Learn how to tell if a text message is a scam. Check 10 warning signs of phishing texts, suspicious links, fake delivery alerts and bank scam texts before you tap.
Text messages feel personal. They arrive on the device you carry everywhere, light up your lock screen, and demand only a glance. That intimacy is exactly what makes SMS such an effective channel for fraud. According to the Federal Trade Commission, impersonation messages sent by text and email remain among the most reported fraud categories year after year, and the attackers behind them have grown skilled at making a short message feel urgent and official.
The good news is that almost every scam text leaves clues. You do not need technical knowledge to spot them; you need a checklist. This guide walks through ten warning signs you can check in under a minute, plus what to do if a message fails the test. Many of the same principles apply to email scams, which we cover separately in our guide to telling if an email is a scam. Text phishing is part of the wider phishing problem, which we explain in our guide on what phishing is and how phishing scams work. If you want a faster answer on a specific message, paste it into Scamlify's SMS Scam Checker, which runs these same checks automatically.
On many phones, a text from a business shows a name instead of a number: "HMRC", "Barclays", "Royal Mail". That sender ID is decorative, not cryptographic. Some carriers check it against a registered database; many do not. That means an attacker routing messages through certain SMS providers can display the name "NatWest" without any authorisation from NatWest.
Worse, your phone threads messages by sender ID string. A fake "NatWest" text can land in the same conversation as your genuine bank alerts, with no visual signal that it is different. If a message in a trusted thread suddenly asks you to do something unusual, do not assume the thread proves the sender.
A link inside an unsolicited text is the single biggest red flag. Legitimate UK banks, HMRC, and most government agencies do not send clickable links in SMS messages. They send a reference number and ask you to log in through their app or a website you already trust.
Watch for:
When in doubt, do not tap. Open the relevant app or type the address yourself.
"Your account will be suspended." "Final notice." "You have 2 hours to respond." Urgency is the most effective tool a scammer has, because it pushes you past the moment where you would normally stop and think. A defined, short deadline (two to four hours) is deliberately chosen to stop you sleeping on it or asking a friend.
Legitimate organisations rarely threaten you into acting within minutes. If a message insists you must act right now or lose access to something, that pressure is itself the warning sign. Slow down and verify through a channel you already trust.
The parcel-delay text is the commodity tier of SMS scams, and it has run for years with almost no variation because it works on base rates. At any moment, a meaningful percentage of the population is expecting a delivery. The message does not need to be targeted; it just needs to hit often enough that recipients self-select into plausibility.
A fake Royal Mail, FedEx, or UPS text typically claims a small fee or customs charge is owed, then links to a convincing payment page that harvests card details. If you are genuinely expecting a parcel, check the courier's own app or the tracking link from your original order confirmation, never the link in an unexpected text. For a dedicated checklist on parcel scams, see our guide on how to spot a fake package delivery text message.
No reputable bank, government agency, or delivery company will text you to ask for your password, full card number, a one-time login code, or identity documents. These details are never needed to "verify" your identity by text, and a request for them is almost always a phishing attempt.
Be especially wary of any message that asks you to read back a code your bank just sent you. Real bank fraud teams will never ask for your one-time passcode. If someone does, hang up and report it.
"You've won a prize." "Refund of £480 waiting for you." "Unclaimed package held for you." If a text offers money, a prize, or a refund you cannot explain, the explanation is usually that someone is trying to take money from you rather than give it to you.
The pattern is consistent: the message creates excitement, then asks for a fee, a payment detail, or account access to "release" the reward. The FTC publishes regular guidance on recognising prize and refund scams: real winnings do not require you to pay first.
Some scam texts come from a normal-looking mobile number; others come from a shortcode (a 5–6 digit number) or an email-to-SMS gateway. A message from a number you have never seen, claiming to be from an organisation you deal with, is a strong signal of spoofing.
If you have a genuine relationship with the organisation, check the number it usually texts from inside your messaging app's history. A brand-new number attached to an urgent request should be treated as suspect.
Modern scam texts are often short and blunt, which can hide errors, but plenty still contain tells: misspelled brand names, odd capitalisation, broken sentences, or strange phrasing. Pay special attention to the brand name itself: a company will almost never misspell its own name in an official message.
Generic language is another signal. "Your account" rather than "Your Barclays account" often means the attacker is mass-sending before knowing which bank you use.
"Reply STOP to unsubscribe." "Call this number to resolve." "Click to verify." Any message that tries to move you away from your normal, monitored channels (your bank's in-app messaging, your official account portal, your known customer service line) is trying to isolate you from the people who would tell you it is a scam.
The Cybersecurity and Infrastructure Security Agency (CISA) advises treating any unsolicited message that pushes you to act through an unfamiliar channel as a potential phishing attempt. Verify independently before you respond.
Sophisticated scammers use data from breaches to make messages feel targeted: your name, the last four digits of a card, a postcode. But they often get a detail wrong: the wrong bank, a parcel you didn't order, a subscription you don't have. That mismatch is your signal to stop.
If a message feels personally relevant but something about it is slightly off, trust that instinct. Open the relevant account directly, using the app or a bookmarked URL, and check there.
If a text has triggered one or more of these signs and you are still unsure, do not tap any links and do not reply. Instead, copy the message (and the sender, if visible) into Scamlify's SMS Scam Checker for an instant assessment of the risk level and the specific warning signs it triggers. It runs the same checks described above, automatically.
If a message shows one or more of these signs, do not tap any links, do not call any numbers in the text, and do not reply. Then:
Yes. Sender IDs can be spoofed, and scam pages can clone a bank's or courier's branding exactly. That is why the appearance of a text is the least reliable signal. The sender, the link destination, and the behaviour the text asks for are far harder for an attacker to fake convincingly.
No. Tapping a link can load a credential-harvesting page, trigger tracking, or in some cases install malware. Preview the destination by long-pressing the link where your phone supports it, and only visit a site by typing the address yourself if you are unsure.
Act quickly. If you entered a password, change it immediately on the real site and enable two-factor authentication. If you entered payment details, contact your bank's fraud department. If you read back a one-time code, tell your bank straight away. The faster you respond, the more you limit the damage.
Most of them do. Phishing emails use the same urgency, impersonation, and suspicious-link tactics. The sender's address and link destinations are the equivalents to check: see our guide to telling if an email is a scam for the email-specific checklist.
Some banks send security alerts by text, but they will not include a link asking you to "verify" or "confirm" details, and they will never ask for a one-time passcode. If a bank text contains a link and a request for information, treat it as suspect and check in the app instead. For a bank-specific checklist, see our guide to fake bank text messages.
The warning signs above are exactly what our tool checks for, instantly and for free. Use Scamlify's free SMS Scam Checker the next time a text feels off, and share it with someone who might need it.