How to verify an unknown call or message without putting yourself at risk
Before you call back or tap a link, use this protocol to check who is behind the contact, protect your information, and decide when to block and report it.
NoCall Blog
Clear guides to identify calls, prefixes and scams before you answer.
A missed call, an urgent text, or a WhatsApp message can look legitimate within seconds. The caller ID may show a company name, the voice may sound professional, and the message may use real details about you. None of that proves who sent it. Caller ID can be spoofed, and links can lead to near-perfect copies of familiar websites.
The safest way to check is to separate verification from response: investigate through a channel you control first, then decide whether you need to reply.
The five-minute rule
Before calling back, replying, or opening a link, pause for five minutes and ask:
- Was I expecting this contact? If you were not expecting a delivery, a bank call, or a specific request, treat it as unverified.
- Am I being pushed to act now? Threats, expiring discounts, locked accounts, and instant prizes create pressure; they do not prove authenticity.
- Is it asking for something I should never share? Passwords, one-time codes, PINs, signing keys, full card details, or remote access are hard limits.
- Does the number or link match exactly? A name on screen is not enough. A domain with one changed letter or a shortened URL can hide the real destination.
- Can I check it without using information from the message? If the only option is to call the displayed number or tap its link, you have not verified anything yet.
If an answer feels wrong, do not try to talk yourself into it. End the contact, save the evidence, and move to an independent check.
How to verify a phone call
1. Hang up when the call is unexpected
You do not have to be polite or solve a problem during an unsolicited call. Say that you will verify the information yourself and end the call. Do not press keys, dial codes dictated by the caller, or install an app so they can “help” you.
The voice, accent, and number on screen do not authenticate anyone. Caller-ID spoofing can make a call appear to come from a business, government office, or even someone you know.
2. Find the official channel yourself
Open the official app or type the organisation’s address into your browser. Use the support number printed on a card, contract, bill, or website you already trusted—not a number supplied by the caller. If you have an account, sign in through the official app or site and check for an alert there.
For a family member or friend, contact them using the number already saved in your address book. Do not answer a new thread just because it uses their name or profile photo.
3. Check the context, not just the name
A real organisation can confirm that an issue exists, but the confirmation should come through an independent channel. Check the request in the official app or ask for an in-account notification. Never read out a verification code to “confirm your identity”: that code confirms access, not the identity of the person calling.
How to verify a text, email, or chat message
Do not open the link to inspect it
A link can lead to a fake page or download harmful software. If the message says there is a problem with an account, type the official address yourself or open the app. Look for the alert inside the account, not through the received link.
Notice the signals, but do not rely on spelling
Urgency, requests for financial information, lookalike domains, shortened links, and unexpected attachments are important warning signs. Spelling mistakes are no longer a reliable test: fraudulent messages can be perfectly written. The content and the independent verification channel matter more than the style.
Do not reply just to ask whether it is real
A reply confirms that your number or account is active and can open a pressure conversation. If the message looks suspicious, use your device or service’s report-spam option and then delete it. Do not click an “unsubscribe” link inside an unexpected message either.
Information you should never give to an incoming caller
- Passwords, PINs, or one-time passcodes.
- Signing keys, recovery codes, or a wallet recovery phrase.
- Full card numbers, security codes, or banking credentials.
- Remote access to your phone or computer.
- Photos of identity documents unless you started the process and verified the channel yourself.
A legitimate organisation may ask you to sign in through its official channel, but it does not need your password or an authentication code read aloud during an unexpected call.
What to do when verification fails
- Do not reply or call back using the contact details in the message.
- Save a screenshot showing the number, time, text, and visible link without opening it.
- Search the number in NoCall’s directory to check for reports and add your own.
- Block the contact and report it as spam from your phone or app.
- If you shared information or opened a link, move straight to what to do during the first hour after a phone scam.
In short
Verification does not mean getting the caller to persuade you. It means closing the received channel and opening one you control. Hang up, use the official app or website, call a number you already trusted, and never share codes or credentials. If you cannot confirm the contact independently, treat it as fraudulent, report it, and move on.
Sources and review
Reviewed:
Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.
Article details
Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.
Received a suspicious call?
Look up the number in NoCall before sharing data, calling back, or clicking any link.
Search a phone number or a company name (Bank of America, Verizon and AT&T...) to check if it has been reported as spam.
