How to check if a suspicious message is a scam by pasting it into an AI
A 5-minute way to get a fast second opinion on a sketchy email or text before you click anything
This guide was written by AI. It passed automated fact and quality checks; no human editor reviewed it.
Scam messages have gotten good. They use real company logos, your real name, sometimes even your real address. Before you click anything, copy the message into an AI assistant and ask for a second pair of eyes. This guide walks you through that in six steps — even if you've never used an AI assistant before. One honest warning up front: the AI is a useful first check, not a verdict, and it cannot actually click the link or call the company for you. You still have to do that part.
💡 Tip: tap a step’s number when you finish it — a green tick appears and your browser remembers how far you got.
- An AI assistant you can sign into — ChatGPT, Gemini, Claude, Microsoft Copilot, and Le Chat all work, and their free plans are fine for this.
- The suspicious message itself, ready to copy (an email, a text, a chat screenshot, or a DM).
- About 5 minutes in total.
- Important: never paste real passwords, full card numbers, or government ID numbers, even if the message contains them — Step 2 shows you how to handle that.
Open a fresh chat in any AI assistant
Open the website or app of any AI assistant — ChatGPT, Gemini, Claude, Microsoft Copilot, Le Chat, or whichever you already use. Start a brand-new conversation rather than dropping the message into an older thread. On a phone, the app icon usually looks like a small chat bubble or a starry logo. On a computer, just go to the assistant's homepage and click into the empty chat box. A clean thread means the AI won't get distracted by older context and will focus entirely on your message. If you don't already have an account, the free sign-up usually takes under a minute and only needs an email address.
You'll know it worked when you see an empty chat box with a placeholder like "Message…" or "Ask anything" and a send button (often an arrow or paper-plane icon).

Redact personal details before you paste
Before you copy the message, take 30 seconds to hide any sensitive bits it contains. Cover real passwords, full credit card numbers, your Social Security or national ID number, your home address, and any one-time login codes. A quick search-and-replace in any notes app works fine. Think of it like covering your hand on a debit-card PIN pad at the store — the AI doesn't need those details to spot a scam, and fewer real numbers in the chat mean less risk if your account is ever hacked. If the message has no personal details at all, you can skip ahead to Step 3.
You'll know it worked when the message still reads naturally but no real numbers, codes, or addresses remain.

Paste the message and ask the AI to flag red flags
Tap or click inside the empty chat box and paste the redacted message. Then add a short prompt asking the assistant to look at it as if it were a security expert. Press the send button (usually an arrow ↗ or paper-plane icon, but apps vary). After a few seconds the AI will start typing a reply — usually a short list of warning signs plus a one-line verdict like "this looks like a phishing attempt" (a fake message designed to steal your login or money) or "this appears legitimate, but verify the sender". If nothing appears after a few seconds, look for a small "stop" or square icon — the response sometimes needs a moment to begin. Apps change often, so if your screen looks a little different, just look for any button that submits your message.
You'll know it worked when you see a written response that names specific warning signs, such as urgency, suspicious links, an odd sender, or requests for personal info.

Read the AI's answer with a critical eye
Treat the AI's reply like a friend's opinion, not a doctor's diagnosis. Read each red flag it names and ask yourself: does this actually match the message I received? Many scams lean on urgency ("act in the next 24 hours"), impersonate a brand you trust, include a link that almost looks right, ask you to click or log in, or demand payment in gift cards or cryptocurrency. If the AI flags something that isn't actually in your message, ignore that point — assistants sometimes guess wrong, and you are still the expert on your own inbox. Conversely, if something feels off to you but the AI didn't mention it, trust your gut and move to the next step. Be especially wary if the AI says "this looks fine" but the message asks you to click a link, send money, or share a code — that's the moment to get a second human opinion.
You'll know it worked when you can repeat back, in your own words, two or three specific reasons the AI gave for its verdict.

Verify any links or sender names yourself
Don't click anything yet. If the message contains a link, hover over it on a computer or long-press it on a phone — you'll see the real destination. Real companies use their own short domain (the brand's actual homepage), while scam links often hide behind words like "secure-login" or "verify-account" on a totally different address. The simple rule: if the link doesn't end on the brand's real site, it's almost certainly fake. If the message claims to be from a person you know, contact that person through a channel you already trust — a phone call or a separate chat — and never reply to the suspicious message itself. If it claims to be from a company like your bank, look up the official number on their real website (type the address yourself, don't use any number inside the message) and ask them directly.
You'll know it worked when you have either confirmed the message is genuine through a trusted channel, or you've concluded it's a scam.

Decide what to do, and don't act in a rush
Now choose one of three actions. If it's a scam: delete it, block the sender, and — if it pretended to be a company — report it to that company through their real website. If it's genuine but unexpected: still don't click links inside it; go to the company's real site yourself and log in there. If you're not sure: leave it alone for an hour, then re-read it cold; urgency is the scammer's favorite tool, and a slow second look usually reveals more. Tell a friend or family member if you're worried — a second human pair of eyes still catches things AI misses, especially with voice or video scams. The whole point of using an AI here is to slow down, not to rush.
You'll know it worked when you take one concrete action in the next few minutes — delete, report, or verify through a trusted channel — instead of leaving the message sitting unread in your inbox.

- Pasting real passwords or full card numbers. The AI doesn't need them, and storing them in a chat creates risk if your account is ever hacked. Fix: redact first (Step 2), or describe the message in your own words instead of pasting it.
- Trusting the AI's verdict without checking. AI assistants sometimes miss obvious scams or flag clean messages by mistake. Fix: always cross-check the specific red flags it names against the actual message (Step 4) and verify with the real company (Step 5).
- Clicking the suspicious link "just to see what happens". That's exactly what the scammer wants. Fix: hover or long-press to read the real URL, and never log in through a link inside an unexpected message — go to the company's website yourself.
Find one message in your inbox you've been unsure about, redact any personal details, paste it into your AI assistant, and ask it to flag the red flags. Five minutes, one fresh chat, one safer decision.
❓ Quick questions
How long does this take?
About 6 minutes — the guide has 6 steps, and you can tick each one off as you go.
Do I need to prepare anything?
- An AI assistant you can sign into — ChatGPT, Gemini, Claude, Microsoft Copilot, and Le Chat all work, and their free plans are fine for this.
- The suspicious message itself, ready to copy (an email, a text, a chat screenshot, or a DM).
- About 5 minutes in total.
- Important: never paste real passwords, full card numbers, or government ID numbers, even if the message contains them — Step 2 shows you how to handle that.
What mistakes should I avoid?
- Pasting real passwords or full card numbers. The AI doesn't need them, and storing them in a chat creates risk if your account is ever hacked. Fix: redact first (Step 2), or describe the message in your own words instead of pasting it.
- Trusting the AI's verdict without checking. AI assistants sometimes miss obvious scams or flag clean messages by mistake. Fix: always cross-check the specific red flags it names against the actual message (Step 4) and verify with the real company (Step 5).
- Clicking the suspicious link "just to see what happens". That's exactly what the scammer wants. Fix: hover or long-press to read the real URL, and never log in through a link inside an unexpected message — go to the company's website yourself.
Keep reading
✦ Generated by AI in AI World HQ's automated newsroom, written in plain language. Checked by automated fact and quality gates — no human editor reviewed this guide. Spot a mistake? Use the buttons above.
☕ Free to read, no ads, no paywall — readers keep it going. Support us (one-off or monthly)
← Back to all stories