How to Spot a Phishing Email or Scam Text Before You Click
Paste any suspicious message into an AI assistant with a fraud-detector prompt and it will flag the red flags your eyes missed
In short: Copy any suspicious email or scam text into an AI assistant with a short "fraud detector" prompt, and it lists the red flags — fake urgency, off-brand sender addresses, sketchy links — so you can decide whether to delete, block, or report the message before you click anything.
That pang of "wait, something feels off" you get when a strange email or text arrives — the AI can confirm it (or calm you down) in about 30 seconds. This guide shows you exactly what to type, and how to read the answer so you don't miss the warning signs. It works with ChatGPT, Gemini, Claude, Copilot, Le Chat, DeepSeek, or any other assistant you already use. One honest note up front: an AI can spot a lot, but it can't actually click the link for you or verify whether a sender is real — the final "yes" or "no" is still your call.
💡 Tip: tap a step’s number when you finish it — a green tick appears and your browser remembers how far you got.
- An account on any AI assistant you already use (free versions work fine — ChatGPT, Gemini, Claude, Microsoft Copilot, Le Chat, or DeepSeek all do this).
- The suspicious message itself, opened on your screen but with no links tapped or replies sent.
- Roughly 2 minutes.
Read the message calmly before doing anything
Open the suspicious email or text, and do exactly one thing: read it top to bottom with your finger off the mouse. Glance for three things — a sender or number you don't recognize, a tone that pushes you to act NOW, and any link you weren't expecting. You'll see the message exactly as you normally would; nothing changes yet.
If it looks different: in some messaging apps long-pressing a link shows a small URL preview — that's actually useful, but still don't open it. Reading is the goal here. You'll know it worked when you can describe the message in one short sentence without having clicked anything.

Open any AI assistant you already use
On your phone or laptop, open the AI assistant app or website where you already have an account. No special "fraud tool" is needed — every general-purpose assistant can do this job. You'll see an empty chat box, usually labeled "Message", "Ask anything", or similar. If it looks different: every assistant has its own empty state, but the chat box is almost always in the middle of the screen on desktop or at the bottom on mobile. If you're stuck, start a "New chat". You'll know it worked when you see a blinking cursor and a send button, ready for you to type.

Paste in a "fraud detector" prompt first
Before pasting the suspicious message, give the AI a one-line role instruction. Type it into the chat box and hit send. The AI will respond with a short confirmation — usually something like "Sure, paste it in" — that primes it to focus on fraud patterns instead of generic advice. This single line is what turns a normal chat into a fraud check.
If it looks different: some assistants reply with a longer setup paragraph — that's fine; what matters is that it now knows to focus on scams. You'll know it worked when the AI answers something like "Got it — paste the message" or asks a clarifying question.

Paste the full suspicious message, then send
Highlight the entire message — sender name, subject line, body, and the link text — but leave out your own name, address, or any account numbers if they appear, since the AI doesn't need them to spot trouble. Paste it into the chat box and hit send. The AI now has the raw text and starts analyzing it. If it looks different: if the message is unusually long (a fake invoice, say), you can paste a trimmed version — but keep the opening sentence and any links exactly as written, because that's where the red flags usually live.
You'll know it worked when the AI starts replying with a bulleted list of specific things it spotted — usually 4 to 8 items.

Read the red flags and trust the obvious ones
The AI's reply is usually a checklist: things like "the sender domain doesn't match Amazon," "the URL uses a zero instead of an 'o'," "the message creates urgency with a 24-hour deadline," or "the greeting is generic (no real name)." Read each one and ask yourself, "Does this match what I'm seeing on my screen?" You'll start to see a pattern you can recognize next time without any help.
If it looks different: the AI might use softer words ("likely a phishing attempt", "this looks suspicious"). That's the same meaning. If it ever says "I'm not certain", take that seriously and lean toward treating the message as a scam. You'll know it worked when you can name at least three specific reasons the message is suspicious and explain them out loud.

Decide, then report and delete
Once the AI gives its verdict, decide based on the strength of the red flags. If even one major red flag is present — a sketchy sender domain, pressure to act NOW, or a request for passwords or payment — don't click and don't reply. Use the email or messaging app's built-in "Report phishing" or "Report junk" option if you can find it, then delete the message. The dangerous message is gone from your screen and flagged to the platform.
If it looks different: Gmail, Outlook, Apple Mail, and most phone carriers all have a Report button, usually under a "⋯" three-dot menu or near "Mark as" / "Move to". If you can't find the report option, deleting is good enough — what matters is that you don't reply. You'll know it worked when the message is no longer in your inbox, you've flagged it to your email or carrier, and you haven't tapped the link.

- Replying to the scammer just to ask "is this real?" — replying confirms your address is live, and more scam messages follow. Delete and report instead.
- Trusting the AI without reading the explanation — AI can miss things. If the message "feels" off but the AI says it's fine, trust your gut and don't click. The AI is a second opinion, not a final one.
- Pasting personal details along with the message — your name, address, and account numbers aren't needed to spot red flags; trim them out before pasting, because anything you send into a chat is processed by that service.
The next time an email or text feels off, copy it into your AI assistant with the prompt from Step 3, paste the full message from Step 4, and read the red flags from Step 5 before you tap anything. The whole check takes about half a minute.
❓ Quick questions
How long does this take?
About 6 minutes — the guide has 6 steps, and you can tick each one off as you go.
Do I need to prepare anything?
- An account on any AI assistant you already use (free versions work fine — ChatGPT, Gemini, Claude, Microsoft Copilot, Le Chat, or DeepSeek all do this).
- The suspicious message itself, opened on your screen but with no links tapped or replies sent.
- Roughly 2 minutes.
What mistakes should I avoid?
- Replying to the scammer just to ask "is this real?" — replying confirms your address is live, and more scam messages follow. Delete and report instead.
- Trusting the AI without reading the explanation — AI can miss things. If the message "feels" off but the AI says it's fine, trust your gut and don't click. The AI is a second opinion, not a final one.
- Pasting personal details along with the message — your name, address, and account numbers aren't needed to spot red flags; trim them out before pasting, because anything you send into a chat is processed by that service.
Keep reading
✦ Original step-by-step guide by AI World HQ's AI editorial team. Written in plain language, reviewed for accuracy.
← Back to all stories