# What Is Smishing? How to Stop Scam Texts

> Smart people click smishing links too. Why SMS scams work on the informed - and the iPhone and Android settings that protect you when you don't notice.

By Lucas · June 27, 2026 · 8 min read · Awareness

Source: https://bluwarden.com/blog/smishing-anatomy-phone-protection

---

## The hook: the two seconds that change everything

A friend texted me two words: "Got caught." Minutes earlier, a message had landed on their phone claiming to be from the tax office, warning of a "mandatory verification," with a link to `gov-taxrefund.help`.

Obvious, right? The real tax authority's domain doesn't end in `.help`. The scam name stitches two familiar words together to manufacture a feeling of trust. But this article isn't about "how to spot a fake link" - thousands of those exist already. It's about something more uncomfortable: **why the same people who read those articles still click.**

---

## The attacker's view: why smishing is the cheapest effective attack

For an attacker, SMS phishing - smishing - is a gift, for three reasons.

- **The channel is trusted by default.** People have been trained for decades to distrust links in email. SMS still feels personal and safe: your bank, your courier, your doctor all text you. That inherited trust is exactly what gets exploited.
- **The screen is small and attention is short.** Mobile browsers routinely hide the full URL, and notification previews show only the link *text*, never the actual domain. The signals you'd use on a desktop simply aren't visible.
- **The cost is near zero.** Bulk SMS tools and leaked phone-number lists cost pennies. Even a 0.1% response rate is profitable, so attackers send millions and don't care about the 99.9% who ignore it.

In my friend's case the attacker combined **authority** (a government body) with **urgency** ("verification is mandatory, now"). That's a textbook pressure combination, and it works regardless of someone's IQ or IT knowledge, because it targets instinct, not logic.

---

## The defender's view: why repeating "be careful" has limits

That reply - "got caught" - isn't random. In security we call it the **awareness-behaviour gap**: people know the rule, but in a specific, emotionally charged moment the rule doesn't fire. Three things drive it.

- **Cognitive fatigue.** The average person gets dozens of notifications a day. The brain leans on shortcuts ("looks like it's from the bank" = real), because fully analysing every message is exhausting and unsustainable.
- **Context collision.** If you genuinely are waiting on a parcel, or you do have an unpaid bill, a scam message that mentions exactly that lands directly on a real worry. Timing does most of the work.
- **The mobile environment strips away signals.** On a desktop you see the full URL in the address bar. On a phone you often see only a button that says "Verify here."

The lesson for anyone doing training: telling people "be careful" for the tenth time doesn't work better than the first. You need two layers - the human (awareness) and the technology (a system that stops the threat before the human has to make a decision at all). For teams, that human layer is best built with realistic practice, not lectures - which is the case for [phishing simulations](/blog/phishing-simulation-why-companies-need-it).

---

## Practical defence: the 5-point check

If a link has already arrived and nothing has flagged it, run these five checks before you tap.

1. **The domain ending.** A real `.gov` site is not `gov-refund.help`; `mybank.com` is not `mybank.account-verify.info`. Read the ending right before the first single slash, not the reassuring words in front of it.
2. **The sender.** Institutions rarely text from a random personal mobile number.
3. **The urgency language.** "Mandatory," "immediately," "your account will be blocked" are markers of emotional pressure, not how official notices actually read.
4. **Were you expecting this?** If your bank, the tax office, or a courier reaches out unprompted, treat that as a signal, not a coincidence.
5. **Verify on another channel.** Open a browser yourself and type the known address by hand, or call the number on your card. Never use the link you were sent - and don't assume a number you found via [a Google or AI search is genuine](/blog/scam-phone-numbers-ai-overviews) either; scammers plant fake support numbers there too.

---

## Technical defence: settings that protect you even when you don't notice

This is the most important part. A checklist depends on you being alert every single time. Settings work when you're tired, distracted, or in a hurry - which is exactly when you get caught. Turn these on once. (These pair well with the broader steps in our [Android](/blog/android-standard-security-hardening) and [iOS hardening guides](/blog/ios-standard-security-hardening).)

### Android (Google Messages)

Google Messages has built-in protection that warns about dangerous links and can block access to malicious sites when a message is flagged as suspicious.

**How to turn it on:**

1. Open the Google Messages app.
2. Tap your profile icon (top right) → **Messages settings**.
3. Choose **Spam protection** (on some phones: "Protection & Safety" → "Spam Protection").
4. Turn on **Enable spam protection**.

With it on, the system checks links in your messages against Google's safety database and, if a link is judged dangerous, blocks it until you mark the message as "Not spam" yourself.

**Worth knowing:** Android doesn't have a single switch for "block all links from unknown numbers." Protection works through threat analysis, not a contact list, so pair Spam protection with the 5-point check above.

### iOS (iPhone Messages)

iPhone has a feature that comes closest to what people actually want: it stops you opening a link from a sender who isn't in your contacts until you approve them.

**iOS 26 and newer:**

1. Open the **Messages** app and tap the filter icon (top left) → **Manage Filtering**.
2. Turn on **Screen Unknown Senders**. (The matching *notification* controls also appear under **Settings → Apps → Messages → Unknown Senders**, but the toggle itself lives in the Messages app.)
3. Optionally turn on **Filter Spam** so suspicious messages are sorted automatically.

**iOS 18 and older:**

1. **Settings** → **Messages**.
2. Find **Message Filtering**.
3. Turn on **Filter Unknown Senders**.

With this on, messages from unknown numbers go to a separate "Unknown Senders" list and - crucially - the links in them can't be tapped until you either mark the sender as known or reply to the message. That's effectively "links from strangers are off by default."

**One trap:** if you ever reply to the message - even once, even just to mock the scammer - the sender can get treated as "known" for future messages. So **never reply to a suspicious text**, full stop.

---

## Quick wins vs long-term strategy

| | Quick win (5 min) | Long-term |
|---|---|---|
| **Android** | Turn on Spam protection | Check the "Spam & blocked" folder regularly; teach family to read domain endings |
| **iOS** | Turn on Screen Unknown Senders | Never reply to unknown messages; periodically review the "Unknown Senders" list |
| **Both** | Add your bank's / tax office's real number to contacts from an official source | Run a short family or team drill with a real smishing example |

---

## Last word

The friend who wrote "got caught" isn't an exception - they're a statistic. Phishing and smishing success rates don't fall because people magically get smarter in a vacuum. They fall when technology starts doing the work instead of memory.

Your job - as a manager, an educator, or just a family member - isn't only to remind people to "be careful." It's to help them turn on the settings, once, that will protect them every time after that.

---

## Summary

1. **Smishing works on urgency, not ignorance.** The lure is a two-second window - a delivery, a fine, a refund - not a test of how much you know.
2. **Read the end of the domain, not the start.** `gov-taxrefund.help` is the `.help` domain, not the tax office. Everything before the final dot is decoration.
3. **Turn on the filter.** Android: Google Messages → Messages settings → **Spam protection**. iPhone (iOS 26+): Messages → filter icon → Manage Filtering → **Screen Unknown Senders**, which also stops you opening links from strangers.
4. **Never reply, not even once.** On iOS a reply can promote the sender to "known" and re-enable their links.
5. **Save real numbers yourself.** Add your bank's and tax office's contact details from a statement or official site, so you never have to trust a number that arrived in a text.
6. **Get to the account another way.** Open the bank's own app or type the address by hand. If the message was real, the same notice is waiting there.
7. **Extend it to the phone and the browser too** - the same reflex covers [scam numbers surfaced by AI assistants](/blog/scam-phone-numbers-ai-overviews).

---

*Want to test whether your team would actually catch a real one? [Get in touch](/#contact) about a phishing and smishing simulation built around your organisation.*
