Suspicious Message
First Aid
Paste a strange text, email or DM. This page looks for caution signals, shows the exact words that triggered them, and gives you a way to verify independently. It does not decide “scam” or “safe.”
Privacy: this page runs entirely in your browser. It has no analytics, account, server upload, external scripts, or AI API. Reloading discards what you typed.
Independent verification path
- Do not use the message’s link, phone number or reply path yet.
- Open the organization’s app yourself, type the known website yourself, use a saved bookmark you already trust, or use a phone number from a card, bill, statement or official document you already had.
- Ask whether the event in the message actually appears there.
- Never give a one-time verification code, password, recovery code or remote-control access because someone contacted you unexpectedly.
- If money is involved, verify the recipient and purpose through a second channel before paying.
The point is to break the attacker’s control of the communication channel. Independent verification is stronger than trying to become a human URL detector.
Why these patterns matter
Urgency / threat
Pressure reduces the time you spend checking. Urgency is a manipulation tool, but it can also occur in legitimate notices.
Credential / code requests
Passwords and one-time codes can transfer control of an account. Legitimate support generally should not need you to read them a code sent for login or recovery.
Unusual payment
Gift cards, crypto, wires and “friends & family” style transfers are hard to reverse and are commonly abused.
Remote access
Installing screen-control software can give a stranger the ability to observe or control your device.
Links
A displayed brand name does not prove the destination domain. Short links can also hide the destination.
Secrecy
“Do not tell anyone” removes the second opinion that could interrupt manipulation.