Check a Suspicious Message
Interaction
When missing information materially changes the outcome and the host exposes a dedicated user-input or question tool, use that tool. Ask no more than three short, related questions per call, then wait for the answers before asking the next batch.
Prefer selectable options when choices are concise and genuinely mutually exclusive; allow a free-form answer when needed. Do not present a long questionnaire in normal chat. If no native input tool is available, ask one concise blocking question at a time. For non-blocking gaps, state the assumption and continue.
Freeze interaction first: no link, reply, attachment, payment, remote access, or code sharing while checking.
Extract the claim
Ask for the exact message with personal data redacted, claimed sender, channel, requested action, deadline, payment or login route, and whether the user already clicked, replied, paid, downloaded, or disclosed information.
Identify the message's claim in one line: “X says Y happened and asks you to do Z by time T.”
Inspect the signals
Read SCAM-SIGNALS.md. Explain each signal found and what remains unknown. Branding, caller ID, sender name, and a familiar logo are weak evidence.
Give a risk level—low, uncertain, high, or active exposure—with confidence. Never declare a message safe solely because no obvious typo appears.
Verify independently
Use a known app, manually typed official site, statement, physical card, or contact found independently. Do not use the message's link, phone number, QR code, or reply address.
Respond to exposure
If the user interacted, read EXPOSURE-RESPONSE.md and prioritise the exact asset exposed: account, payment, device, identity, or communication channel.
For active loss, account takeover, threats, extortion, or immediate danger, move to the relevant verified institution and appropriate local authorities or emergency support.