Digital Trust Examples
Real-world scam scenarios across SMS, email, QR codes, and payment links — each broken down with the red flags to spot and the verification steps to take before you act.
How to use these examples
Each scenario below presents a real type of digital scam, the message a victim might receive, the specific red flags that reveal it, and a step-by-step verification process. These are educational examples based on common attack patterns — not a substitute for professional cybersecurity advice. The goal is to build the habit of verifying before you act, not after.
The Package Delivery Smishing Text
You receive a text message claiming to be from a delivery service. It says your package is being held and you need to confirm your address and pay a small redelivery fee.
“ROYAL MAIL: Your parcel is being held at our depot. Confirm your address and pay £1.99 redelivery fee within 24h or it will be returned: http://royalmail-track.co/confirm?id=8842”
Red flags to spot
royalmail-track.co is not the official Royal Mail domain (royalmail.com). Scammers register look-alike domains that differ by a single character or hyphen.
“Within 24h or it will be returned” manufactures pressure so you act before checking. Real delivery services rarely demand immediate payment via text link.
Legitimate carriers process fees through their official website or app — not through a link sent in an SMS.
Real delivery notifications include your tracking number and usually your name. This message has neither.
How to verify
Open the delivery service's official app or website and enter your tracking number — not the one from the text.
Type the company's known URL directly into your browser. Compare it character-by-character with the link in the message.
Call the delivery service's official customer service number from their website — never a number provided in the suspicious text.
Forward suspicious texts to your carrier's spam reporting number (e.g. 7726 in the UK / US) and delete the message.
A legitimate delivery notification includes your name and tracking number, links to the carrier's official domain, and never demands payment through an SMS link.
Sample Trust Index score
An illustrative breakdown of how this scenario would score — nothing is submitted or stored.
Unregistered short code, no carrier sender ID, no account reference.
royalmail-track.co is a look-alike of the official royalmail.com.
Small fee requested through an SMS link rather than the carrier's app.
24-hour deadline, generic greeting, no tracking number.
What would change this score?
Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.
Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.
One-page verification checklist
Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.
- Unfamiliar shortened domain
- Urgency deadline
- Payment through a link
- Generic greeting, no tracking number
- Check your actual order
- Verify the domain
- Contact the sender on a known channel
- Report the message
See how SMS / Text ranks among channels people worry about most — from live, anonymous survey data.
The Vendor Invoice Phishing Email
An email arrives that looks like it's from a supplier your company regularly works with. It says their bank details have changed and asks you to update your records before the next payment.
From: accounts@vendorname-payments.net Subject: URGENT: Updated Bank Details – Action Required “Dear Customer, We have recently updated our banking information. Please update your records and direct all future payments to the new account below. Kindly process the attached invoice at your earliest convenience to avoid any disruption in service.”
Red flags to spot
The sender domain is vendorname-payments.net, not vendorname.com. The real domain would be the company's primary domain — a payment subdomain is unusual.
Bank account changes are one of the highest-risk Business Email Compromise (BEC) tactics. Legitimate vendors confirm these changes through multiple channels.
“Dear Customer” instead of your name or company name. A real vendor knows who you are.
“At your earliest convenience to avoid disruption” implies consequences for delay — a common manipulation tactic.
How to verify
Call your existing contact at the vendor using a phone number you already have on file — never one from the email.
Check the full headers for the originating IP and authentication results (SPF, DKIM, DMARC). Mismatches reveal spoofing.
Check whether the bank account, formatting, and sender address match previous legitimate invoices from the same vendor.
For any bank detail change, require verbal confirmation and a second person's sign-off before processing payment.
A legitimate vendor communicates bank detail changes through a verified phone call or secure portal and confirms with your existing contact — never solely by email.
Sample Trust Index score
An illustrative breakdown of how this scenario would score — nothing is submitted or stored.
Look-alike domain (vendorname-payments.net) instead of the vendor's real domain.
Attachment-driven request with no link to a known vendor portal.
Unprompted bank-detail change — the classic invoice-redirect pattern.
'URGENT' subject and service-disruption threat to rush approval.
What would change this score?
Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.
Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.
One-page verification checklist
Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.
- Look-alike domain
- Bank detail change via email
- Vague greeting
- Pressure language
- Verify through a known contact
- Inspect the email headers
- Compare with past invoices
- Implement a dual-approval process
See how Email ranks among channels people worry about most — from live, anonymous survey data.
The Tampered Parking Meter QR Code
You park on a city street and see a QR code sticker on the parking meter. Scanning it takes you to a payment page that looks like the official city parking app — but it's designed to steal your card details.
Scanning the code opens: https://park-pay-city.com/pay?zone=4471 The page shows a city logo, asks for your card number, CVV, and billing address, and says your parking session will start after payment.
Red flags to spot
Scammers place adhesive QR stickers over legitimate codes on parking meters, restaurant tables, and public signs. Check for layered or misaligned stickers.
park-pay-city.com is not the official city or parking-operator domain. Real municipal parking URLs typically use a .gov or the operator's known domain.
Legitimate parking apps use secure, tokenised payment through their own verified app or a well-known payment processor — not a raw card-entry form on an arbitrary website.
The QR code sends you to a web page rather than the official app store listing. Real parking QR codes typically link to the operator's official app.
How to verify
Look for stickers placed over the original printed code. If the QR sticker looks newer or differently placed than surrounding signage, don't scan it.
Download the parking app from the Apple App Store or Google Play Store by searching for the city or operator name — don't scan a code on the meter.
Most modern phones show the URL a QR code resolves to before opening it. If the domain doesn't match the official operator, close it.
Legitimate payment pages use HTTPS with a valid certificate and a recognised payment processor. If the page asks for raw card details with no payment-provider branding, leave immediately.
A legitimate parking payment uses the city's official app or a verified payment processor with HTTPS and tokenised card handling — not a raw card-entry form on an unfamiliar domain.
Sample Trust Index score
An illustrative breakdown of how this scenario would score — nothing is submitted or stored.
A physical sticker carries no verifiable issuer — anyone can place it.
Destination domain is not the city's official parking domain.
Raw card fields with no recognised payment-processor branding.
Plausible context, but zero independent way to confirm the payee.
What would change this score?
Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.
Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.
One-page verification checklist
Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.
- Sticker over the original code
- Unfamiliar URL
- Direct card entry on an unknown page
- No app store verification
- Inspect the QR code physically
- Use the official app directly
- Preview the URL before opening
- Check for HTTPS and payment security
See how QR Code ranks among channels people worry about most — from live, anonymous survey data.
The Online Marketplace Fake Payment Link
You're selling an item on an online marketplace. A buyer says they want to pay immediately and sends you a link, claiming it's a 'secure payment protection' service. The link is a fake page designed to capture your bank login credentials.
“Hi, I'd like to buy this right away. I can pay through Buyer Protection. Just confirm your details here so the funds get released to your account: https://secure-buyerprotect.io/verify?seller=88412”
Red flags to spot
secure-buyerprotect.io is not a recognised payment processor. Legitimate marketplaces use their own built-in escrow or well-known platforms like PayPal or Stripe.
In legitimate marketplace transactions, the buyer sends payment through the platform — the seller never needs to enter bank credentials on an external link.
“I'd like to buy this right away” combined with a custom link is a classic overpayment scam setup. The fake page harvests your login, and no real payment ever arrives.
The buyer is trying to move the transaction off the marketplace to a private link. Marketplaces warn users to stay on-platform for exactly this reason.
How to verify
Use the marketplace's built-in payment system. If a buyer insists on an external link, refuse and report them.
Real payment processors use domains like paypal.com, stripe.com, or the marketplace's own checkout page. Any other domain is a red flag.
No legitimate payment process requires a seller to log into their bank account through a buyer-provided link. This is always a credential-harvesting scam.
Check their account age, reviews, and verification badges on the marketplace. Newly created accounts with no history are high-risk.
A legitimate marketplace payment flows through the platform's own checkout or a recognised processor like PayPal or Stripe. A seller is never asked to enter bank credentials on a buyer-provided link.
Sample Trust Index score
An illustrative breakdown of how this scenario would score — nothing is submitted or stored.
Buyer account created days ago, no history or verification.
Payment link on a domain unrelated to the marketplace or any known processor.
Asks the seller for bank credentials — never part of a real payout.
Off-platform move plus 'courier already booked' urgency.
What would change this score?
Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.
Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.
One-page verification checklist
Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.
- Unfamiliar payment platform
- Seller is asked to enter bank details
- Rush to pay immediately
- Off-platform communication
- Keep the transaction on-platform
- Check the payment URL against known providers
- Never enter bank login credentials on a link
- Verify the buyer's profile
See how Payment Link ranks among channels people worry about most — from live, anonymous survey data.
Verification habits that work across every channel
While each channel has its own verification steps, four habits apply universally — no matter whether you're checking a text, an email, a QR code, or a payment link:
Slow down when there's urgency
Scammers manufacture time pressure to bypass verification. Any message demanding immediate action is itself a red flag — take a moment to check.
Verify the destination, not the link
Hover, preview, or type the known URL directly. Short links and look-alike domains are the most common entry point for fraud.
Confirm identity through a separate channel
If a message claims to be from your bank, vendor, or a buyer, verify by calling their official number or logging in through their known website — not through the message.
Never share credentials on a page you didn't navigate to yourself
No legitimate process requires you to enter bank logins, card details, or passwords on a page you reached through a link someone else sent.
Frequently asked questions
How can I tell if a text message is a scam?+
Look for urgency, requests for personal or payment information, shortened or unfamiliar links, and sender numbers that don't match the organisation's official channels. Never click a link in an unexpected text from your bank, delivery service, or government agency — instead, navigate to their official website or app directly.
What should I check before clicking a link in an email?+
Hover over the link to preview the destination URL, check that the sender's email domain matches the organisation's real domain, look for personalised information that a scammer wouldn't know, and be suspicious of urgent or threatening language. When in doubt, go directly to the organisation's website instead of clicking.
Are QR codes safe to scan?+
QR codes can route you to any URL, including malicious ones. Before scanning a QR code in a public space or from an unfamiliar source, check for tampering (stickers placed over the original code), avoid scanning from printed flyers or unsolicited emails, and preview the URL if your device offers that option. If the destination asks for login credentials or payment, close it immediately.
How do I verify a payment request is legitimate?+
Confirm the request through a separate, known channel (call the person or organisation on their official number), check that the payment platform and URL are the real ones, be wary of pressure to pay immediately, and never enter card details on a page you reached through an unfamiliar link. Legitimate platforms use secure, verifiable payment infrastructure — not ad-hoc links.
What is the single most important thing I can do?+
Slow down. Scammers rely on urgency to bypass your normal caution. Whenever a message, call, or request demands immediate action, treat that urgency itself as a red flag and take a moment to verify through a separate, trusted channel before acting.
Help us research digital trust.
Have you encountered a scam like these? Share your experience — it's anonymous and takes two minutes.