When a message, website, call, invoice, or payment request feels urgent, pause before responding. This practical scam-checking workflow helps you preserve evidence, verify the sender through an independent channel, identify common phishing and fraud signals, and choose the safest next step before money or personal information is exposed.
Overview
Asking “is this a scam?” is useful, but a quick search or a familiar logo cannot provide a complete answer. Scammers can copy branding, spoof phone numbers, use compromised accounts, and build convincing fake websites. The safest approach is a repeatable process that separates the message from the underlying claim.
Start with a pause. Do not click links, open unexpected attachments, call the number in the message, share a verification code, or send payment while you investigate. If the request involves your bank, employer, a government service, a delivery, a marketplace purchase, or a technical-support problem, open the organization’s known app or type its official address yourself. Use contact information from a statement, account portal, card, contract, or previously verified directory—not from the suspicious message.
Next, classify the request:
- Information request: Is it asking for a password, Social Security number, account number, one-time code, identity document, or payment-card details?
- Access request: Does it ask you to install software, grant remote access, log in through a link, or change a security setting?
- Payment request: Does it demand a wire, gift card, cryptocurrency, payment-app transfer, unusual invoice, or other difficult-to-reverse payment?
- Urgency request: Does it threaten suspension, legal trouble, missed delivery, job loss, account closure, or another consequence if you do not act immediately?
One warning sign does not prove fraud, and a polished message is not proof of legitimacy. Treat several signals together as a reason to stop and verify through a separate channel.
Checklist by scenario
Email and text messages
- Inspect the full sender address or number, not just the display name. Look for misspellings, unexpected domains, unusual country codes, or an address unrelated to the claimed organization.
- Read the request as if you had no context. Does it ask you to “confirm,” “unlock,” “pay,” or “verify” something you did not initiate?
- Preview a link without opening it, if your device allows. A long, shortened, misspelled, or unrelated domain deserves caution. Do not assume a secure connection symbol proves the site is genuine.
- Check the account directly. For a possible bank text scam, package delivery scam, toll notice, or government impersonation message, use the organization’s official app, website, or published contact route.
- Report phishing or a text scam using your email provider, phone controls, or the platform’s reporting feature, then delete the message after preserving any needed evidence.
For examples involving benefit threats, student-loan relief, vehicle agencies, or toll payments, review the relevant Social Security scam guide, student loan scam alerts, DMV and government impersonation guide, or toll text scam guide.
Websites and login pages
- Check the domain name character by character. Fake websites often add words, hyphens, subdomains, or look-alike characters to resemble a trusted brand.
- Ask how you reached the page. A search result, social-media advertisement, QR code, or unsolicited link can lead to a copy even when the page looks professional.
- Look for consistent contact details, a clear business identity, realistic policies, and links that work as expected. Missing information or copied text is a warning, but a complete-looking site can still be fraudulent.
- Do not log in merely to test a site. If you already entered a password, change it from the genuine service and change it anywhere else that reused the password.
- Use an online scam checker or scam website checker as an additional signal, not as the only decision. No lookup tool can guarantee that a site is safe or unsafe.
For a deeper URL and storefront review, see How to Check if a Website Is a Scam.
Calls and voicemail
Caller ID is not reliable proof of identity because phone numbers and names can be manipulated. Ask for the caller’s name, department, and reference number, then end the call. Find the organization’s number independently and call back through that route. Never provide a one-time code, move money to “protect” it, install remote-access software, or stay on the line while being pressured to act.
Repeated calls, silent calls, and threats are reasons to document and block—not reasons to trust a caller who claims to be helpful. The scam phone number lookup guide explains what call patterns can and cannot tell you.
Invoices, jobs, marketplaces, and payment requests
For an invoice, verify the supplier, account details, purchase order, and requested change using a known contact. A familiar name or attached PDF is not enough; fake invoice scams often rely on routine billing processes and time pressure. Use this invoice verification guide for a focused review.
For a job offer, confirm the employer through its independently located careers page. Be cautious if the “employer” asks you to pay for equipment, deposit a check, buy gift cards, or send personal documents before normal hiring steps. For a marketplace or payment-app request, keep communication and payment within the platform where possible, verify the item and seller, and avoid off-platform urgency. Gift cards, cryptocurrency, wire transfers, and some payment-app transfers can be difficult to recover once sent. Do not provide a gift-card number or PIN to someone who contacts you unexpectedly; consult the gift card scam guide when that payment method appears.
What to double-check
Before taking action, write down the claim in one sentence: “My account will be closed,” “my package needs a fee,” or “this person wants a deposit.” Then verify that claim separately. Look for the notice inside the official account, a matching order record, a known vendor contact, or a documented conversation. If the claim exists only in the incoming message, treat it as unverified.
Check the destination, not just the branding. Review the exact email domain, web address, callback number, payment recipient, and bank-account name. Small inconsistencies matter, particularly when a request asks to change payment instructions or transfer money to a new recipient.
Preserve evidence before deleting anything: screenshots, full email headers when available, URLs, phone numbers, receipts, usernames, transaction IDs, dates, and a short timeline. Do not forward suspicious content to coworkers or friends if doing so could spread a malicious link; share it through a safe reporting process instead.
Consider whether your own account may be affected. If you clicked a link, entered credentials, downloaded software, or approved a login, change credentials from a trusted device, enable multifactor authentication, review active sessions, and contact the real service. If financial information was exposed, contact the financial institution using a verified number and ask what protective steps apply. For exposed identity information, use the steps in the data breach protection guide.
Common mistakes
- Trusting logos and tone: Design quality and professional language can be copied.
- Searching only the phone number: A clean result does not prove the caller is genuine, and a spoofed number may belong to an unrelated person.
- Calling the message back: Use a separately verified number instead.
- Clicking to “see what happens”: A page can capture credentials, trigger a download, or confirm that your address is active.
- Relying on HTTPS: Encryption protects the connection; it does not establish the site owner’s honesty.
- Sending a small test payment: A small transfer can still expose account details or confirm that you will comply.
- Continuing after a red flag: You do not need absolute proof to pause, refuse, or verify independently.
- Deleting evidence too early: Records can help a bank, platform, employer, or investigator understand what happened.
When to revisit
Return to this checklist whenever a message asks for money, credentials, identity documents, remote access, or an unusual change to a normal process. Revisit it before seasonal planning cycles, travel, tax-related tasks, benefits reviews, school enrollment, major online purchases, or periods when your team handles more invoices and account resets. Scammers frequently adapt familiar themes to current events and routine deadlines.
Update your personal or team workflow when applications, payment tools, password managers, email filters, or multifactor-authentication methods change. Make sure everyone knows the independent verification route for important vendors and services. A simple rule is useful: urgent requests are handled through a known channel, and payment or credential changes require a second check.
If you already shared information or sent money, act quickly without waiting to determine exactly what happened. Contact the bank, card issuer, payment platform, employer, or affected service through a verified channel; secure exposed accounts; preserve evidence; and report the incident to the relevant platform or consumer-protection authority. Review tech-support scam recovery guidance if remote access or software installation was involved. The goal is not to prove your judgment was perfect—it is to contain the damage, protect remaining accounts, and create a clear record of the incident.