How to Check if a Message Is a Scam With AI
By Chatday Editorial Team ·
The text arrives at 9pm. Your bank, apparently, has spotted a payment you did not make. There is a link. There is a deadline. Your stomach drops.
Ten years ago you could spot these by the typos. That clue is gone. The people sending them have the same AI you do, and they use it to write in clean, friendly, perfectly punctuated English, in whatever language you speak, at a scale no human team could match. The good news is that the tool works in both directions. Before you tap anything, you can paste that message into an AI and ask it what it sees.
This guide covers the practical version: what to paste, the exact questions that get useful answers, what you should never put in a chat box, why a second model is worth the extra thirty seconds, and the places where this approach genuinely fails.
Why scam messages suddenly got so convincing
The numbers are worth a moment because they explain the shift. In its 2025 annual report, the FBI’s complaint centre gave artificial intelligence its own section for the first time, logging 22,364 complaints that mentioned AI and roughly $893 million in losses. Voice cloning shows up in the saddest category: distress scams, where someone calls sounding exactly like your child or your parent, cost victims over $5 million that year.
The FBI also makes a point that matters more than the totals. In investment fraud, complaints with a clear AI link came to about $632 million, while investment scams overall ran past $8 billion. Most people simply never find out that AI was part of it.
Separately, the US Federal Trade Commission reported in June 2026 that people lost $3.5 billion to imposter scams in 2025, nearly one in three fraud reports, with losses close to three times what they were in 2020. An imposter scam covers the whole category: someone pretending to be your bank, a delivery company, a government office, your boss, or your child.
So the change is simple to state. Writing a flawless, personalised, urgent message in any language got cheap. That means the old advice, look for bad grammar, now puts people at risk.
What to paste into the AI, and what to never paste
The check itself takes about a minute. Open a chat, paste the message, and ask. You can paste the text, or upload a screenshot if the message lives in an app you cannot copy from, which is usually the case with bank alerts and delivery notices.
Before you paste, take ten seconds to strip out anything that identifies you.
Do keep the parts that carry the evidence: the sender’s number or email address, the exact wording, the link as text (do not tap it), and what the message is asking you to do. Those are the things worth judging.
The three questions that do the actual work
Asking “is this a scam?” gets you a hedge. These three get you something you can act on. Each one opens in a chat with the message ready to go.
That second half is the useful bit. Knowing what a real bank alert looks like, no links, no deadline, and it tells you to log in the normal way, is a skill you keep. A yes or no answer teaches you nothing.
Scam links are built to be misread. A long address filled with the words secure and verify, with the real destination placed at the end, works well on a phone screen where most of it is cut off. Asking specifically for the domain solves that.
That last question is usually the most useful one. Scams tend to break down over a specific, ordinary detail you can check: a company registration number, a physical address, a named person you can look up, or a request to move the conversation to a normal video call.
Ask a second model before you act
Here is the honest limitation of a single AI answer. Models are agreeable by design. If you paste a message and add “this looks fake to me, right?”, you have already told it what you want to hear, and it will often oblige.
Two things fix that. Ask neutrally, and ask twice, using a different model for the second read. Different models were trained differently and phrase their doubts differently. When two of them independently flag the same sentence, that is a real signal. When one says scam and the other says routine, you have learned that the message is genuinely ambiguous, which is itself useful, and you go verify it directly.
This is the part that is awkward if each AI lives behind its own subscription and its own login. Having them in one place, where you paste the message once and switch models on the same conversation, turns the second opinion from a chore into a tap. That is the whole reason to keep several models within reach rather than committing to one.
Which check fits which kind of message
Not everything that arrives needs the same treatment. A rough guide:
| What arrived | The fastest check | The thing that gives it away |
|---|---|---|
| Bank or payment alert | Paste the text, ask what a real alert looks like | Any link at all, plus a deadline measured in hours |
| Delivery or customs fee | Check the domain as plain text | A small fee for a parcel you cannot name |
| A job offer or recruiter | Ask what you can verify right now | Interview by chat only, and payment before you start |
| Investment or crypto tip | Ask what would have to be true | Guaranteed returns, and pressure to act today |
| A relative in trouble, by call | Hang up and call them back yourself | Urgency, secrecy, and a request to not tell anyone |
| A photo or screenshot | Upload it and ask what is odd about it | Mismatched logos, odd sender, a number that is not the official one |
For that last row, a screenshot is often all you have, and describing it in words loses the detail. Uploading the image and asking what looks wrong with it works well, and our guide on how to make AI explain any photo or screenshot covers that technique properly. The image analyzer is built for the same job if you would rather not start from a blank chat.
Notice that the voice call row does not involve AI at all. That is deliberate. If the person on the phone sounds exactly like your daughter, no chat window is going to help you in that moment. Hang up, call the number you already have saved, and agree a family code word before you ever need one.
Where this falls short
This method has real limits, and it is worth being clear about them.
AI can be confidently wrong. It will occasionally invent a detail about a company’s policy or state that a domain is official when it is not, for the same reason it invents citations, which we unpacked in why AI confidently makes things up. Treat the answer as a well-informed friend’s opinion, not a ruling.
It cannot see what it was not given. A model reading pasted text has no way to check whether the sending number really belongs to your bank, whether that domain was registered last Tuesday, or whether the invoice matches your actual account. It reasons about the wording and the structure. That catches most of what is sent to ordinary people, and it misses a targeted attack built from your real details.
It can also be too suspicious. Genuine messages from real companies are often written badly, with pointless urgency and tracking links that look sketchy. If an AI flags something you were half expecting, that is a prompt to verify, not proof of fraud.
And the verification step never moves. Whatever the answer, if the message concerns money or an account, contact the organisation using a number or app you already had, never one from the message. AI shortens the list of things worth worrying about. It does not replace the phone call.
If you already tapped, replied, or paid
Speed matters more than embarrassment here, and this happens to careful people constantly.
Call your bank straight away using the number on your card and tell them exactly what happened. Change the password for any account you entered details into, and any other account sharing that password. Turn on two-factor authentication where it was not already on. Report it to your national fraud body, because those reports are what produced the numbers at the top of this article. If you sent money by transfer or crypto, report it within hours rather than days, since the window for recovering anything is short.
Then, when things are calm, paste the original message into an AI and ask it to break down how it worked on you. Understanding the specific pressure it used, urgency, authority, or fear for someone you love, is what makes the next one easier to ignore.
The habit worth building
You do not need to become suspicious of everything. You need one small pause between the message arriving and your thumb moving, and something useful to do with that pause.
Paste it. Ask what it wants and what a real version would look like. Ask a second model if the answer matters. Then verify through a channel you already trust. The whole thing takes less time than reading this paragraph took, and it works precisely because the people sending these messages are counting on you not stopping at all.