Back to TRUST.AI
Research Guide
TRUST.AI Research

Digital Trust Examples

Real-world scam scenarios across SMS, email, QR codes, and payment links — each broken down with the red flags to spot and the verification steps to take before you act.

How to use these examples

Each scenario below presents a real type of digital scam, the message a victim might receive, the specific red flags that reveal it, and a step-by-step verification process. These are educational examples based on common attack patterns — not a substitute for professional cybersecurity advice. The goal is to build the habit of verifying before you act, not after.

SMS / Text

The Package Delivery Smishing Text

You receive a text message claiming to be from a delivery service. It says your package is being held and you need to confirm your address and pay a small redelivery fee.

The Message
“ROYAL MAIL: Your parcel is being held at our depot. Confirm your address and pay £1.99 redelivery fee within 24h or it will be returned: http://royalmail-track.co/confirm?id=8842”

Red flags to spot

1
Unfamiliar shortened domain

royalmail-track.co is not the official Royal Mail domain (royalmail.com). Scammers register look-alike domains that differ by a single character or hyphen.

2
Urgency deadline

“Within 24h or it will be returned” manufactures pressure so you act before checking. Real delivery services rarely demand immediate payment via text link.

3
Payment through a link

Legitimate carriers process fees through their official website or app — not through a link sent in an SMS.

4
Generic greeting, no tracking number

Real delivery notifications include your tracking number and usually your name. This message has neither.

How to verify

1
Check your actual order

Open the delivery service's official app or website and enter your tracking number — not the one from the text.

2
Verify the domain

Type the company's known URL directly into your browser. Compare it character-by-character with the link in the message.

3
Contact the sender on a known channel

Call the delivery service's official customer service number from their website — never a number provided in the suspicious text.

4
Report the message

Forward suspicious texts to your carrier's spam reporting number (e.g. 7726 in the UK / US) and delete the message.

What a legitimate interaction looks like

A legitimate delivery notification includes your name and tracking number, links to the carrier's official domain, and never demands payment through an SMS link.

Sample Trust Index score

An illustrative breakdown of how this scenario would score — nothing is submitted or stored.

18/100
High risk — do not act
Sender identity1/5

Unregistered short code, no carrier sender ID, no account reference.

Link & destination1/5

royalmail-track.co is a look-alike of the official royalmail.com.

Payment integrity1/5

Small fee requested through an SMS link rather than the carrier's app.

Pressure & context2/5

24-hour deadline, generic greeting, no tracking number.

Trust signals scored: 5 of 20 — a higher score means more independently verifiable signals. Low scores mean you cannot confirm the sender, link, or payee before acting.

What would change this score?

Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.

18/100
High risk — key signals cannot be confirmed

Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.

Presets:

One-page verification checklist

Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.

Red flags to check
  • Unfamiliar shortened domain
  • Urgency deadline
  • Payment through a link
  • Generic greeting, no tracking number
Verify before you act
  • Check your actual order
  • Verify the domain
  • Contact the sender on a known channel
  • Report the message
Score this risk in the Trust Index

See how SMS / Text ranks among channels people worry about most — from live, anonymous survey data.

Email

The Vendor Invoice Phishing Email

An email arrives that looks like it's from a supplier your company regularly works with. It says their bank details have changed and asks you to update your records before the next payment.

The Message
From: accounts@vendorname-payments.net
Subject: URGENT: Updated Bank Details – Action Required

“Dear Customer, We have recently updated our banking information. Please update your records and direct all future payments to the new account below. Kindly process the attached invoice at your earliest convenience to avoid any disruption in service.”

Red flags to spot

1
Look-alike domain

The sender domain is vendorname-payments.net, not vendorname.com. The real domain would be the company's primary domain — a payment subdomain is unusual.

2
Bank detail change via email

Bank account changes are one of the highest-risk Business Email Compromise (BEC) tactics. Legitimate vendors confirm these changes through multiple channels.

3
Vague greeting

“Dear Customer” instead of your name or company name. A real vendor knows who you are.

4
Pressure language

“At your earliest convenience to avoid disruption” implies consequences for delay — a common manipulation tactic.

How to verify

1
Verify through a known contact

Call your existing contact at the vendor using a phone number you already have on file — never one from the email.

2
Inspect the email headers

Check the full headers for the originating IP and authentication results (SPF, DKIM, DMARC). Mismatches reveal spoofing.

3
Compare with past invoices

Check whether the bank account, formatting, and sender address match previous legitimate invoices from the same vendor.

4
Implement a dual-approval process

For any bank detail change, require verbal confirmation and a second person's sign-off before processing payment.

What a legitimate interaction looks like

A legitimate vendor communicates bank detail changes through a verified phone call or secure portal and confirms with your existing contact — never solely by email.

Sample Trust Index score

An illustrative breakdown of how this scenario would score — nothing is submitted or stored.

20/100
High risk — verify out of band
Sender identity1/5

Look-alike domain (vendorname-payments.net) instead of the vendor's real domain.

Link & destination2/5

Attachment-driven request with no link to a known vendor portal.

Payment integrity0/5

Unprompted bank-detail change — the classic invoice-redirect pattern.

Pressure & context1/5

'URGENT' subject and service-disruption threat to rush approval.

Trust signals scored: 4 of 20 — a higher score means more independently verifiable signals. Low scores mean you cannot confirm the sender, link, or payee before acting.

What would change this score?

Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.

20/100
High risk — key signals cannot be confirmed

Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.

Presets:

One-page verification checklist

Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.

Red flags to check
  • Look-alike domain
  • Bank detail change via email
  • Vague greeting
  • Pressure language
Verify before you act
  • Verify through a known contact
  • Inspect the email headers
  • Compare with past invoices
  • Implement a dual-approval process
Score this risk in the Trust Index

See how Email ranks among channels people worry about most — from live, anonymous survey data.

QR Code

The Tampered Parking Meter QR Code

You park on a city street and see a QR code sticker on the parking meter. Scanning it takes you to a payment page that looks like the official city parking app — but it's designed to steal your card details.

The Message
Scanning the code opens: https://park-pay-city.com/pay?zone=4471

The page shows a city logo, asks for your card number, CVV, and billing address, and says your parking session will start after payment.

Red flags to spot

1
Sticker over the original code

Scammers place adhesive QR stickers over legitimate codes on parking meters, restaurant tables, and public signs. Check for layered or misaligned stickers.

2
Unfamiliar URL

park-pay-city.com is not the official city or parking-operator domain. Real municipal parking URLs typically use a .gov or the operator's known domain.

3
Direct card entry on an unknown page

Legitimate parking apps use secure, tokenised payment through their own verified app or a well-known payment processor — not a raw card-entry form on an arbitrary website.

4
No app store verification

The QR code sends you to a web page rather than the official app store listing. Real parking QR codes typically link to the operator's official app.

How to verify

1
Inspect the QR code physically

Look for stickers placed over the original printed code. If the QR sticker looks newer or differently placed than surrounding signage, don't scan it.

2
Use the official app directly

Download the parking app from the Apple App Store or Google Play Store by searching for the city or operator name — don't scan a code on the meter.

3
Preview the URL before opening

Most modern phones show the URL a QR code resolves to before opening it. If the domain doesn't match the official operator, close it.

4
Check for HTTPS and payment security

Legitimate payment pages use HTTPS with a valid certificate and a recognised payment processor. If the page asks for raw card details with no payment-provider branding, leave immediately.

What a legitimate interaction looks like

A legitimate parking payment uses the city's official app or a verified payment processor with HTTPS and tokenised card handling — not a raw card-entry form on an unfamiliar domain.

Sample Trust Index score

An illustrative breakdown of how this scenario would score — nothing is submitted or stored.

25/100
High risk — do not proceed
Sender identity1/5

A physical sticker carries no verifiable issuer — anyone can place it.

Link & destination1/5

Destination domain is not the city's official parking domain.

Payment integrity1/5

Raw card fields with no recognised payment-processor branding.

Pressure & context2/5

Plausible context, but zero independent way to confirm the payee.

Trust signals scored: 5 of 20 — a higher score means more independently verifiable signals. Low scores mean you cannot confirm the sender, link, or payee before acting.

What would change this score?

Tick the checks you were able to complete independently. The score updates in your browser only — nothing is submitted or stored.

25/100
High risk — key signals cannot be confirmed

Each unchecked box is a signal you cannot confirm yet — treat the request as unverified until you can.

Presets:

One-page verification checklist

Everything above condensed into a single checklist you can copy into notes or print and keep beside your desk.

Red flags to check
  • Sticker over the original code
  • Unfamiliar URL
  • Direct card entry on an unknown page
  • No app store verification
Verify before you act
  • Inspect the QR code physically
  • Use the official app directly
  • Preview the URL before opening
  • Check for HTTPS and payment security
Score this risk in the Trust Index

See how QR Code ranks among channels people worry about most — from live, anonymous survey data.

Universal Principles

Verification habits that work across every channel

While each channel has its own verification steps, four habits apply universally — no matter whether you're checking a text, an email, a QR code, or a payment link:

Slow down when there's urgency

Scammers manufacture time pressure to bypass verification. Any message demanding immediate action is itself a red flag — take a moment to check.

Verify the destination, not the link

Hover, preview, or type the known URL directly. Short links and look-alike domains are the most common entry point for fraud.

Confirm identity through a separate channel

If a message claims to be from your bank, vendor, or a buyer, verify by calling their official number or logging in through their known website — not through the message.

Never share credentials on a page you didn't navigate to yourself

No legitimate process requires you to enter bank logins, card details, or passwords on a page you reached through a link someone else sent.

FAQ

Frequently asked questions

How can I tell if a text message is a scam?+

Look for urgency, requests for personal or payment information, shortened or unfamiliar links, and sender numbers that don't match the organisation's official channels. Never click a link in an unexpected text from your bank, delivery service, or government agency — instead, navigate to their official website or app directly.

What should I check before clicking a link in an email?+

Hover over the link to preview the destination URL, check that the sender's email domain matches the organisation's real domain, look for personalised information that a scammer wouldn't know, and be suspicious of urgent or threatening language. When in doubt, go directly to the organisation's website instead of clicking.

Are QR codes safe to scan?+

QR codes can route you to any URL, including malicious ones. Before scanning a QR code in a public space or from an unfamiliar source, check for tampering (stickers placed over the original code), avoid scanning from printed flyers or unsolicited emails, and preview the URL if your device offers that option. If the destination asks for login credentials or payment, close it immediately.

How do I verify a payment request is legitimate?+

Confirm the request through a separate, known channel (call the person or organisation on their official number), check that the payment platform and URL are the real ones, be wary of pressure to pay immediately, and never enter card details on a page you reached through an unfamiliar link. Legitimate platforms use secure, verifiable payment infrastructure — not ad-hoc links.

What is the single most important thing I can do?+

Slow down. Scammers rely on urgency to bypass your normal caution. Whenever a message, call, or request demands immediate action, treat that urgency itself as a red flag and take a moment to verify through a separate, trusted channel before acting.

Help us research digital trust.

Have you encountered a scam like these? Share your experience — it's anonymous and takes two minutes.

Disclaimer. TRUST.AI is an early-stage research and product-development initiative. These examples are educational and based on common scam patterns. They are not professional cybersecurity, legal, or financial advice. Users should independently verify important digital interactions.