DefenseGo Direct
Core move

Go Direct

Do not act on links in messages. Reach the company through its official app or a bookmark.

This move is free.No product needed — see Tools only if a paid option genuinely helps.

Almost every scam text and phishing email has one job: to get you to tap its link. Go Direct removes that link from the equation entirely. Instead of acting on the message, you reach the company yourself — and the whole attack collapses, because it only worked through the door you didn't use.

The link is the attack

A smishing text or phishing email isn't dangerous because of what it says — it's dangerous because of where its link goes. The FBI defines smishing as "a social engineering attack using fake text messages to trick people into downloading malware, sharing sensitive information, or sending money." The words just exist to get your thumb onto the link, which leads to a look-alike page built to harvest your password or card number.

That's why arguing with the message — "is this real? does it look right?" — is a losing game. The link can be made to look perfect. Go Direct skips the judgment call: you never use the message's link at all, so it doesn't matter how convincing it is.

What "Go Direct" means

When a notice arrives — a package needs a fee, a toll is unpaid, your bank flagged something, an account needs reverifying — you treat the message only as a prompt to check, never as a place to act. Then you reach the company through a route you already trust: the app on your phone, a bookmark you saved, the number on the back of your card, or an address you type yourself.

If the message is real, you'll see the same thing on the real account. If it's a scam, you'll see nothing — and you'll have given the link nothing.

How to do it, by channel

For a text or email: don't tap anything. Open the company's official app, or type its known web address into your browser yourself, and check there. The FCC's advice for toll texts is exactly this — go to your account directly rather than through the message.

For a phone call: hang up and call back on a number you find independently (this is the closely related Call-Back Rule). For a QR code in an unexpected place: don't scan it — go to the source directly instead.

Set it up today
  1. When any "account / payment / delivery problem" message arrives, pause before tapping — assume the link is hostile until proven otherwise.
  2. Find the company a way you already trust: its app on your phone, a bookmark you made, or the number on your card or statement.
  3. Check the claim there. A real issue shows up on the real account; a scam shows nothing.
  4. Save bookmarks now for your bank, toll service, and main shopping accounts, so "go direct" is one tap when you're rushed.
  5. Never reply to a scam text — not even "STOP" or "N". Delete it, and forward spam texts to 7726 (SPAM).

What it looks like with a "package held" text:

Text USPS: your package is held pending a $2.99 redelivery fee. Confirm here: usps-redeliver[.]info
You (doesn't tap) Opens the real USPS app from the home screen instead.
You No held package, no fee owed. Deletes the text.

Frequently asked

What if the message turns out to be real and I miss something?

Going direct never makes you miss a real notice — it just routes you to it safely. If a toll, package, or bank issue is genuine, it will be waiting for you on the official app or account when you check there. You lose nothing by ignoring the link; you only lose the risk.

The link looked exactly like the real website. How can that be a scam?

Look-alike addresses are trivial to make — a slightly-off domain, a familiar logo, a convincing layout. The FBI notes scam links are "created to impersonate" the real service's name. That's precisely why Go Direct doesn't rely on spotting the fake: you don't use the link at all, so a perfect copy is as useless to the scammer as a sloppy one.

Is it safe to just reply asking if it's legitimate?

No — don't reply at all. Any response, even "STOP", confirms to the scammer that a real person is reading, which often brings more messages. Delete it and check the real account directly instead.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every move is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›