🐟 Phishy
HomeScam guides

What is smishing (SMS phishing)?

Updated July 24, 2026 · Phishy team

Smishing is a phishing attack that arrives as a text message. The word is a blend of SMS and phishing, and the idea is simple: instead of a fake email, the scammer sends a short text pretending to be an organisation you trust — your bank, a delivery company, a toll road, a tax office — with a link to a cloned website. You type your details in, and they go straight to the criminal. Smishing has overtaken email phishing as the most common attack on ordinary people, for one uncomfortable reason: your email inbox is defended by Google or Microsoft, and your text inbox is defended by nothing. This guide covers the exact definition, how smishing differs from phishing and vishing, why texts work so well, the real message templates in circulation, and how to check a suspicious text for free — without tapping the link.

🔍 Suspicious message? Paste it here and check for free
🔒 Your message is only checked, never stored. Phishy collects no personal data.

The definition, in one line

Smishing = an attempt to steal your credentials, card details or money using an SMS or text message that impersonates a legitimate organisation. It is a subcategory of phishing, defined by the channel it uses. The term comes from SMS + Phishing, and you will also see it written as SMS phishing or text message scam.

Smishing vs phishing vs vishing vs quishing

Same social engineering, different delivery: • Phishing — email. A fake bank email with a login link. • Smishing — SMS or text message. A short text with a link. • Vishing — a phone call. A "bank representative" asking for your one-time code. • Quishing — a fraudulent QR code, stuck over a real one on a parking meter or restaurant menu. The distinction matters practically, not academically: each channel has a different defence. In email you can hover over a link and read its true destination before clicking. On a phone, you cannot. That single fact is why smishing works.

Why text messages beat email for scammers

Four reasons stack up against you: 1. No filter. Your email provider runs machine-learning spam and phishing filters. SMS has almost none — the message lands directly in your hand. 2. You cannot inspect the link. Links in texts are shortened and unreadable, and the only way to "see where it goes" is to open it, which is exactly the trap. 3. High trust and instant attention. Texts are where real one-time codes and delivery updates arrive. Open rates approach 100%, usually within minutes. 4. Sender ID spoofing. An attacker can set the displayed sender name so the scam text lands inside the same thread as your bank's genuine messages, right underneath them. A message appearing "in the usual place" proves nothing at all.

The smishing templates you will actually receive

Different countries, same skeleton. The most common worldwide: • Delivery: "Your parcel is being held. Pay the $1.99 customs fee to release it: [link]" — works because almost everyone is waiting for a package. • Toll road / traffic fine: "Unpaid toll of $4.30 detected. Pay now to avoid a penalty: [link]" — a small, oddly precise amount you would not bother disputing. • Bank alert: "Unusual activity detected on your account. Verify immediately: [link]". • Card issuer: "A suspicious transaction was detected on your card. Approve or cancel: [link]". • Tax refund: "You are eligible for a refund. Update your bank details to receive it: [link]". • Wrong number that becomes a romance or crypto approach: "Hi, is this Sarah?" — no link at all at first, just a conversation that turns into an investment pitch weeks later. Notice the pattern: a familiar institution, a small sum or a reward, artificial urgency, and a link. Almost always all four together.

7 warning signs you can check in ten seconds

• The domain is not the official one. Read it character by character: royalmail.com is real, royal-mail-delivery.info is not; paypal.com is real, paypa1.com is not. • A shortened link (bit.ly, tinyurl, cutt.ly) in a message asking for money or personal details. Real institutions do not shorten their links. • An unusual top-level domain for a major company: .xyz, .top, .icu, .info. • A small, non-round amount ($1.99, $4.30) — chosen deliberately so you pay rather than check. • Manufactured urgency: "within 24 hours", "to avoid a fine", "your parcel will be returned". • A generic greeting with no name, no tracking number, no last four digits of your account. A real organisation chasing a debt knows who you are. • A request to enter a password, CVV or one-time code through the link. There is no legitimate situation where this happens.

How to check a suspicious text without tapping the link

This is where most people go wrong: do not open it "just to see". Loading a malicious page can fingerprint your device, serve you a tailored fake login screen, or trigger a download. Instead: 1. Long-press the message → Copy. 2. Paste it into the free checker at the top of this page. 3. In a few seconds you get a clear verdict: safe, suspicious, or phishing — with a short explanation of why. The check runs on our side, in an isolated environment: we follow the shortened link all the way to its final destination, compare it against global phishing databases (Google Safe Browsing, VirusTotal and others), and analyse the wording of the message itself. Your phone never touches the link. No signup, no install.

How to verify a real debt, parcel or bank alert

The rule is absolute: never verify through the link in the message. Always through a channel you open yourself. • Delivery — open the courier's official app, or type the address manually, and check the tracking number the shop gave you (not the one in the text). • Bank or card issuer — open the official app, or call the number printed on the back of your card. Never a number from the message. • Government or tax — type the official domain yourself. Tax authorities do not announce refunds by text. If the debt, parcel or alert does not appear in the official channel, the message is a scam. Delete it and block the sender.

If you already fell for it: do these in order

The first minute matters more than everything after it: 1. Entered card details — call your card issuer now (number on the back of the card) and freeze the card. Most jurisdictions protect you against fraudulent charges, but fast reporting is what makes that protection work. 2. Entered banking credentials or a password — call your bank, then change that password everywhere else you reused it. 3. Gave away a one-time code — sign in to the account, sign out all other devices, and turn on two-factor authentication. 4. Report it. In the UK forward the text to 7726 (free); in the US report to the FTC at reportfraud.ftc.gov; in Israel call 119. Reporting is what gets the fake site taken down and protects the next person. 5. Screenshot the message and the link before deleting — you will need it for the chargeback claim. And no, there is nothing to be embarrassed about. These messages are written by professionals and sent to hundreds of thousands of people at a time.

Preventing smishing before it reaches you

The Phishy app scans incoming SMS and WhatsApp messages and warns you before you tap, rather than after. But the people hit hardest are older parents, who tend to pay quickly "to avoid trouble". With Family Mode you connect a parent's phone with their consent — and when a smishing message arrives on it, you get an alert immediately, without ever seeing any of their private messages. For someone who will not check a link themselves, that is the only protection that actually works.

Want Phishy to check every message automatically — for your parents and kids too?
The free app scans your texts and WhatsApp automatically and warns you before you tap. Download now:
App Store — iPhone▶ Google Play — Android

FAQ

What is smishing?

Smishing is a phishing attack delivered by SMS or text message. The name blends SMS and phishing. The scammer sends a text impersonating a trusted organisation — a bank, a courier, a tax office — with a link to a cloned site that steals your details or money.

What is the difference between smishing and phishing?

They are the same con through different channels. Phishing arrives by email, smishing by text message, vishing by phone call, and quishing through a fraudulent QR code. Smishing is often more dangerous than email phishing because SMS has almost no spam filtering and you cannot hover over a link to see where it leads.

What is vishing?

Vishing (voice + phishing) is a scam carried out over a phone call — for example someone claiming to be from your bank's fraud team asking for a one-time code or card details. The rule is the same: a genuine institution will never ask for a password or code over the phone.

How do I spot a smishing text?

Look for the four ingredients together: a familiar organisation, a small amount or reward, urgency, and a link. Then check the link itself — a domain that is not the official one, a shortener, or an unusual extension like .xyz or .top is a strong tell. A message with no name, no tracking number and no account digits is suspicious by default.

How can I check whether a text is a scam without clicking the link?

Long-press the message, copy it, and paste it into the free checker on this page. The check runs in an isolated environment on our side — we follow the link to its real destination and compare it against global phishing databases. You get an answer in seconds, with no signup and without your phone ever touching the link.

Is it dangerous just to open a smishing link?

Opening a link alone is usually not enough to steal your data — the damage happens when you enter details or install something. Still, a malicious page can fingerprint your device or serve a tailored fake login screen, so close it, enter nothing, and download nothing. If you installed an app from the link, remove it immediately and run a security scan.

I entered my card details — what should I do first?

Freeze the card first, by calling your card issuer on the number printed on the back. Only then review recent transactions, dispute anything you did not authorise, and report the scam. Speed is what limits the damage.

How do I report a smishing message?

In the UK, forward the text to 7726 free of charge. In the US, report it at reportfraud.ftc.gov. In Israel, call the National Cyber Directorate on 119. Reporting helps get the fake website taken offline.

Can I block smishing messages completely?

Not entirely — scammers rotate through numbers constantly. What you can do is block each sender that scams you and install an app that scans incoming messages and warns you before you tap. Phishy does this for free, and in Family Mode it also alerts you when such a message reaches an elderly parent.

Why do scam texts always ask for such small amounts?

Because a $2 fee is not worth disputing. Nobody calls a helpline over two dollars — they just pay and move on. But the scammer does not want the $2; they want the full card number, expiry and CVV you type into the payment page. The small sum is the bait, not the goal.

Want Phishy to check every message automatically — for your parents and kids too?
The free app scans your texts and WhatsApp automatically and warns you before you tap. Download now:
App Store — iPhone▶ Google Play — Android
More guides:Deepfake scams: how to spot AI voice and video fraudThe Facebook romance scam: when a beautiful stranger messages firstKeeping kids safe on Roblox and online gamesHow to protect elderly parents from online scamsHow to protect your kids from online scams"Your parcel is on hold" — the fake customs-fee scamText "from your bank" — how to spot the impersonationSuspicious WhatsApp message — check before you replyHow to tell if a link is safe before you click"Congratulations, you've won" — the fake-prize scamCrypto and investment scams — the guide