Fake Text Messages: How to Tell If a Text Is Real or a Scam
How to spot fake text messages, smishing scams, and AI-generated messages. Practical checks you can do in 30 seconds before clicking any link.

Your phone buzzes. A text says your bank account has been locked, or a package could not be delivered, or the IRS is about to take legal action. It includes a link. The message looks legitimate. It might even include your name.
In 2023, Americans lost $10 billion to text message scams, a figure that grew 14% from the year before [1]. The FTC logged over 330,000 reports of fraud initiated through text messages, making SMS the single most common contact method for scams, ahead of phone calls, email, and social media combined [2].
The people behind these messages are not sending them one at a time. They use automated systems that blast millions of texts per day, cycling through spoofed numbers and disposable SIM cards. Some messages are entirely template-based. Others are now drafted by large language models, personalized with data scraped from breaches and data brokers.
This guide covers how to identify fake text messages in 30 seconds or less, what to do when you receive one, and how to protect yourself when a text includes images or links that look convincing.
Key Takeaways
- Scam texts (smishing) are the number one contact method for fraud, costing Americans $10 billion in 2023 alone.
- Legitimate companies almost never send unsolicited texts with links asking you to "verify" or "confirm" anything.
- Urgency and fear are the primary tools. If a text makes you feel panicked, that reaction is by design.
- Any images attached to or linked from a suspicious text can be checked for AI manipulation using free detection tools.
- When in doubt, contact the company directly through their official app or website. Never use the link in the text.
What "Smishing" Actually Looks Like in 2026
The term smishing (SMS + phishing) covers any text message designed to trick you into clicking a link, sharing information, or sending money. The category has expanded well beyond the crude "you've won a prize" messages that were easy to laugh off a decade ago.
Here is what modern smishing looks like:
The fake delivery notification
"USPS: Your package cannot be delivered. Confirm your address here: usps-redelivery-confirm.com"
This variant exploits the fact that most people are expecting a package at any given time. The link leads to a site that looks like USPS, UPS, or FedEx. It asks for your address, then your credit card to cover a small "redelivery fee." The fee is fake. The card number is now in someone else's hands.
The bank alert
"Chase ALERT: Unusual activity detected on your account. Verify immediately: chase-secure-verify.com"
Some versions spoof the sender ID so the message appears in the same thread as legitimate bank notifications. The linked site replicates the bank's login page. You enter your credentials. The attacker now has them.
The government threat
"IRS: Legal action pending for unpaid taxes. Respond within 24 hours to avoid arrest. irs-payment-portal.com"
The IRS does not initiate contact through text messages. Neither does the Social Security Administration. Neither does any law enforcement agency. Any text claiming to be from a government body demanding immediate action is a scam, full stop [3].
The personal lure
"Hey, I found those photos from the trip. Check them out: shared-album-photos.com/trip"
These work by being vague enough to trigger curiosity. They often include an image thumbnail or claim to link to shared photos. The linked site may install malware or prompt you to enter social media credentials.
The AI-generated variant
This is newer and harder to spot. Instead of using recycled templates, scammers feed your name, location, and recent activity (from data breaches or social media) into a language model. The result is a text that sounds personal enough to bypass your initial skepticism.
"Hi Sarah, this is Downtown Dental confirming your appointment for Thursday. Please confirm or reschedule here: downtown-dental-booking.com"
If you actually have an appointment with that business, this message looks completely normal.
The 30-Second Check
When you receive a text that asks you to click a link, verify information, or take any action, run through this sequence. It takes less than 30 seconds.
1. Check the sender
Legitimate businesses send texts from short codes (5 or 6 digit numbers) or verified business names. Random 10-digit phone numbers, especially ones from area codes that do not match the company's location, are a red flag.
That said, spoofing a short code is possible. A legitimate-looking sender does not guarantee a legitimate message.
2. Read for urgency and threats
Scam texts almost always manufacture urgency. "Act now." "Within 24 hours." "Immediately." "Your account will be closed." Real companies do not threaten you via text message. If your bank actually detected fraud, they would freeze the transaction first and contact you through their app or a verified phone call.
3. Inspect the link without clicking it
On most phones, you can long-press a link to preview the URL without opening it. Look for:
- Misspelled domains: usps-delivery-confirm.com instead of usps.com
- Extra subdomains: secure.bankofamerica.login-verify.com (the actual domain there is login-verify.com, not bankofamerica.com)
- URL shorteners: bit.ly, tinyurl, or other shortened links that hide the destination
If the URL does not clearly belong to the company that supposedly sent the message, do not open it.
4. Check any attached images
Some scam texts include images: fake receipts, fake screenshots of account activity, fake ID documents. These are designed to make the message feel more credible.
If a text includes an image that seems meant to prove something, save it and run it through Witness. AI-generated or manipulated images often contain artifacts that detection tools catch even when your eyes cannot.
5. Verify through official channels
This is the step that defeats almost every smishing attempt. Do not reply to the text. Do not click the link. Instead:
- Open the company's official app on your phone
- Go to the company's website by typing the URL yourself
- Call the number on the back of your credit card or on the company's official site
If there is a real problem with your account, package, or tax filing, it will show up through official channels. If it does not, the text was fake.
Why These Scams Work So Well
Text messages have a 98% open rate, compared to roughly 20% for email [4]. People read texts almost immediately. They read them on small screens where URL inspection is harder. They read them in contexts where they are distracted: commuting, working, cooking.
Scammers also exploit the trust people place in SMS as a channel. Email spam filters have trained people to be skeptical of emails. Text messages still feel more personal, more direct, more likely to be real.
And the volume is staggering. The spam-blocking service RoboKiller estimated that Americans received 78 billion spam texts in 2023 [5]. At that volume, even a tiny success rate generates enormous revenue for scammers.
When Images Are Part of the Scam
Not all smishing is about links. Some scam texts use images as the weapon:
- Fake screenshots of transactions claiming someone sent you money by mistake and asking you to "return" it
- AI-generated photos of people in emergencies, used in "wrong number" scams that build to a relationship and eventually a financial request
- Manipulated screenshots of conversations, designed to blackmail or extort
In each case, the image is intended to make you believe something that is not true. This is where detection tools become directly useful. An image claiming to show a Venmo transaction, a hospital bill, or a person in distress can be checked for signs of AI generation or digital manipulation.
Save the image. Upload it to witness.vision/scan. If the image was generated or altered, the scan will flag it. It takes less than a minute and does not require an account.
What to Do If You Already Clicked
If you clicked a link in a scam text and entered information:
- Change your passwords immediately for any account whose credentials you entered. If you reuse that password anywhere else, change it there too.
- Enable two-factor authentication on your bank, email, and social media accounts if you have not already.
- Contact your bank or credit card company if you entered payment information. They can freeze your card and monitor for unauthorized charges.
- Report the text. Forward it to 7726 (SPAM), the reporting number used by most U.S. carriers. File a report with the FTC at ReportFraud.ftc.gov.
- Monitor your accounts for unusual activity over the following weeks.
If you installed an app or downloaded a file from the link, run a security scan on your device immediately. Consider a factory reset if you cannot confirm the file was harmless.
How to Reduce the Number of Scam Texts You Receive
You cannot eliminate them entirely, but you can reduce the volume:
- Register with the National Do Not Call Registry at donotcall.gov. It does not stop illegal texts, but it reduces legitimate telemarketing.
- Enable your carrier's spam filter. AT&T, T-Mobile, and Verizon all offer free spam-blocking tools.
- Do not reply to unknown senders, even to say "stop." Replying confirms your number is active and can increase the volume of spam you receive.
- Limit where you share your phone number. Every online form, loyalty program, and app that has your number is a potential leak source.
- Use a secondary number for online shopping and signups. Services like Google Voice provide free numbers that keep your primary number private.
The Bottom Line
Fake text messages work because they exploit speed and trust. They arrive on a device you check constantly, in a format you associate with personal communication, and they demand a fast response.
The defense is simple: slow down. Do not click links in unexpected texts. Verify through official channels. Check images that seem designed to convince you of something.
If you receive a suspicious text with an image or a link to an image, run it through Witness before you act on it. A 30-second check is worth more than a $2,000 loss.
- [1]Federal Trade Commission, "Consumer Sentinel Network Data Book 2023," https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2023
- [2]Federal Trade Commission, "Texting scams: Scammers' #1 way to reach you," June 2024, https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2024/06/texting-scams
- [3]Internal Revenue Service, "IRS warns taxpayers of new scams; reminds people to never share personal information via text or social media," https://www.irs.gov/newsroom/tax-scams-consumer-alerts
- [4]Gartner, "SMS Marketing Statistics 2024," https://www.gartner.com/en/digital-markets/insights/sms-marketing-open-rates
- [5]RoboKiller, "2023 Phone Scam Report," https://www.robokiller.com/spam-text-insights


