August 17, 2026
What Is Smishing? How to Spot and Stop SMS Phishing Texts
What is smishing?
Smishing (a blend of "SMS" and "phishing") is a scam where fraudsters send text messages designed to trick you into clicking a malicious link, calling a fake number, or handing over personal and financial information. It's the SMS version of email phishing — and it's become one of the fastest-growing forms of fraud, because a text message feels more immediate, more personal, and more trustworthy than an email.
Smishing texts typically impersonate a brand or organisation you already trust: your bank, a delivery courier, a parking app, a government tax office, or even a family member. The goal is always the same — get you to act quickly, before you stop to think.
How does smishing work?
Most smishing attacks follow the same basic pattern:
- You receive an unexpected text claiming there's a problem: an unpaid parcel delivery fee, a suspicious bank login, an overdue parking charge, a tax refund waiting, or a locked account.
- The message creates urgency — "act within 24 hours," "your account will be suspended," "final notice."
- It includes a link to a website that looks like the real thing but is actually a lookalike domain built to steal your login, card details, or personal information.
- Some messages ask you to reply first (often with "Y" or "STOP") before the link becomes clickable — a trick to bypass spam filters and, on iPhone, to get iMessage to activate a link from an unknown sender.
If you enter information on the fake site, or call the number provided, scammers can drain your bank account, open credit in your name, or resell your data to other criminals.
Common smishing examples
- "Your parcel couldn't be delivered — pay a redelivery fee" (impersonating a courier)
- "Unusual activity detected on your account — verify now" (impersonating a bank)
- "You have an unpaid parking charge — pay to avoid a fine" (impersonating a parking app — see our breakdown of the RingGo text scam for a real-world case study)
- "You're eligible for a tax refund — claim here" (impersonating a tax authority)
- "Your subscription payment failed — update your card" (impersonating a streaming or subscription service)
All of these follow the same playbook: a trusted name, an urgent problem, and a link.
Smishing vs phishing: what's the difference?
Phishing is the broad category of scams that trick you into giving up sensitive information — it can happen by email, phone call, social media, or text. Smishing is phishing carried out specifically over SMS or text message. It's often more effective than email phishing because texts have higher open rates, feel more personal, and are harder to filter — most people are used to spam email but still trust texts by default.
Stop scam texts before they reach you
SMS Filter can automatically block messages containing a link from unknown senders, plus scam keywords — free to download, all on-device.
How to spot a smishing text
- Unexpected urgency. Real organisations rarely demand instant action by text.
- A link that doesn't match the official domain. Hover or long-press the link (without tapping) to preview the actual URL — look for extra words, unusual endings, or misspellings of the real brand name.
- Requests to reply before the link works. No legitimate company asks you to text "Y" to "activate" a link.
- Generic greetings and poor spelling. "Dear customer," typos, and odd punctuation are common red flags.
- A sender number that looks like a random mobile number, not a short code or the brand's known sender ID.
If you're ever unsure whether a message is real, don't use the link in the text. Open the official app or type the company's known website address directly into your browser instead.
What to do if you receive a smishing text
- Don't click the link and don't reply.
- Don't call any number included in the message.
- Report it. In the UK, forward suspicious texts to 7726 (spells "SPAM" on a keypad), a free reporting service run by mobile carriers. In the US, you can report smishing to the FTC at reportfraud.ftc.gov or forward it to your carrier.
- Delete the message once reported.
- If you already clicked a link or entered details, contact your bank immediately, change any reused passwords, and monitor your accounts for suspicious activity.
How to protect yourself from smishing long term
- Never click links in unsolicited texts — go to the official app or website directly instead.
- Enable your phone's built-in spam protection where available.
- Use a dedicated SMS filter to block spam and smishing automatically before it reaches your inbox, like SMS Filter. It includes a smart filter that blocks any text containing a link from an unknown sender — the single most effective automated rule against smishing, since almost every smishing text relies on getting you to tap a link. Learn more on how SMS Filter can protect you.
- Keep your number private where you can, since leaked or sold phone numbers are the main source of smishing campaigns.
- Talk to family members, especially those less familiar with these scams — smishing disproportionately targets older adults and people who are less used to spotting phishing red flags.