Ultra Prompt

← All articles

How to tell if a text or email is a scam before replying

Your dad just got a text about an unpaid toll bill he never received. One click could hand over his savings. Scammers have gotten good at exactly this moment: the message sounds plausible, the urgency is real enough to feel, and replying feels like the responsible thing to do. It isn't. The fastest way to protect him is to spot the scam before anyone responds. A basic checklist helps. A structured AI prompt does it better, faster, and without missing the tricks a human eye skips over. By the end of this guide you'll have a ready-to-copy "Scam Detector Prompt," a three-step prompt-chaining workflow, and eight side-by-side examples that show exactly why vague questions get vague answers.

The five red flags that show up in nearly every scam

Scammers don't reinvent the wheel. They use the same playbook because it works. Learn to spot five patterns and you'll catch the vast majority of phishing texts and emails before they do any damage.

1. Manufactured urgency

Phrases like "immediate action required," "your account will be closed in 24 hours," or "pay now to avoid legal action" are designed to short-circuit your thinking. Real institutions give you time. Scammers can't afford for you to pause and check.

2. An unfamiliar or spoofed sender

The display name might say "FedEx" or "IRS," but the actual sending address or number is a random string. On a phone, the number often shows as a local area code to seem familiar. On email, hover over the sender name to reveal the real address underneath.

3. A request for personal or financial information

No legitimate company will ask for a bank account number, Social Security number, or credit card via text or unsolicited email. If the message wants money or credentials, treat it as a scam until you verify through official channels.

4. Corporate branding mixed with bad grammar

A real toll authority or bank has editors. Scam messages often have the logo of a real company alongside "We noticed irregulary in you're account." The mismatch is intentional in some cases (it filters out skeptical people) and sloppy in others. Either way, flag it.

5. Mismatched or hidden links

The link text might say "pay.ezpass.com" while the actual URL underneath points somewhere completely different. On desktop, hover before you click. On mobile, hold the link to preview the destination. If the domain doesn't match the organization's official website, stop.

Here's what that looks like when you run a real message through an AI prompt:

BEFORE: "Your toll bill is overdue! Pay now at http://secure-tollpay.com to avoid legal action."

AFTER (AI analysis):
- Urgency flag: YES ("avoid legal action")
- Sender verification: UNKNOWN number, not in official toll authority contacts
- Request for payment: SUSPICIOUS URL (domain does not match any official toll authority)
- Verdict: POTENTIAL SCAM

Spot any one of these five cues and treat the message as suspicious until proven otherwise. You don't need all five to be confident. One is enough to pause.

Paste the message, check the signals

The fastest first step is to copy the entire text or email body into a structured AI prompt. Don't just ask "is this a scam?" That question gets you "it might be" and nothing useful. Ask the model to extract specific signals and return them in a format you can act on.

This template works in any LLM chat interface you already use, including ChatGPT, Claude, or Gemini:

You are a scam-detection assistant. Analyze the following message and return JSON with these keys:
{
  "urgency": true/false,
  "unknown_sender": true/false,
  "payment_request": true/false,
  "bad_grammar": true/false,
  "suspicious_link": true/false,
  "verdict": "SAFE | SCAM | NEEDS_REVIEW"
}

Flag "suspicious_link" as true if any URL does not match the organization's
official domain. Flag "unknown_sender" as true if the sending number or
email address cannot be verified against official contact information.

Message: <<>>

The structured output matters. A JSON response means you can see exactly which flags triggered the verdict, not just a yes/no. If your dad forwards you the text, you paste it in and have a machine-readable answer in about 10 seconds.

One thing worth knowing: the AI is doing pattern recognition on the text you give it, not live database lookups, unless you're using a model with web access or tool integrations. Treat its verdict as a strong signal, not an infallible one. You still make the call. The model narrows it down so your judgment goes to the right place.

Verify through the front door, never the link

The single most dangerous thing anyone can do with a suspicious message is click the link to "check if it's real." That's exactly what the scammer wants. Instead, go to the front door: type the organization's official website address directly into your browser, or call the number listed on their official site.

For links you've already spotted, you can check them without ever clicking. Copy the URL and run this sub-prompt:

Analyze the following URL without visiting it.

URL: http://secure-tollpay.com

Return:
{
  "matches_official_domain": true/false,
  "notes": "Brief explanation of what the domain is and who registered it",
  "verdict": "SAFE | SUSPICIOUS"
}

If you cannot verify the domain as an official government or corporate domain,
mark it SUSPICIOUS by default.

For a more technical check, paste the URL into VirusTotal (a free URL scanner) or run a WHOIS lookup on the domain. A toll-payment domain registered very recently that claims to be an official government portal is a red flag worth investigating further. WHOIS lookup will show you the registration date and registrant details in seconds.

Try this: Before calling your dad back, paste the URL from his text into VirusTotal and the sub-prompt above. If either flags it suspicious, you already have your answer and can tell him exactly why not to click.

If front-door verification fails, the message is a scam. It doesn't matter if every other signal looked clean. A mismatched domain ends the investigation.

For more on integrating AI safety checks into practical workflows, the guide on how to safely integrate AI systems with a security checklist covers the same verification-first mindset in a different context.

What to do if money already moved

Sometimes you find out after the fact. The toll bill got paid. The gift card code got sent. A quick, scripted response in the first few hours can limit the damage significantly. Here's a prompt that generates a tailored action list for a senior who has already sent money:

You are an incident response guide for financial fraud. A senior adult has just
realized they sent money in response to a scam text or email.

Provide a numbered action list they should follow in the next 60 minutes.
Be specific about who to call, what information to have ready, and what not to do.
Write in plain language, no jargon.

A well-prompted model will give you something like this:

1. Call your bank or card issuer right now. Ask them to freeze the account and dispute the transaction. Have the exact amount, date, and merchant name ready.

2. If you sent a wire transfer, ask the bank to issue a recall. This is time-sensitive; the sooner you act, the better your chances of a recall succeeding.

3. File a report at reportfraud.ftc.gov (United States) or your country's equivalent consumer protection agency. Keep the report number.

4. Screenshot everything: the original message, any links, the payment confirmation, and any follow-up messages.

5. Change any passwords you shared or that are tied to the accounts involved.

6. Do not reply to the scammer again, even to tell them off. Any response confirms your number or email is active.

Speed matters here more than anything else. Wire transfers are notoriously difficult to reverse once they clear, and other payment methods carry their own recovery challenges depending on how they were processed. Bank card disputes give you the best chance of recovery the sooner they're reported. The prompt above gets a non-technical person to the right steps without them having to Google their way through a panic.

Prompt chaining: Verify sender, urgency, and links in one workflow

Running three separate prompts works. But you can chain them so the AI moves through each step automatically, feeding the output of one stage into the next. This is what turns a one-off check into a reusable personal "Scam Filter."

Here's the full chain, ready to copy:

### STEP 1: Extract red-flag signals

You are a scam-detection assistant. Analyze the message below and return JSON:
{
  "urgency": true/false,
  "unknown_sender": true/false,
  "payment_request": true/false,
  "bad_grammar": true/false,
  "suspicious_link": true/false,
  "extracted_urls": ["list any URLs found in the message"]
}

Message: <<>>

---

### STEP 2: Check each URL from the "extracted_urls" field above

For each URL in the list, return:
{
  "url": "...",
  "matches_official_domain": true/false,
  "notes": "...",
  "link_verdict": "SAFE | SUSPICIOUS"
}

---

### STEP 3: Final verdict

You are a decision engine. Using the JSON outputs from Step 1 and Step 2,
produce a final assessment:
{
  "final_verdict": "SAFE | SCAM | NEEDS_REVIEW",
  "confidence": "HIGH | MEDIUM | LOW",
  "reason": "One sentence explaining the primary reason for the verdict",
  "recommended_action": "What the reader should do next"
}

You can run this as three consecutive messages in a single chat window. The model holds context between steps, so you don't need to re-paste anything after Step 1. The final output gives you a verdict, a confidence level, a reason, and a next action, which is everything you need to tell your dad what to do.

If you want this to run even faster, save the full chain as a reusable template. Ultra Prompt's Security and Privacy prompt category has structured templates built for exactly this kind of workflow, so you're not rebuilding the chain from scratch every time.

Real-world examples: good vs. bad prompts tested on actual scam messages

Vague questions produce vague answers. The table below shows eight real scam message types, what a generic prompt returns, and what the structured chain returns instead.

# Original message (scam) Bad prompt → result Structured chain → result
1 "Your bank account is frozen, call 555-1234 now." "Is this phishing?" → maybe Flags urgency, unknown sender, unsolicited phone number → SCAM
2 "You won a $500 gift card! Click http://gift-claim.com" "Is this safe?" → unclear Payment link found; link check shows unregistered domain → SCAM
3 "IRS notice: you owe $2,300. Pay at http://irs-paynow.com" "Is this legit?" → yes (wrong) Domain does not match irs.gov; urgency flag triggered → SCAM
4 "Your Amazon order failed, verify here: https://amz-secure-login.com" "Looks okay." → safe (wrong) Registrant unknown; safe browsing check fails → SCAM
5 "Package delivery issue – reply with your credit card to re-schedule." "Probably spam." → vague Payment request + grammar flag → SCAM
6 "Important: update your Medicare info at http://medicare-update.org" "Seems legit." → no verdict Domain not .gov; urgency cue present → SCAM
7 "Your Apple ID will be disabled. Click https://apple-verify.com now." "Maybe phishing." → inconclusive Unknown sender + suspicious domain; does not match apple.com → SCAM
8 "We need your Social Security Number to process a refund." "Ask for more info?" → no clear answer Personal data request + payment context flagged → SCAM

The pattern is consistent. "Is this a scam?" gives you a shrug. A structured prompt with explicit extraction criteria gives you a verdict you can act on. The AI isn't replacing your judgment, it's doing the signal extraction so your judgment can go to the right place: deciding what to do next, not squinting at whether the link looks suspicious.

This same principle, using structured prompts to turn vague tasks into clear outputs, is worth applying in other areas. The post on how to evaluate new AI models in 15 minutes uses the same structured-criteria approach in a completely different context, and the logic transfers directly.

FAQ

Q: What words or phrases in an email almost always mean it's a scam?

A: "Urgent action required," "your account will be closed," "verify your information now," "pay immediately to avoid," and any unsolicited request for a payment link or personal credentials. Legitimate organizations use these phrases rarely and never combine multiple in a single message.
Q: Can ChatGPT or similar tools actually detect phishing messages?

A: They can produce useful, structured analysis when you give them a structured prompt rather than a vague question. Paste a suspicious message into any of these tools alongside explicit extraction criteria and they'll work through urgency language, mismatched domains, and payment requests in the text you provide. The quality of the output depends almost entirely on how specific the prompt is. Vague prompts get vague answers. And whatever the model returns, you make the final call.
Q: How do I check a suspicious link without clicking it?

A: On desktop, hover over the link to preview the actual URL. On mobile, hold the link to see the destination. Then copy the URL and paste it into VirusTotal (a free URL scanner) or run the link-check sub-prompt above. Never click to "just see where it goes."
Q: What should I do if I already replied to a scam text?

A: Stop responding immediately. Contact your bank if any financial information was shared. Alert your mobile carrier that your number may have been confirmed active to scammers. Change any passwords mentioned in the conversation. File a report at reportfraud.ftc.gov. Do it in that order, today.
Q: Are there free prompt templates that help spot email scams?

A: The scam-detector templates in this article are free to copy right now. Ultra Prompt's Security and Privacy prompt category includes additional structured templates for ongoing use, so you're not rewriting the prompt every time a new suspicious message arrives.
Q: Do I need technical skills to use these prompts?

A: No. Every prompt in this guide is copy-paste ready. Open any LLM chat interface, paste the prompt, replace the placeholder with the suspicious message, and read the output. If you can forward a text, you can run this check.

Run it now

The recipe is free. Each link opens the finished prompt with the blanks already named, so you fill in your job and paste the result into the AI you use.

More like this, for whatever you are working on: open Ultra Prompt.

Ready to level up your prompts?

Ultra Prompt has 1,000+ expert-crafted templates. Stop guessing, start prompting.

Try Ultra Prompt Free
S

Written by Sean

Founder of Ultra Prompt. Building the prompt engineering toolkit I wish existed.