Reviewed and updated August 2026
Staying safe · 6 minute readMessages with nothing left to spot
For twenty years the advice was to watch for bad spelling, clumsy grammar, and a greeting that didn't use your name. That advice is now actively harmful, because it teaches people that a well-written message is a safe one.
Why the old tells existed at all
The mistakes were never a mistake in the way people assumed. Some were the result of scams written by people working in a second language. Some were deliberate — a clumsy message filters out anyone alert enough to notice, leaving only the most promising targets to be worked on by hand.
Either way, the errors were a side effect of humans doing the writing. Software writes them now, in fluent English, in whatever tone the situation calls for. There is no longer a spelling mistake to find, so a system built on finding spelling mistakes has nothing to do.
The replacement rule, in one sentence
Stop judging the message and start judging what it's asking you to do. Fluency is now free; what a message wants from you is much harder to disguise.
What to look at instead
Almost every one of these messages, however well written, has to do one of a very small number of things — and each one is a reason to slow down.
- It wants you to sign in. The link goes to a page that looks exactly right and collects your password. Nothing about the design tells you anything, because copying a design is trivial.
- It wants money to move, or bank details changed, or an invoice paid to a new account.
- It wants a code you were just sent. No real organisation ever needs the code from your text messages. Not one, not ever, no matter how convincing the reason.
- It wants you to install something or grant access so someone can help you.
- It creates a deadline. Your account closes today, the payment fails tonight, the offer ends in an hour.
A message doing none of these is usually just a message. A message doing one of them deserves the same treatment regardless of how polished it reads.
The habit that replaces spotting mistakes
- Never travel through the message. Don't click its link, don't call its number, don't reply to its address. Open a new window and go to the site the way you normally would, or ring the number on your card or your last paper statement. This single habit disarms nearly all of it, because the whole scheme depends on you using the door they built.
- Check by a different route than the one that contacted you. An email about your bank gets confirmed by phone. A text about a delivery gets checked in the courier's own app. Never confirm a channel using itself.
- Treat a matching detail as meaningless. These messages now routinely include your real name, your address, the last four digits of a card, or a genuine recent order — bought or scraped from a leak. Accurate detail is evidence of research, not legitimacy.
- Slow down when it's urgent. Urgency is the one ingredient every version needs, precisely because a person in a hurry skips step one.
Worth doing once, then forgetting about
Turn on two-step verification for your email account specifically, before your bank or anything else. Email is the master key: whoever controls it can reset the password on everything else you own. It takes about five minutes and it is the single highest-value security thing most people can do.
And remember the flip side — because you'll now be receiving codes, nobody legitimate will ever phone to ask you to read one out.
When you're not sure
You don't have to become good at judging messages. Delete anything you're unsure about and go directly to the organisation yourself. If it was real, it will still be there when you arrive — a genuine problem with your account does not evaporate because you refused to use a link.