How to Check a Suspicious Text in 30 Seconds
Free: How to Keep Yourself Safe From Scammers
9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.
How to Check a Suspicious Text in 30 Seconds
It's 8:14 on a Tuesday morning. A text lands: "Your package couldn't be delivered. Update your address here." No name, no order number, just a link. You're not sure. You've got maybe ten seconds of attention for this before you're back to making coffee.
Here's the thing — checking it properly takes about as long as reading it twice. Most people skip that step not because it's hard, but because they don't know what "checking" is actually supposed to look like. So they either click it, or they ignore it and hope. Neither is great. If you want the reasoning behind seven specific warning signs to eyeball first, that's a good five-minute read. This one's shorter: here's the third option, and it takes 30 seconds.
The habit, not the debate
You don't need to become a fraud analyst to handle this. You need one habit: before you tap a link, send money, or reply with any personal detail, run the message itself through something that checks it against what's already known — not just how the sentence is worded, but whether the actual link or number in front of you has already burned somebody else this week.
That's the whole idea behind Cautellus's scanner. Paste in a text, a link, or a screenshot, and it checks what you gave it against 10,000+ confirmed scam entities pulled from six Reddit scam-tracking communities, FBI IC3 alerts, FTC reports, and three global phishing databases tracking over 770,000 malicious domains — refreshed every six hours. It also runs typosquat detection against 25+ major brand domains, so "arnaz0n-support.com" gets caught even if you'd have skimmed right past it. Your first scan's on the house — it's the fastest way to check any of the text message scams making the rounds right now.
Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.
Scan it free →Or: Get the Chrome extension to scan pages without leaving your browser.
Step by step: what to actually do with the text on your screen
- Copy the whole message, link included. Don't retype it and don't trim the link off — select the text, copy it exactly as it arrived. FTC guidance is consistent on the underlying habit here: never tap the link, and verify independently instead — this is the "verify" step made concrete.
- Paste it into the scam text checker. Not just the URL. The words around it — the urgency, the impersonated sender, the specific ask — are signals in their own right, and a link-only check throws all of that away before it even starts.
- Read the score, then read the tactic line underneath it. The number tells you the risk band. The line underneath tells you why — which is the part that actually teaches you to spot the next one without a tool.
- Act on what it tells you. Confirmed-bad: delete it, don't engage, and if you already tapped the link, see the section below. Comes back clean: it's not a green light to blindly trust the sender, just a sign nothing in it matched a known threat yet — see "what safe doesn't mean" below.
That's it. Slower to read than to actually do.
Why the whole message beats just the link
If you've only ever pasted a bare URL into a link checker, you've been running half the check. A link checker answers one question: has this exact URL shown up on a blocklist yet. That's useful, and it's also blind to brand-new scam infrastructure that hasn't been indexed yet, and to everything that isn't the link — the "don't tell anyone," the countdown timer, the fake order number designed to feel specific enough to be real. Text volume alone makes this worth doing on reflex now, not just when something feels off — see why scam texts keep getting worse for the bigger picture.
A perfectly written fake fraud alert is the clearest example — no link at all, just a phone number and a very convincing bank-branded tone. I broke down a real one from Reddit that had nothing a link checker could have caught, because there was nothing to check but the words.
Cautellus's scanner also includes behavioral detection: it identifies manipulation patterns — urgency, false authority, emotional pressure — regardless of whether the grammar is clean or the message was written by an AI tool that doesn't make the usual mistakes anymore. That's the layer a link-only check skips entirely, and it's exactly where the well-written scams are winning right now.
The three things people actually have
In order of how often people actually have each one on hand:
- The text itself. Most common. Copy and paste it whole, per the steps above.
- A screenshot. Someone forwarded it, or you saved it before deleting the original. You don't need to retype anything — upload the image and OCR pulls out every URL, phone number, and email address embedded in it, then runs each one through the same threat check.
- Just a link. Sometimes that's genuinely all you've got — a bare URL with no context. Still worth checking, just know you're getting the narrower version of the read described above.
What a clean result doesn't mean
This is the part most scam-checking content skips, and it's the part that actually matters. A "safe" result means nothing in the message matched a known bad signal — not that the person or number behind it is who they claim to be. A scammer running a brand-new number for the first time can come back clean, because nobody's reported it yet. That's not a flaw specific to Cautellus; it's true of any detection system built on records of what's already been seen. I go deeper on this honest-limits point, including what each risk band is actually telling you, in what your Cautellus risk score actually means.
The practical takeaway: a clean scan plus a request for money, a password, or a verification code is still worth a callback on a number you already have — not because the tool failed, but because "unreported so far" and "verified legitimate" aren't the same claim.
If you already tapped the link or replied
No lecture here — this is exactly the moment the whole message was designed to produce. A few things to do right away:
- Don't enter anything else. If a page asked for a password or card number and you haven't submitted it yet, close the tab.
- If you did submit something, change that password immediately, and anywhere else you reuse it.
- Contact your bank directly using the number on the back of your card, not anything from the text, if money or account details were involved.
- Run any follow-up message through the scanner too — a lot of these scams have a second-stage text or call once the first one lands, and it's worth checking before you respond to that one either.
Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.
Check it now →Already been scammed? See where and how to report it.
FAQ
Do I need to type the text out again to check it? No. Copy the whole message as-is — including the link — and paste it. Retyping risks dropping the exact URL or number, which is often the part that matters most.
Should I paste just the link, or the whole message? The whole message. A link-only check only sees the URL. The words around it — the urgency, the impersonated sender, the payment instruction — carry their own signals that a link checker never sees.
What if I only have a screenshot, not the original text? That's normal — most people forward what they have. Upload the screenshot instead of retyping it. OCR pulls out any links, phone numbers, or email addresses in the image and checks each one.
What does a "safe" result actually mean? It means nothing in the message matched a known bad signal — not that the sender is verified trustworthy. A number you don't recognize can come back safe and still be worth a callback on a number you already have, especially if money or personal info is involved.
Is checking a text free? You get one free scan every 30 days, no card required. Beyond that, unlimited scans are part of Cautellus Plus ($9.99/mo, with a 7-day free trial that requires a card and renews unless you cancel).
How is this different from just asking a chatbot if it's a scam? A chatbot reads the tone of the message and gives you a judgment call. A scanner checks the actual link, number, or sender against a live record of what's already been reported. Different jobs — read more in why ChatGPT isn't a scam scanner.
You had ten seconds of attention for that text anyway. Spend them on the scan instead of the gamble.
Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.
Scan something free →Want unlimited scans + the Chrome extension? See pricing.
Courtney
Founder, Cautellus · 20+ years in financial services
Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.
Learn moreKeep reading
Support Our Mission
Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.