How to Spot a Phishing Text (Smishing)
The tell-tale signs of a scam SMS, and the safe steps to take before you tap anything.
A phishing text (smishing) is a scam SMS or messaging-app message that pretends to be from a bank, delivery service, or government body to make you tap a link or share personal details. Spot it by checking for urgency, an unknown sender, an odd link, and requests for OTPs or passwords, then delete it without tapping.
- Phishing texts create urgency: account blocked, parcel held, prize expiring.
- Real banks and government bodies never ask for your OTP, PIN, or password by text.
- Hover over or long-press links to check the real address before tapping.
- Shortened or lookalike web addresses are a major red flag.
- Never call a phone number given inside a suspicious message.
- When unsure, contact the company using their official app or website, not the text.
Your phone buzzes: “Your bank account has been suspended. Verify now to avoid closure.” There is a link, and a clock ticking in your head. This is a phishing text, also called smishing, and it is designed to make you act before you think. The good news is that once you know the pattern, these messages become easy to spot and even a little predictable.
This guide breaks down exactly how phishing texts work, the specific warning signs to look for, and the safe steps to take when one lands in your inbox. None of it requires technical skill, only a habit of pausing before you tap.
How a phishing text is built to fool you
Every smishing message leans on the same emotional levers. Recognising them is half the battle.
- Urgency and fear. “Act within 24 hours,” “account will be blocked,” “parcel will be returned.” Panic makes people skip their normal caution.
- Authority. The message pretends to be your bank, a courier, a tax office, or a well-known brand, borrowing trust it has not earned.
- A single, easy action. Tap this link, call this number, share this code. The scam only works if you take that one step.
- A reward or a threat. Either you have won something, or you are about to lose something. Both are bait.
Understanding these levers helps because the story changes but the structure never does. Whether it claims to be a lottery win or a KYC update, the shape is identical.
The stories scammers love to tell
In India especially, a handful of stories come around again and again. Knowing them by name makes them easier to laugh off. There is the bank KYC update, warning that your account will be frozen unless you verify immediately. There is the parcel on hold, claiming a delivery is stuck and asking for a small fee or address confirmation. There is the electricity bill, threatening that your connection will be cut tonight. And there is the reward or refund, telling you a cashback or lottery amount is waiting to be claimed. Every one of these is engineered to make you tap a link in a hurry. Once you recognise the template, the specific wording stops mattering.
The warning signs, one by one
Here is a practical checklist you can run through in a few seconds.
| Red flag | What it looks like | Why it matters |
|---|---|---|
| Unknown sender | A random mobile number or an odd short code | Real institutions use consistent, recognisable sender IDs |
| Urgent threat | “Verify now or lose access” | Pressure is a manipulation tactic, not standard practice |
| Strange link | Shortened or a misspelled brand name | Hides the real destination from you |
| Request for secrets | Asks for OTP, PIN, CVV, or password | No legitimate body ever asks for these by text |
| Poor language | Odd grammar or spacing | Mass scam messages are often carelessly written |
The single most reliable rule is the last one in that table turned into a promise: no genuine bank, wallet, or government body will ever ask for your OTP, PIN, CVV, or password by text or call. Anyone who does is a scammer, full stop.
How to check a link without falling for it
The link is the trap door. Before you go anywhere near it, inspect it.
- Do not tap. Long-press the link instead. Your phone will usually show a preview of the full web address.
- Read the real domain. Look at the part just before the first single slash. A message claiming to be from a bank but pointing to a random or misspelled address is fake.
- Beware shorteners. Shortened links hide the destination entirely. Treat any shortened link in an unexpected message as suspicious.
- Watch for lookalikes. Scammers register addresses that swap or add letters to a real brand name. A close-but-wrong spelling is a giveaway.
Scam links often lead to fake login pages that look convincing. To understand how those fake pages and download traps are constructed, see our explainer on how fake app download sites work.
Beware the phone number trick
Not every phishing text carries a link. A growing variation gives you a phone number instead, urging you to call “customer support” or “the fraud department” about a problem with your account. This is designed to get around your caution about links. The moment you call, a convincing-sounding person walks you through steps that end with you sharing an OTP, reading out card details, or installing a remote-access app so they can “fix” things. Treat any phone number inside an unexpected message as part of the scam. If you genuinely need to contact your bank, use the number printed on your card or in the official app, never one handed to you in a message.
What to do when a phishing text arrives
Once you have identified a message as suspicious, the safe response is short and consistent.
- Do not tap any link or call any number in the message. If you want to check whether there is a real problem, open the company’s official app or type their known website address yourself.
- Never share codes. An OTP is a key to your account. Sharing it, even with someone claiming to be support staff, hands over that key.
- Report and block. Most Android messaging apps let you mark a message as spam and block the sender. This protects you and helps filters catch similar messages.
- Delete it. Once reported, remove the message so you are not tempted to revisit it later.
If you are ever unsure whether a message about your Google or bank account is real, going straight to the source is always safe. Our guide on how to secure your Google account shows how to review recent activity directly.
Why reporting matters more than you think
It is tempting to simply delete a scam text and move on, but taking the extra few seconds to report it does real good. When you mark a message as spam, your messaging app and mobile operator learn from it, which helps their filters catch similar messages before they reach other people. In effect, each report you make protects family members and neighbours who might be more likely to fall for the same trick. Reporting also removes the message from your main inbox, so you are not tempted to revisit it in a weaker moment. It is a small civic habit with an outsized benefit.
If you already tapped or shared something
Mistakes happen, and acting fast limits the damage. Do not waste time on embarrassment.
- Shared a password? Change it immediately from the official app or website, and change it anywhere else you reused it.
- Shared an OTP or card details? Contact your bank or the service straight away to freeze the account or card and flag any transactions.
- Installed a file? Run a check with Google Play Protect and review recently installed apps. Our guide on what to do after you installed a suspicious APK lays out the full cleanup.
- Turn on 2FA. Adding two-factor authentication means a stolen password alone can no longer open your account.
Build habits that make you scam-proof
You cannot stop scam texts from being sent, but you can make them harmless. A few standing habits do most of the work.
- Treat every unexpected message with an action request as guilty until proven innocent.
- Verify through official channels only, never through the contact details inside the message.
- Slow down. Urgency is the scammer’s main weapon; refusing to hurry disarms it.
- Keep your phone updated so that even an accidental tap has fewer ways to cause harm.
It also helps to talk about these scams openly with the people around you, especially older relatives who may be less familiar with the tactics. Fraudsters rely on isolation and embarrassment; someone who has been tricked often stays quiet out of shame, which lets the scam spread unchallenged. A quick family conversation about the parcel and KYC stories, and a shared rule never to share OTPs, protects the whole household at once. Encourage anyone unsure about a message to simply pause and ask a trusted person before tapping. That single habit of checking with someone stops a large share of scams in their tracks.
Phishing texts succeed only when they rush you. Once you recognise the pattern of urgency, authority, and a single easy action, you can read the whole trick at a glance. For more on staying safe day to day, explore our mobile security guides and the practical checklist on our security page.
Frequently asked questions
What is the difference between phishing and smishing?
Phishing is the general term for scams that trick you into revealing information or installing something harmful, traditionally by email. Smishing is simply phishing delivered by SMS or a messaging app. The tactics are the same, only the channel differs, so the same caution applies to both.
I tapped a link in a phishing text but did not enter anything. Am I safe?
Usually yes, if you only opened the page and did not type any details or install anything. Simply loading a web page rarely harms an updated phone on its own. To be safe, close the page, do not enter any information, and avoid downloading any file the page offered.
How did scammers get my number?
Phone numbers leak through data breaches, contest forms, shopping sites, and lists sold between spammers. Many smishing campaigns also simply dial through number ranges at random. Receiving a scam text does not mean you were specifically targeted or that your phone is compromised.
Should I reply STOP to make the texts end?
Not to a scam message. Replying confirms your number is active and often leads to more messages, not fewer. For genuine marketing from a known company, STOP works, but for a suspected scam it is safer to delete and, where available, report the message as spam.
What should I do if I entered my password or OTP?
Act quickly. Change the password for that account immediately from the official app or website, and if you shared an OTP, contact your bank or the service to freeze or reverse any activity. Turning on two-factor authentication afterwards adds a second layer of protection for the future.
Can my phone report these texts automatically?
Many modern messaging apps flag suspected spam and let you report it with a tap. On Android you can usually mark a message as spam and block the sender from the conversation menu. Reporting helps your provider filter similar messages for other people too.
Get launch updates from Aavot
One email when the official app ships. No spam, unsubscribe anytime.
Related reading
How to Avoid Subscription-Trap Apps
Spot and avoid subscription trap apps on Android: recognise fake free trials, hidden auto-renewals, and dark patterns before they charge your card.
How to Stay Safe on Public Wi-Fi
Public Wi-Fi safety made simple: practical steps to protect your Android phone on airport, cafe, and hotel networks without falling for scams.
How to Lock Apps on Android
Learn how to lock apps on Android using built-in App Pinning, Private Space, and app-level locks to protect WhatsApp, banking, and photos.