Smishing Analyzer
Check a messageDownload
Appearance

Plain-language glossary

The words that get used as though everyone already knows them.

Last reviewed 28 August 2026

OTP One Time Password

A short code, usually six digits, sent to your phone to prove it is really you.

It is the last thing standing between someone and your account. This is why every scam eventually asks for one, and why no genuine bank ever will.

UPI Unified Payments Interface

The system behind GPay, PhonePe, Paytm and your bank app for sending money instantly.

A UPI transfer is instant and hard to reverse. A "collect request" asks you to pay someone; approving one sends money out, it never brings money in.

UPI PIN

The four or six digit number you type to approve a UPI payment.

You only ever need it to send money. If someone says you must enter it to receive money, they are taking money from you.

Phishing

Pretending to be someone you trust in order to get your details.

The name is a pun on fishing: a lure is put out, and whoever bites is caught.

Smishing SMS phishing

Phishing that arrives as a text message rather than an email.

A text feels more personal and more urgent than an email, and phones show less of a web address, so a fake one is harder to spot.

APK Android Package

An installable Android app file.

An APK from a link installs software that Google has never checked. This is how apps that read your messages and steal banking details get onto a phone.

Sender ID

The short name a company sends from, like VM-HDFCBK or AD-AMAZON, instead of a phone number.

Registered businesses in India send from these headers. A message claiming to be your bank but arriving from an ordinary ten digit mobile number is a strong sign it is not your bank.

Shortened link

A short web address such as bit.ly or tinyurl that redirects to a longer one.

It hides where the link actually goes. Legitimate businesses have no reason to hide their own address from you.

Lookalike domain

A web address that is almost, but not quite, a real one. hdfcbnk.com instead of hdfcbank.com.

It is designed to survive a glance rather than an inspection, which is why reading an address letter by letter matters.

AePS Aadhaar enabled Payment System

A way of withdrawing money using an Aadhaar number and a fingerprint.

It means a fingerprint can move money. This is why messages asking you to confirm biometric or Aadhaar authentication are dangerous.

SIM swap

When someone takes control of your phone number by having it moved to their SIM.

Whoever controls your number receives every OTP sent to it. This is why a request to approve a port or share a UPC code is serious.

Screen sharing app

Software such as AnyDesk or TeamViewer that lets another person see and control your screen.

Someone on a call can watch you type your password and then use it. No bank will ever ask you to install one.

Digital arrest

A scam where a caller poses as police, CBI or customs and keeps you on a video call while you transfer money to "clear" a case.

No law enforcement agency in India works this way, and none takes payment to close a case.