Scams · guide

Short code 22395: what that text is, and what to do

By Alberto Gulotta · Updated · 18 min read

A text arrived from short code 22395, you did not ask for it, and no page seems to agree on who sends it. That disagreement is the real finding: of the five results recorded for this page on 10 September 2026, not one was a source that could know, and there is one check the rulebook puts in your hands instead.

No company is named here as the sender, because the evidence for every name in circulation is a forum thread or a page that does not contain the claim. Everything below is quoted from the United States short code registry, the CTIA short code handbook and the Federal Trade Commission, each read in full on 10 September 2026.

What a short code is, and why it is not a phone number The short code registry sells codes rather than looking up their owners. Its own order form states that a code must contain five or six numeric digits, not starting with zero or one, and that select or memorable codes cost one thousand dollars a month each. A short code is therefore a rented slot in a messaging programme, not a telephone line: there is nothing at the other end to ring, and the digits identify the lease rather than the company using it. A RENTED SLOT, NOT A TELEPHONE LINE An ordinary number belongs to one line you can ring it back and somebody answers A short code five or six digits, leased by the month, per programme nothing to ring back So the digits name a lease, not a company Which is why the answer to “who is this?” is not on your screen. AI Tools Primer · figure
The shape and the price are from the short code registry’s own order form, read 10 September 2026. Figure drawn by AI Tools Primer.

What a short code is, and why you cannot ring it back

The five digits are not a phone number that somebody owns. They are a slot rented by the month from a registry, and the registry is a shop rather than a directory. Its public search page — the one that comes up when you look for who a code belongs to — is an order form with a shopping cart, and it tells you the two things that define the object: “Code must contain 5 or 6 numeric digits, not starting with 0 or 1”, and “Select or Memorable codes are $1,000/m each”.

That is the whole shape of it. A company rents digits, attaches them to a messaging programme, sends from them, and stops paying when the programme ends. The next company rents the same digits. Nothing about the number itself survives the change of tenant, which is the first reason no honest page can publish a list of which codes are safe.

It also explains the thing that makes people uneasy: you cannot ring it. There is no line at the other end and no voicemail, because the 22395 short code was never a telephone line to begin with. Silence when you dial is the normal behaviour of the object, not a sign that something is wrong.

Who knows who leases a short code, and who they tell The registry states that at least once annually its vetting agents vet all short code leaseholders, their brand clients and associated content providers, and that complete registry vetting results are available to registrants through their short code portal at any time. Registrants are the companies that lease codes. The information exists, it is checked every year, and the person receiving the message is not among the people it is shown to. THE INFORMATION EXISTS. THE ARROW TO YOU DOES NOT. The registry vets every leaseholder, at least once a year The registrants the companies that lease codes, through their portal You not on the list This is not secrecy, and it is not a gap in your research The register is a trade service. It answers to the companies that pay for codes, and the public search on its site is an order form for renting a free one. AI Tools Primer · figure
Both statements are quoted from the short code registry’s Registry Vetting Process page, read 10 September 2026. Figure drawn by AI Tools Primer.

Who operates short code 22395: what can be established, and what cannot

Somebody does know. The registry states that “At least once annually, CTIA’s Vetting Agents vet all short code leaseholders, their Brand Clients and associated Content Providers with the Registry Vetting process”, and it says who receives the outcome: “Complete Registry Vetting results are available to CSC Registrants through their short code portal access at any time”.

Registrants are the companies that lease codes. So the information exists, it is refreshed every year, and it is delivered to the trade rather than to the person holding the phone. That is not a conspiracy and it is not a hole in your searching; it is what the register is for.

Here is what was tried on 10 September 2026, so that the next person does not repeat it. The registry’s public lookup turned out to be the rental form described above, not an owner search. The interface behind it answered every path attempted with an authentication error. The two companies most often named in connection with these digits publish no short codes of their own anywhere on their websites, help centres or developer documentation, all of which were searched.

So this page does not tell you who sends it, and that is the finding rather than a gap in it. Every page that does tell you is doing one of two things: reading the content of the message and guessing backwards from it, or repeating a forum. Both are the method that produces a different answer every time, which is exactly what has happened here.

The answers in circulation contradict each other

This is worth seeing laid out, because a single confident answer feels like knowledge and three confident answers are the thing itself.

Google showed six organic results for this code on 10 September 2026 and five are in the record for this page; why the sixth is not there was never written down. In those five, Google’s summary box named an authentication provider, and the citation it offered for that was a five-year-old forum thread of thirty-nine words. A widely read legal-explainer page named a large American bank, citing that bank’s own security page as its source. A third answer, a checkout wallet, appeared elsewhere in the same results. Three different companies, three different industries, one set of digits.

One of the three can be checked, and it fails. The bank’s security page was read on 10 September 2026: it publishes twenty-two short codes as its own, each with the programme it belongs to, and these digits are not among the twenty-two. The page cited as the proof is the page that contradicts it. Nothing here says the bank does not send it — a company can use a code it does not list — only that the evidence offered for the claim does not contain the claim.

None of the three is repeated here as an answer, and none is named. Naming a company as the sender of a message on this evidence is how somebody ends up ringing the wrong bank, or trusting a message because a page said the sender was reputable.

Three answers in circulation, and the one check that is yours Searching these digits produces at least three different owners: an authentication provider named by Google’s summary box on the strength of a forum thread, a large American bank named by a widely read page, and a checkout wallet named by others. None cites a source that could know, and the bank’s own security page lists twenty-two short codes without this one among them. The check that does work is in the short code rulebook: a message sender must answer the word HELP with the programme name and how to contact them. THREE ANSWERS, NONE WITH A SOURCE THAT COULD KNOW An authentication firm named by a summary box, sourced to a forum A large bank named by a popular page — the bank does not list it A checkout wallet named by others again, with nothing behind it The rulebook gives you one question you can ask Text HELP to the code Message senders must answer HELP with the programme name and how to reach them. An answer identifies the programme. Silence tells you it is not following the rules. AI Tools Primer · figure
The obligation is section 3.4 of the CTIA Short Code Monitoring Program Handbook, version 1.9. The bank’s list was counted on its own security page. Figure drawn by AI Tools Primer.

The one check you can actually run

The rulebook for United States short codes is the CTIA Short Code Monitoring Program Handbook, and it places an obligation on the sender that the reader can use. Section 3.4: “At a minimum, Message Senders must respond to messages containing the HELP keyword with the Program name and further information about how to contact the Message Sender.”

Sending the single word HELP to the code is therefore not a reply to the message, not a confirmation that you read it, and not a request for anything. It is the one question the rulebook obliges the other end to answer, and the answer is the programme name and a contact route. That names the programme when the sender follows the rules, and tells you something equally useful when it does not: a code that answers HELP with nothing is a code operating outside the handbook, which is itself the finding.

Two limits, stated rather than glossed. This is a United States scheme, and it does not describe short codes in other countries. And the handbook is a trade rulebook rather than a law, so a sender who ignores it is not committing an offence — it is the wireless carriers, not a regulator, who enforce it by auditing and by cutting off codes.

The same handbook is the reason an unexpected code is genuinely irregular rather than merely annoying. Section 3.3.1 is one sentence: “Unsolicited messages should not be transmitted using Short Codes.” It defines those as including “messages delivered without a consumer’s consent and messages sent after a consumer has opted out”.

The code in the message, and the only rule that matters

Whatever the digits at the top turn out to belong to, the six digits inside the message behave the same way, and this is the part worth carrying away from the page.

A verification code that arrives unasked means somebody is putting your number or your address into a login box. Not that they are in. The code is the second half of a pair and it came to you, which means whoever asked for it does not have it. One stray message is usually a stranger mistyping their own number. The same message returning over several days is somebody trying, repeatedly, and the useful response is on the account rather than on the message: change the password there and everywhere it is reused, and check whether the address involved has appeared in a known data breach, which is where the attempt normally starts.

And the code is never read out to anybody. The Federal Trade Commission states it without qualification: “Anyone who asks you for your account verification code is a scammer.” That includes a caller who rings a minute later, knows your name, and says they are from the company whose code you have just received — which is the ordinary shape of the attack, because the code alone is useless to them until you hand it over.

The other set of digits people search for by number, short code 787473, brings up the same question and gets the same answer here: the sites that name an owner for it are aggregators and forums rather than sources that could know, and the registry publishes the leaseholder to the trade rather than to the recipient. What to do does not change with the digits.

What to do, in order, and none of it costs anything

The first two steps settle almost every case. The rest is for a message that keeps coming.

Do not send the code to anyone The FTC: “Anyone who asks you for your account verification code is a scammer.” This holds even if the caller knows your name and the company is real.
Count the messages before doing anything else One, then silence: somebody mistyped their own number. The same message over several days: treat it as attempts to sign in, and go to the account.
Text the single word HELP to the code, if you want the programme named The handbook obliges the sender to answer with the programme name and a contact route. No answer is also information.
Do not ring the digits, and do not expect a directory to name them There is no line to ring, and the register releases leaseholder details to the companies that lease codes, not to recipients.
Report it if somebody asked you for the code ReportFraud.ftc.gov for the person who asked; forwarding the text to 7726 feeds the carriers’ own filtering.

The two that arrive with a name attached. When the message carries a brand rather than only digits, the remedy belongs to that company and there is a first-party route to it: a Link verification code is Stripe’s wallet, and a Shop verification code is Shopify’s, and each has a page that stops the messages without answering one.

Where this sits. A code you did not ask for is the quietest thing in phishing and scam calls, and usually a sign of something being attempted rather than something having happened. The other message that arrives from bare digits is about a parcel, and it turns on the same kind of fact: a real delivery text is one you asked for, and has no link in it. If what you are getting is constant marketing rather than codes, reducing spam texts is a different job. If the number on a call looks like your bank’s, the screen proves nothing. If a reused password is why anything is being tried, that is the door. And if codes stopped arriving at all, a SIM swap moves the number itself.

Where to start

Four ways into this page.

“Who is this number?”
What can be established, and what cannot — who operates it
“Why do the answers contradict each other?”
Three names in circulation, one checkable, and it fails — answers that contradict
“Is there anything I can check myself?”
One thing, from the rulebook — the check that is yours
“What do I do about the code?”
The rule that never changes — the code itself

The same text with a brand on it

When the message names a company, the remedy belongs to that company, and both of these have a first-party route that does not involve replying.

When a stray code is a symptom

A code that keeps returning points at something behind it, and these are the pages for the something behind it.

Questions people also ask

What number is short code 22395?

It is not a phone number. It is five digits leased by the month from the United States short code registry and attached to a messaging programme, so there is no line to ring back and the digits identify a lease rather than a company.

Who owns short code 22395?

Not one of the five results recorded for this page on 10 September 2026 was a source that could know. The registry vets every leaseholder at least once a year and states that the results are available to registrants — the companies that lease codes — through their portal. The pages that do name an owner disagree with each other and cite forums or a page that does not contain the claim.

Is a text from short code 22395 a scam?

The message itself is usually a real verification code. The scam, when there is one, is the call or message that follows and asks you to read the code out. The FTC is flat about it: “Anyone who asks you for your account verification code is a scammer.”

Why did I get a code when I was not logging in to anything?

Somebody put your number or your email address into a login or checkout box. One stray message is normally a stranger mistyping their own number. The same message repeating over days means somebody is trying an account of yours, and the response belongs on the account.

Can I find out who a short code belongs to?

Not from the public register. Its search page is an order form for renting an unused code, and its interface refuses unauthenticated requests. The route that exists is the handbook one: text HELP to the code, which the sender is obliged to answer with the programme name.

Should I reply STOP or block short code 22395?

Blocking is safe and does nothing about the cause. Replying to an unexpected message confirms the number reaches a real person; HELP is the exception worth making, because the rulebook requires an answer that identifies the programme.

Not covered here. It does not name the company behind the digits. Three different companies are named for them elsewhere, the one claim that can be checked turns out not to be supported by the page cited for it, and the register releases leaseholder details to the companies that lease codes rather than to the people receiving the messages.

It does not publish a list of safe or unsafe codes. Codes are leased by the month and change hands, so a list would be wrong the week after it was written.

And it sells nothing. There is no product here, no affiliate link, and the only actions suggested are free ones on official sites. What holds instead is simple: the shape and price of a short code come from the registry’s own order form, the vetting statements from its Registry Vetting Process page, the HELP obligation and the rule on unsolicited messages from the CTIA handbook with its version and effective date, the rule on the code itself from the FTC, and no company is named as the sender of anything.

Sources

  1. CTIA — Short Code Monitoring Program Handbook, version 1.9, effective 2 August 2023, read in full: section 3.4, which requires message senders to answer the HELP keyword with the programme name and how to contact them, and section 3.3.1, which states that unsolicited messages should not be transmitted using short codes and defines those as including messages sent without consent and messages sent after an opt-out — api.ctia.org, read 10 September 2026.
  2. U.S. Short Code Registry — Registry Vetting Process: that CTIA’s vetting agents vet all short code leaseholders, their brand clients and content providers at least once a year, and that complete vetting results are available to registrants through their short code portal at any time — www.usshortcodes.com, read 10 September 2026.
  3. U.S. Short Code Registry — Find a short code: the page that a search for a code owner leads to, which is an order form with a shopping cart rather than a lookup, and which states the shape of a code and the monthly price of a select or memorable one — www.usshortcodes.com, read 10 September 2026.
  4. Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): that anyone who asks you for your account verification code is a scammer, and the direction to report at ReportFraud.ftc.gov — consumer.ftc.gov, read 10 September 2026.
  5. Federal Trade Commission — How to recognize and report spam text messages: the routes for reporting, including forwarding to 7726 — consumer.ftc.gov, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026 · last checked 11 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.