Back to blog

How to verify a suspicious message, call, or link before responding

A practical method for pausing, independently verifying a contact, and deciding what to do when a message, call, or link may be a scam.

6 min read
Person calmly reviewing a suspicious phone message beside a laptop

A message can look urgent, familiar, and completely ordinary: a bank alert, a delayed package, an invoice, a relative needing help, or an offer that expires in minutes. That is exactly why possible scams are not always obvious.

The most useful alternative is not trying to guess whether every message is real or fake. It is using a short process that prevents you from responding under pressure. The U.S. Federal Trade Commission (FTC) notes that many scams share three elements: unexpected contact, urgency, and specific instructions about how to pay or what information to provide. Read the FTC guide to scam warning signs.

Urgency is not proof that something matters; very often, it is a reason to verify before acting.

The STOP method for unexpected contacts

Use these four steps before clicking, calling the number in a message, sharing a code, or sending money.

  1. Stop. Do not respond while you feel rushed, afraid, excited, or embarrassed. A legitimate notice can usually wait a few minutes; a scam often depends on an immediate reaction.
  2. Think about the request. Identify exactly what you are being asked to do: click a link, open a file, provide a password or code, install an app, make a payment, or move money.
  3. Operate through an independent channel. Open the official app, type the website address yourself, or look up the official phone number. Do not use links, buttons, phone numbers, or email addresses included in the unexpected contact.
  4. Pass it on or delete it. If you cannot confirm the request, do not continue. Mark the message as spam, block the sender where appropriate, and report it to the platform or impersonated organization.
Visual diagram showing a verification pause between a suspicious message and an official channel
When a contact is unexpected, pausing and checking outside the message is often the safest first response.
Keeping the received message separate from the verification channel reduces the chance that the scam itself controls the check.

Signals that justify an immediate pause

One signal alone does not prove fraud. But the more signals you see together, the less reasonable it is to follow the message’s instructions.

  • The contact was unexpected. You were not expecting a delivery, charge, offer, password change, or call from that person.
  • It uses a major threat or reward. “Your account will be closed,” “you owe a fine,” “you won a prize,” or “a family member is in danger” are stories designed to trigger a fast reaction.
  • It discourages verification. Anyone insisting that you stay on the line, tell no one, or avoid checking the account another way is removing your ability to confirm the story.
  • It asks for data it should not need through that channel. Passwords, authentication codes, full card details, identity documents, or remote device access require especially careful verification.
  • It dictates a hard-to-reverse payment method. In an unexpected contact, demands for cash, gift cards, wire transfers, cryptocurrency, or certain instant payments deserve extra caution.
  • The link, sender, or phone number only resembles the real one. A changed letter, unusual domain, or local-looking number does not establish authenticity. The FTC notes that caller ID can be spoofed. Review FTC advice on imposter scams.

How to verify without trusting the message itself

If it appears to come from a company, bank, or online service

Close the message and use the official app or a website address you already know. Check whether there is actually a notice, purchase, invoice, or account restriction. If you need help, use a number on the back of your card, on an earlier statement, or on an official website you found independently.

If it appears to come from a public agency

Do not assume that a name, logo, or case number makes the contact authentic. Search for the agency’s official portal without using the received link, then check its published contact channels and procedures. Impersonators can copy real names or invent organizations that sound official.

If it appears to come from someone you know

Verify through a second channel you have used before: call a saved number, send a message to another known account, or ask a question whose answer is not public on social media. Do not treat the possibly compromised chat as the only proof.

What to do with links, attachments, and verification codes

Links and attachments can lead to pages that imitate real services or install unwanted software. The cautious approach is not to open them from an unexpected message. If you think the notice might be genuine, find the service independently and check the issue there.

Temporary verification codes deserve one simple rule: do not share them. Their purpose is to prove that you are trying to sign in or approve an action. If someone asks for one by phone, chat, email, or social media, stop the interaction and check the account through an official channel.

The FTC recommends keeping devices updated and using multi-factor authentication, because that added layer can make account access harder even if someone gets your password. Read the FTC explanation of phishing and multi-factor authentication.

If you already clicked, replied, or shared information

Do not let concern turn into inaction. Acting quickly may limit the damage.

  1. End the contact. Do not continue the conversation or install tools suggested by the other person.
  2. Change exposed credentials. Use the official site or app, starting with your email account if you reused that password elsewhere.
  3. Review account activity. Look for logins, recovery changes, purchases, transfers, or unfamiliar devices.
  4. Contact the relevant provider. If you shared banking details or made a payment, contact the institution promptly through its official channel.
  5. Secure the device. Update the system and security software; if you opened a file or installed something, run a security scan.
  6. Report it and keep evidence. Save screenshots, numbers, emails, and receipts to report the incident to the platform, impersonated organization, or relevant authority.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) summarizes a useful phishing response: recognize it, report it, and delete it. Read CISA’s phishing avoidance tip sheet.

A routine that prevents rushed decisions

Prevention does not mean distrusting everything. It means reserving an independent check for actions that could cost money, account access, or privacy. Make it a personal or family rule: no unexpected payment, password reset, access code, or installation is approved from the first message received.

Conclusion: when a message pressures you to act, do not try to solve the issue inside that same conversation. Leave the channel, find official contact details, and verify the claim before responding. That brief pause is a practical defense against many forms of impersonation.