comes after the @ symbol, and only at that.
  2. Preview the link without opening it. Press and hold on a phone, hover on a desktop, and read the domain.
  3. Ask what the deadline is. Real deadlines are measured in weeks. Scam deadlines are measured in hours, because thinking is the enemy.
  4. Name the thing being asked for. A code, a password, a card number, a payment, a download or an approval. All six are worth suspicion in an unsolicited message.
  5. Match it to reality. Do you bank there? Did you order anything? Is that really your energy supplier? A surprising number of scams fail this question instantly.

If the message survives all five and still asks you to do something, do it through the app or by typing the company's address yourself. You lose thirty seconds. That is the entire cost of being safe.

Reading a sender address properly

Mail apps show a display name because it is friendlier, and that is exactly the weakness. A message can display "Chase Fraud Alert" while the real address is a free mailbox or a domain registered last week.

Once you expand it, read the domain from right to left. The important part is the last two labels before the first slash or the end: the registered domain. In service@alerts.example-bank.com the real domain is example-bank.com. In service@examplebank.security-check.net the real domain is security-check.net, and the bank's name is just a word someone typed.

The common tricks are worth recognizing by sight:

TrickWhat it looks likeWhy it works
Subdomain stuffingpaypal.com.account-verify.ioThe familiar name appears first and reading stops there
Hyphen insertionamazon-support.comScans as normal branding
Character swaprnicrosoft.com, paypaI.comrn resembles m, capital I resembles lowercase l
Different suffixyourbank.co instead of .comOne missing character
Link shortenerbit.ly and similarHides the destination completely

Shorteners deserve a rule of their own. A legitimate company sending you a link about your money has no reason to hide where it goes. In a text about a parcel, an account or a payment, a shortened link is a reason to stop.

A link is not the only thing that can carry you somewhere. Attachments do the same job less visibly: an HTML file that opens a local copy of a sign-in page, a PDF whose entire content is one button, or a picture of a QR code you are invited to scan. The QR version is deliberate, because it moves you from the device where you can preview a link to the phone where you cannot, and a phone browser shows only the first part of a long address. Treat all three the way you treat a link you cannot preview: leave the message, open the company's app, and see whether the same alert is waiting inside your account. Reading a web address is a ten minute skill and it pays for itself here, which is what the anatomy of a URL walks through.

Why the old typo advice expired

For years the standard advice was to look for bad spelling, odd phrasing and weird punctuation. That signal came from the fact that many scammers wrote in a second language. Text generation removed the barrier completely, and messages now arrive in fluent English, or fluent Spanish, French or German, with correct branding and plausible reference numbers.

Two things replaced it. First, structure: real companies address you consistently, usually with a name or a partial account number, and they rarely ask you to resolve something entirely inside a message. Second, channel: your bank's app can show you a genuine alert, and a text cannot prove anything. Judging the request rather than the wording is the habit that holds up, which is the same conclusion reached in phishing explained.

Logos and formatting mean nothing either. They are copied directly from the real emails, often by forwarding a genuine one and editing the link.

The requests that are always fake

Some asks have no legitimate version. If you see one, you can stop evaluating and start deleting.

Read me the code you just received. Codes exist to prove you are you. No bank, courier, marketplace, gaming platform or support desk needs to hear one. This is also how attackers get past two-factor: they have your password already and need you to complete the login.

Pay with gift cards. No government, utility, court, employer or tech company accepts iTunes, Amazon, Google Play or Steam cards. Gift cards are used because they are irreversible and can be spent from anywhere in the world within minutes.

Move your money to a safe account. Banks freeze accounts and block cards. They never ask you to transfer your balance somewhere for protection, and that particular script is covered in bank impersonation scams.

Install this so I can help you. Remote access tools are legitimate software being used against you, and the moment they are running, your screen and your accounts are visible to a stranger. The long version of that script, including the fake refund that follows months later, is the tech support scam.

Pay a small fee to release something. A 1.99 or 2 pound handling charge is not the target. The card details are, and the parcel fee trick is the most common version.

Small habits that cut the volume

It helps to know why the message reached you in the first place. Addresses and mobile numbers are traded in bulk, and most of them were exposed years earlier in a breach at a company you once used. A list is worth more when the sender knows a real person is reading it, and that is precisely what a reply confirms. With genuine marketing, replying STOP is a standard opt out and it works. With a scam text it tells the sender the number is live, so the volume goes up rather than down. Do not reply, do not tap the unsubscribe line in a message you were not expecting, and report it instead.

Use a separate email address for shopping, newsletters and one off signups, so that anything arriving at your main address is already unusual. Turn off automatic image loading if your mail app allows it, since images confirm that a message was opened. Report rather than reply: most mail apps have a report phishing option that helps the filter, and in many countries you can forward scam texts to a short reporting number run by the carriers.

What to do next

If you already tapped the link, the most useful question is what happened after the tap, not the tap itself. Nothing typed and nothing downloaded usually means nothing to fix. If you did enter details, work through the checklist for after a phishing click and change the password from a different device before anything else.

Common questions

How do I see where a link goes before tapping it?

On a phone, press and hold the link until a preview panel appears, then read the domain and cancel. On a desktop, hover over the link and read the address in the bottom corner of the window. Never use the link itself as the way to check it.

The text came from a normal mobile number, does that make it real?

No. Numbers are cheap and easily spoofed, and many scam texts are sent from ordinary looking mobile numbers precisely because a shortcode looks more corporate. Judge the request and the link, not the sender number.

Is it dangerous to open a text or reply stop?

Opening a text is safe. Replying confirms your number is live and usually brings more messages, so delete instead, and report it to your carrier's spam service if there is one.

My email provider let it through, does that mean it passed a check?

Filters catch most bulk spam but cannot judge a single well written message sent to one person. Arrival in your inbox is not a verdict.