Verifying a Suspicious Message Before You Respond or Click
Photo credit: GadgetLite.net | All Things Tech
In this article
A practical, step-by-step approach to checking whether a text, email, or call is legitimate before you take any action.
Key Takeaways
- Legitimate organizations never pressure you to act immediately via text, email, or phone.
- Always verify a sender's identity using contact details you find independently — not ones provided in the message.
- Hovering over or inspecting a link before clicking can reveal whether it leads somewhere trustworthy.
- When in doubt, go directly to the official website or call the organization's published number.
- Reporting suspicious messages protects not just you, but others in your contact network.
Why Verification Matters More Than You Think
Digital fraud — including phishing emails, smishing (SMS phishing), and vishing (voice call phishing) — accounts for a significant share of consumer financial losses each year. What makes these attacks effective is not technical sophistication; it's social engineering, meaning the manipulation of normal human instincts like trust and urgency.
Scammers impersonate banks, delivery services, government agencies, and tech companies because people are conditioned to respond quickly to those names. A message that appears to come from your mobile carrier about an unpaid bill, or from the IRS about a tax issue, can feel immediately credible — even when it isn't.
Building a short verification habit before you respond to any unexpected message is one of the most practical defenses available. It costs you a few minutes and can prevent considerable harm. For a broader look at building these habits, see everyday behaviors that reduce phishing risk.
What you will need
Tools That Help You Verify
You don't need specialized software to verify a suspicious message. The tools below are broadly available and free to use. Having a clear idea of what each one is for makes the verification process faster and more reliable.
Search Engine
Look up the official contact details of any organization mentioned in the message.
Official Organization Website
Verify account alerts or requests by logging in directly rather than clicking any link.
Link Preview Tool (e.g., browser hover or URL expander)
Inspect where a shortened or embedded link actually leads before clicking.
Save Official Contact Details Ahead of Time
Store verified phone numbers and website addresses for your bank, mobile carrier, and other key services in your contacts or a secure note. When a suspicious message arrives, you'll already have a trusted source to compare against — no searching required under pressure.
Step-by-Step: How to Check a Message Before Acting
Follow these steps in order whenever you receive an unexpected message that asks you to click a link, provide personal information, call a number, or take urgent action.
Pause — do not click, call back, or reply yet
The moment you feel urgency, alarm, or confusion after reading a message, treat that reaction as a signal to slow down. Scammers deliberately trigger emotional responses — fear of a locked account, excitement about a prize — to short-circuit careful thinking. Set the message aside for at least 60 seconds before doing anything.
Examine the sender address or number carefully
For emails, look at the full sender address — not just the display name. A message may show "PayPal Support" as the name while the actual address is something like support@paypa1-alerts.com. For text messages, check whether the number matches one on the company's official website. Be alert to slight misspellings, extra hyphens, or unfamiliar country codes.
Inspect any links before clicking them
On a desktop browser, hover your mouse over a link — the actual destination URL will appear in the bottom status bar. On a mobile device, press and hold the link to preview the URL without opening it. Check that the domain matches the organization's real website exactly. Shortened URLs (like bit.ly links) can be expanded using a free URL-expander service before you visit them.
Verify through an independent, trusted channel
Search for the organization's official contact information using a search engine or a statement you already have (a printed bill, the back of your bank card, the company's official app). Call or visit that source directly. Do not use any phone number or link provided within the suspicious message itself — those can route you directly to a scammer.
Check your account directly on the official site
If the message claims there's a problem with your account — a failed payment, a security alert, a package delivery — open a fresh browser tab, type the organization's official web address by hand, and log in. If there really is an issue, you'll see it there. If you see nothing, the message was almost certainly fraudulent.
Report the message and block the sender
In the US, you can forward suspicious text messages to 7726 (SPAM), which reports them to your carrier. Phishing emails can be forwarded to the Anti-Phishing Working Group at reportphishing@apwg.org, and you can also report them directly to the impersonated organization. Most email clients have a built-in "Report phishing" or "Report spam" button. After reporting, block the sender.
Common Scenarios and What to Watch For
Understanding how these messages typically look in real life makes the steps above easier to apply. Email red flags security experts notice cover a wide range — from mismatched sender domains to generic greetings like "Dear Customer" instead of your actual name.
Text-based scams often mimic package delivery notifications or bank alerts. They frequently contain a short message and a link, with little identifying context. Phone-based scams may involve a caller claiming to be from tech support or a government agency, sometimes using spoofed caller ID (where the displayed number is faked) to appear legitimate.
In all cases, the verification process is the same: pause, examine, and confirm through an independent source. If you're newer to recognizing these patterns, our beginner's guide to online scam recognition walks through the fundamentals without assuming any prior knowledge.
Two-Factor Codes Are Targeted Too
Scammers sometimes call or text victims while simultaneously trying to log in to their accounts, then ask the victim to read back the verification code that arrives. No legitimate organization will ever ask you to share a one-time code sent to your phone. If this happens, hang up immediately and change your password. Learn more about how verification codes work in our article on SMS codes vs. authenticator apps.
Never Use Contact Info From the Suspicious Message
A message may include a customer service number or a link that looks official. Scammers include these specifically to intercept your verification attempt. Always find contact information from a source you already trust — your account statement, the back of your card, or a direct web search.
