
To spot an SMS scam, pause before acting, look for an unexpected request or pressure to pay, and verify the message through the organisation’s official app, website or a contact number you already trust. AI can help examine redacted wording. It cannot certify that the sender, link or payment is safe.
“Your parcel is held. Pay R25 to release it.”
It sounds like a small inconvenience with a small price tag. That is exactly why it deserves a second look. The payment may be small. The invitation to hand over your card details is not.
Episode 3 of Everyday AI, “Is this a scam?”, uses a South African parcel-text example. R25 is an illustrative amount, not an official courier fee or a claim about a real delivery. Whether your message mentions rand, pounds or dollars, the useful habit is the same: slow down, ask better questions and check outside the message.
Watch Episode 3: Is this a scam?
The short video shows a parcel text, an AI question and warning signs, followed by the important instruction to check directly. This written guide adds the privacy step: remove personal details and the live link before asking AI for help.
How to spot an SMS scam without opening its link
An SMS scam, often called smishing, tries to turn a text into an action that benefits the sender. A message might ask for a delivery payment, a login or information that you would normally protect.
The US Federal Trade Commission’s text-scam guidance describes fake delivery notifications and messages that lead to imitation websites. Its central advice is practical: use contact details you know are genuine, not those supplied in the suspicious text.
Look for a mismatch between the message and what you know:
- Are you actually expecting that delivery, refund or request?
- Does it demand payment or private information before you can check the details?
- Is it pushing you to act immediately?
- Does the displayed address hide where you would end up?
- Can you find the same request in the official app or account you opened independently?
A warning sign is a reason to check, not proof on its own. A genuine delivery can involve a problem, and a scam can arrive while you are expecting a parcel. Neither coincidence settles the question.
Do not use spelling as your safety test. A message can be neatly written and still be deceptive. The UK National Cyber Security Centre explains how scams use apparent authority, urgency and emotion. Professional-looking wording is not independent verification.
A practical five-step AI message check
1. Stop the action, not just the conversation
Leave the message’s links and payment instructions alone. Do not reply with account details or a code. You do not need to open a suspicious page to ask whether the wording deserves caution.
If this concerns work, follow your organisation’s reporting procedure. A suspicious invoice or account alert belongs with the person responsible for that account, not in a casual group chat containing client details.
2. Make a safe, plain-text version
Copy only the wording needed for the exercise. Remove names, phone numbers, account or tracking numbers, addresses, passwords, card details and one-time codes. Replace the whole web address with [link removed].
For example:
Your parcel is held. Pay a small release fee today at [link removed].
You can add non-sensitive context: “I am not expecting a parcel” or “I am expecting an order, but I have not checked the official app yet.” Do not supply private order records just to make the AI sound more certain.
Removing information is not a guarantee of complete anonymity. Use only an AI service that is suitable for the information you intend to share, and follow your workplace’s data rules.
3. Ask for warning signs, not a verdict
Use this prompt:
Review this redacted message for warning signs. Do not open or follow links. Separate what the wording actually says from assumptions. List what I should verify through an independently found official source. Do not declare the message genuine or safe. Message: [paste redacted wording]. Context: [brief non-sensitive context].
This is a reading exercise, not a security scan. The prompt gives the assistant a narrow job and makes uncertainty visible. A confident answer still needs checking.
4. Turn the answer into a verification checklist
Imagine the AI replies: “The message asks for money, imposes a deadline and uses an unfamiliar payment route.”
Your next step is not “AI says scam, case closed.” It is to check the delivery status in the courier’s official app, review your order with the retailer, or contact the organisation through details you found independently.
If it says “this looks legitimate”, the same independent check still applies. You have inspected a piece of wording, not authenticated the sender. A useful AI answer explains what remains unknown.
5. Decide what to do using the real source
Do not pay through the message while you investigate. If the organisation confirms that the request is false, use the reporting options in your messaging app or ask your mobile network for the appropriate route in your country. Do not assume one country’s reporting shortcode works everywhere.
Keep any evidence needed for a bank, employer or official report before deleting the message. Do not circulate the live link to friends as a warning. Explain the pattern instead.
What if I already clicked or shared information?
Do not waste the next ten minutes blaming yourself. What happened next matters more than how convincing the message was.
The NCSC’s guidance for people who have shared sensitive information distinguishes the response by what was exposed:
- Bank or card details: contact your bank immediately through its official app or trusted number. Tell it what you shared and ask what needs blocking or checking.
- A password: change it through the real service. Change it on other accounts where you reused it.
- Software installed or a link opened: use your device’s established security tools or get help from a trusted IT professional. If it is a work device, report it to your IT contact.
Do not ask a chatbot to investigate your banking login or paste a one-time code into it. If money is missing, contact your bank and the appropriate local reporting authority. The reporting route depends on where you live.
The small-business lesson: build a pause into the workflow
The same habit is useful beyond parcel texts. Treat an unexpected change to supplier bank details, an urgent payment request or a customer-data request as a reason to verify through an established contact route.
A simple team checklist can ask: What is being requested? Who is responsible for checking it? How will the sender be confirmed independently? Who approves the action? Use this as a proposed process, not as a substitute for your existing IT, finance or security controls.
Ankor’s practical AI business systems focus on structured work and human approval. Ankor Nexa helps organise business context, plans and drafts; the Ankor Nexa product page explains the offer. It is not a scam detector and does not authenticate couriers, bank messages or supplier accounts.
The connection is the working habit: let AI help you prepare a clearer checklist, then let a person verify and approve the real action. If you want to try Ankor’s business workflows, the current offer includes a seven-day free trial, with no card and no automatic charge. Check the Ankor FAQ for access and trial details.
Frequently asked questions
Can AI tell me for certain whether an SMS is a scam?
No. AI can help examine wording and suggest checks, but it cannot certify the sender or a link as safe. Verify the request through an official app, website or trusted contact route you found independently.
What should I remove before pasting a message into AI?
Remove names, phone numbers, account and tracking numbers, addresses, passwords, card details, one-time codes and the live link. Keep only the wording and brief non-sensitive context needed to understand the request.
Does a small parcel fee mean the message is a scam?
Not by itself. An unexpected fee, pressure to pay or an unfamiliar payment route is a reason to pause. Check the delivery with the real courier or retailer before making a payment.
What should I do if I gave away card details or a password?
Contact your bank immediately if banking details were shared. Change an exposed password through the real service and anywhere else you reused it. Follow your employer’s reporting procedure for a work account or device.
Is Ankor Nexa a fraud-detection product?
No. Ankor Nexa supports structured AI-assisted business work, drafts and human approval. It does not replace bank checks, cybersecurity tools or independent verification of a sender.
Save this guide and share the habit: pause, redact, ask, verify. Everyday AI from Ankor helps you learn one practical use at a time, while you stay in charge.
Stay in the loop
Get practical AI tips and product updates, no spam, unsubscribe any time.