What Is Smishing? SMS and Text Scams Explained
Smishing is phishing done through SMS or text messages. A scammer texts you pretending to be a bank, a courier, or a service you use, and includes a link or a phone number that leads to a fake page or a fraudster. The name is simply “SMS” plus “phishing,” and it works because a text feels personal and urgent.
Why text scams work so well
People trust their inbox less than they used to, but a text still feels immediate and legitimate. Smishing exploits that. A message arrives on the same screen where your real bank and delivery updates appear, it uses a familiar name, and it gives you a small, urgent task: pay a tiny fee, confirm a detail, claim a reward. The link does the rest.
Because texts are short, there is little room for the errors that used to give scams away. That makes the structural checks below more useful than judging the wording.
Common smishing examples
- Fake delivery fees. “Your parcel is held, pay a small customs fee to release it.” See the parcel delivery fee scam.
- Bank alerts. “Your KYC will expire today, update now to avoid a block,” like the SBI and HDFC KYC scams.
- Prize and refund notifications. “You have won” or “your refund is pending,” designed to get your card details.
- Job offers. Unsolicited “work from home” texts that lead to pay-to-earn task scams.
- Account warnings. “Suspicious login detected,” pushing you to a fake login page.
The warning signs of a smishing text
- A link that is not the exact official domain. A shortened link or extra words like
-verifyor-kycare red flags. - A tiny fee to release something. Real duties are not collected through a chat link for a few rupees.
- Requests for an OTP, PIN, or card number. No legitimate service asks for these by text.
- A reply-to number that is an ordinary mobile, not an official channel.
- Pressure to act today, or within a couple of hours.
What to do about a suspicious text
- Do not tap the link or call the number in the message.
- Verify independently. Open the official app or type the website yourself, or call a number from your card or a printed bill.
- Check the link safely. Paste it into a link safety checker so it opens in a sandbox, not on your device.
- Do not install anything the text points to, especially APK files.
- Report and delete. Forward the message to your carrier’s spam reporting service, then delete it.
If you already entered details, follow the steps in our guide on what to do after clicking a phishing link.
The quickest check
You do not have to decide alone. Forward the text to Kaval on WhatsApp and it inspects the link, the domain, and the wording, then tells you in seconds whether it is safe or a scam, plus what to do next. It is free, and it is a good habit to teach anyone in your family who gets a lot of texts.
Smishing is just phishing wearing a text message. For the wider picture, read what is phishing, and for phone-call versions, see what is vishing.
Frequently asked questions
What is smishing? Smishing is phishing carried out through SMS or text messages. A scammer sends a text pretending to be a bank, courier, or service, with a link or number that leads to stolen details or money. The word combines SMS and phishing.
Can a text message hack my phone? Simply reading a text will not hack your phone. The danger comes from acting on it: tapping a malicious link, installing an app it points to, or sharing an OTP or password. Do not click links or install files from unknown senders.
What are common smishing examples? Fake parcel delivery fees, bank KYC or account-block warnings, prize or refund notifications, and job offers are the most common. They all use urgency and a link or phone number to pull you in.
How do I check if a text message is a scam? Do not use the link or number in the message. Verify through the official app or a number you find yourself, and if you are unsure, forward the message to a scam checker like Kaval on WhatsApp for a verdict before you act.