Scams · guide

Link verification code: what that text actually means

By Alberto Gulotta · Updated · 22 min read

A link verification code arrived by text and you did not ask for it. Link is Stripe’s checkout wallet, the code is real, and the thing that decides what to do is not the wording of the message: it is whether it happened once or keeps happening.

Nothing here is a product and no number is published as safe or unsafe. Everything below is quoted from Link, Stripe, Twilio, the Federal Trade Commission and the United States short code registry, each read in full on 10 September 2026.

Why a code on its own opens nothing, in the Federal Trade Commission’s own image The FTC compares an account password and a verification code to the lock on a doorknob and a deadbolt lock: if you unlock the doorknob but not the deadbolt you cannot get in, and if you know the password but not the code you cannot get in either. The same is true for somebody attacking the account, which is the reason the code is worth asking you for. The figure shows the two locks side by side, with the note that whoever already has the password needs only the second one, and that is the message that arrives asking you to read it out. TWO LOCKS, AND WHY ONE ALONE IS USELESS The password the FTC calls it the lock on the doorknob — something you set, once, and reuse The verification code the deadbolt — a new one every time, sent to a phone or an inbox that is supposed to be yours Whoever already has the first one needs only the second That is what the message asking you to read the code out loud is for. AI Tools Primer · figure
The two-lock comparison and the wording are the Federal Trade Commission’s, from its March 2024 consumer alert on verification codes. Figure drawn by AI Tools Primer.
Once, or again and again: the only question that changes what you do One unexpected Link verification code, and then nothing, matches the explanation Stripe and Link both give: somebody else typed their own phone number incorrectly at a checkout, and the code went to you. Nothing of yours is involved and there is nothing to do. The same code arriving repeatedly is a different situation: something is repeatedly asking for a code against your number or your email address, which is what an attempt to sign in looks like from your side, and the useful move is on the account the code protects rather than on the message. THE SAME MESSAGE, TWO COMPLETELY DIFFERENT SITUATIONS ONCE A typing mistake, almost always Stripe: “it is likely that someone else entered their own number incorrectly” AGAIN AND AGAIN Something is trying to sign in Each code is one attempt against your number or your email — and the attempts are being made now Nothing to do. Do not send the code on. Go to the account, not to the message: change the password, then move the codes off SMS. AI Tools Primer · figure
The left-hand explanation is quoted from Stripe’s own support page. The split itself is the distinction no page on the first page of results makes. Figure drawn by AI Tools Primer.

Once is a typing mistake. Repeatedly is not.

This is the distinction that decides everything else, and it is the one thing missing from every page currently on the first screen of results for this question.

One code, then nothing. Stripe’s own wording for this case: “If you received a message from us but did not enter your phone number on a website using Link, it is likely that someone else entered their own number incorrectly.” Somebody mistyped a digit at a checkout, their code came to you, and their purchase failed. Nothing of yours is involved. There is nothing to fix and nobody to tell.

The same code, again and again, over days. Each of those messages is a request for a code made against your phone number or your email address. Something is making those requests repeatedly, and it is not a person mistyping the same wrong digit for a week. The important thing is where the answer is: not in the message, and not in the number it came from, but in the account the code protects. Somebody is attempting to reach it, which means an email address of yours is being used as a login somewhere, and the value of knowing that is that you can get ahead of it.

What to do with that is ordinary and effective. Change the password on the account the code belongs to and on anything sharing that password. If the email address turns up in a known data breach, that is the likely source of it being tried at all. And move the second factor off text messages where you can, because a code that is generated on your own device is not a code somebody can ask you to read out — the difference between the two is worth understanding before you rely on either.

The one rule, and it has no exceptions

Nobody legitimate will ever ask you for the code. The Federal Trade Commission puts it without qualification: “Never give your verification code to someone else. It’s only for you to log into your account. Anyone who asks you for your account verification code is a scammer.”

That covers every route the request can take: a phone call, a text message replying to the code, a chat window, an email, a person claiming to be from the fraud department of your own bank. The FTC names that last case specifically, because it is the one that works.

The FTC’s instruction for the moment it happens is four short steps: “If someone asks you for your verification code, don’t engage. Hang up. Block their number. Stop texting them.” And if you are worried the account really does have a problem, the same alert tells you how to check without using anything the caller gave you: “contact your bank, credit union, or investment advisor directly. Use a number you trust, like the one on your statement or in your app. Never use the number the caller gave you; it’ll take you to the scammer.”

Notice what that rule protects you from. It does not require you to work out whether the message is real. It works even when you cannot tell, which is most of the time, and that is the whole point of having it decided in advance.

How to stop the messages, from Link’s side

Two routes, both published by Link itself, and neither of them involves replying to the text. Replying is the one thing worth avoiding on principle, because a reply confirms to whoever is on the other end that the number reaches a real person.

If you do use Link. Its help page offers the direct remedy for a code you did not ask for: “You can take precautions by logging out of Link on all devices.” That ends whatever session on some other machine is being remembered. Link also points at its own record of what has been bought through it — “You can see your past purchases through Link by going to Activity” — which is the fastest way to find out whether anything went through rather than merely being attempted.

If you do not use Link and never knowingly did. Then the account should not exist, and Link says so: “If you don’t remember saving your information with Link during a previous purchase, you can delete any Link account associated with your email.” Deleting it removes the reason the messages are being generated at all.

Neither of these is a setting on your phone, and blocking the number does not help for long: the codes come from short codes that rotate, and blocking one silences the next genuine code you actually need rather than the unwanted ones.

The chain a verification code travels, and the point where it stops being readable A shop takes a payment; Link, which is Stripe’s wallet, is asked to verify the phone number; a messaging company such as Twilio actually sends the text; and it leaves from a five or six digit short code. Twilio describes its own position in that chain in its help centre. The last step is where the reader is stuck: the number on the screen is the only part visible, and no source that would know publishes which company is behind it. WHO ACTUALLY SENT IT, AND WHERE THE TRAIL ENDS 1 A shop takes a payment 2 Link, by Stripe verifies the number 3 A messaging firm sends the text 4 A short code what you can see Only step 4 is visible to you, and step 4 names nobody The registry that vets the leaseholder gives the result to the leaseholder, not to you, and Stripe does not publish the number it sends from. AI Tools Primer · figure
Twilio describes step 3 in its own help centre; step 4 and the closing line are from the Short Code Registry’s published vetting process, and Stripe’s own page on this message — about 370 words, read again on 11 September 2026 — does not contain the number. Figure drawn by AI Tools Primer.

The number it came from, and what can and cannot be established about it

A great many of these messages arrive from a bare five- or six-digit sender rather than a name, and that sender is the thing people end up searching for. It is worth saying plainly what can and cannot be established about one, because the pages that answer confidently are guessing.

What can be established. Search results tie the digits to this exact question rather than to any company: the first organic result for the bare sender number, read on 10 September 2026, is the same discussion thread that is first for the words “link verification code”. People searching the digits and people searching the name are the same people with the same message open.

What cannot. The United States short code registry, run by CTIA, does vet who leases every code — “At least once annually, CTIA’s Vetting Agents vet all short code leaseholders, their Brand Clients and associated Content Providers” — and it keeps the answer inside: “Complete Registry Vetting results are available to CSC Registrants through their short code portal access at any time.” Registrants are the companies that lease codes. Not the person receiving one. The public search on the same site is a leasing form for codes that are still free, not a lookup of who holds which.

Stripe does not publish the number it sends from either — searched across its own sites on 10 September 2026, and it is not there. So this page attributes nothing.

And the confident answers elsewhere are checkably wrong at least once. One widely-read page states flatly that a particular five-digit sender belongs to a named American bank, and cites that bank’s own security page as its authority. That security page lists twenty-two short codes the bank uses, and the number in question is not one of them. Read on 10 September 2026, both of them. It is a useful demonstration of how such an attribution gets produced, and a reason to treat the confident naming of a sender as unverified until the company itself publishes it — which some companies do, in exactly this form.

What the rules say a legitimate short code must do. The relevant document is CTIA’s Short Code Monitoring Program Handbook, version 1.9, effective 2 August 2023. Its customer care section requires that “At a minimum, Message Senders must respond to messages containing the HELP keyword with the Program name and further information about how to contact the Message Sender”, and its compliance tables require that reply to carry the “Program (brand) name OR product description”. So a compliant programme is identifiable in principle. In practice that means sending a message to a number you did not expect, which tells whoever is behind it that the number is live — so it is a poor first move for a code you did not ask for, and the account-side checks above are better ones.

Where a request for your code gets reported

Receiving an unrequested code is not itself something to report; nobody has done anything to you yet. What is worth reporting is the second half, when a person asks you to hand the code over.

The FTC’s route for that is one address: “report them to the FTC at ReportFraud.ftc.gov”. It takes a few minutes, it does not require you to have lost anything, and it is the same address whether the approach came by phone, by text or by email.

Twilio, one of the companies that physically sends codes on behalf of businesses, publishes its own explanation of why a stranger’s security code reaches you: “The message came from Twilio, a communications service that businesses use to send security codes when you log in or sign up for their service”, and for repeated messages it directs people to its support team rather than to the business. It is a useful reminder that the company whose name is on the message is often not the company that sent it.

If money has already moved, or an account of yours has already been taken, this page is not where to spend the next ten minutes: the deadlines are on the identity theft page and the first hour is the one that counts.

Ten minutes, and none of it costs anything

In this order. The first two settle which situation you are in.

Count the messages One, then silence: a stranger’s typing error, nothing to do. Several over days: treat it as an attempt to sign in and carry on down this list.
Do not send the code anywhere, to anyone, for any reason The FTC: “Anyone who asks you for your account verification code is a scammer.” No exception for somebody who says they are from your bank.
Change the password on the account the code belongs to And on anything else using the same one. This is the step that actually ends repeated attempts.
Close the Link side of it Link’s own two remedies: log out of Link on all devices, or delete any Link account associated with your email if you never meant to have one.
Report the request, not the code ReportFraud.ftc.gov, if a person asked you to hand the code over.

The one next to this one. The same message arrives under a different brand name from Shop Pay, and although the question reads identically the fix is somebody else’s: that is on the Shop verification code page, which has a first-party opt-out form that removes your number without replying to anything.

Where this sits. A code you did not ask for is the quietest of the things collected under phishing and scam calls, and usually the earliest: it is a sign of something being attempted rather than something having happened. If the messages are constant and not about codes at all, reducing spam texts is a different job. If a password of yours is the reason any of this is being attempted, that is the door. And if a number rather than an account is what was taken, a SIM swap is a different attack with a free defence.

When the message carries no brand at all. This page can name the sender because the message does. When all you have is five digits, the question changes into who leases those digits, and the register keeps that answer for the companies that lease codes — what was tried instead, and the one check that is yours. The general vocabulary for all of this — why a text and a call need different responses — is what smishing and vishing refer to, and the commonest unbranded lure of the lot is the parcel delivery text.

Where to start

Four ways into this page.

“What even is Link?”
The wallet and why it has your number — what link is
“It has happened four times this week.”
That is the other case — once or often
“Somebody is asking me for the code.”
One rule, no exceptions — never
“How do I make it stop?”
Link’s own two routes — how to stop

The same message, other names

An unrequested code looks the same whichever wallet sent it, and the remedy is always the wallet’s, never the phone’s.

If it is more than a stray code

Repeated codes are a symptom. These are the pages for what they are usually a symptom of.

Questions people also ask

Why am I getting a link verification code text?

Because a checkout wallet called Link, made by Stripe, is verifying a phone number — either yours, on a device it does not recognise, or somebody else’s who mistyped a digit at a shop’s checkout. Stripe’s own wording is that “someone else entered their own number incorrectly”.

Why did I get a verification code when I did not request it?

One unexpected code, then silence, is almost always a stranger’s typing mistake and needs nothing from you. The same code arriving repeatedly is different: something is asking for a code against your number or email over and over, and the useful action is on the account it protects, not on the message.

Is a link verification code text a scam?

The message can be a genuine code from a real payment service, and Link and Stripe both describe sending exactly this message. What is always a scam is the follow-up: somebody contacting you and asking you to read the code out. The FTC is flat about it: “Anyone who asks you for your account verification code is a scammer.”

Should I reply STOP to make them stop?

Replying tells whoever is on the other end that the number reaches a real person, and it does not address the cause. Link publishes two routes that do: logging out of Link on all devices, or deleting any Link account associated with your email address.

Who is the five-digit number that sent it?

It cannot be established from any source that would know. The United States short code registry vets every leaseholder but releases the result only to “CSC Registrants through their short code portal access”, and Stripe does not publish the number it sends from: its own page on this message, read again on 11 September 2026, does not contain it. Pages that name a company for a given sender disagree with one another.

Does this mean my phone has been hacked?

No. A verification code arriving is a message sent to your number; it requires nothing on your phone and proves nothing about it. What it can indicate, when it repeats, is that an email address or a number of yours is being tried as a login somewhere else.

Not covered here. It does not tell you who operates a short code. The registry that knows gives the answer to the companies that lease codes and not to the people who receive them, so this page says that instead of naming somebody.

It does not tell you to reply to the message, in any form. Every route offered here goes through the account or the company’s own site, because a reply confirms the number is live and does nothing about the cause.

And it does not sell you anything to stop it. Nothing on this page costs money, no product is named as a defence, and there is no affiliate link anywhere on it. What holds instead is simple: every quotation is from Link, Stripe, Twilio, the FTC or the short code registry with the date each was read, the number the message came from is deliberately not attributed to anybody, no page here tells you to reply to an unexpected text, and nothing is sold.

Sources

  1. Link — Why did I receive an email/SMS when I don’t have a Link account?: that Link uses email and SMS to verify identity on a new site or new device, the distinct explanation that an unrequested SMS often means being remembered on another device, the note that a number may simply have been entered by mistake, and the two remedies — logging out of Link on all devices, and deleting any Link account associated with your email — support.link.com, read 10 September 2026.
  2. Stripe — Received “Your Stripe verification code is” text message from Stripe: that the message follows from a phone number saved for future purchases using Link, that Link works at tens of thousands of online businesses, and the wording for the unexpected case — that it is likely somebody else entered their own number incorrectly — support.stripe.com, read 10 September 2026.
  3. Twilio Help Center — Why am I Receiving Verification Code Messages or Calls?: that the message came from Twilio, a communications service businesses use to send security codes at login or sign-up, that a code you did request should simply be used, and that recurrent messages go to Twilio support — help.twilio.com, read 10 September 2026.
  4. Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): the comparison of password and code to a doorknob lock and a deadbolt, the rule that anyone who asks for your account verification code is a scammer, the four-step instruction — don’t engage, hang up, block their number, stop texting them — the direction to report at ReportFraud.ftc.gov, and the advice to reach your bank only on a number you already trust — consumer.ftc.gov, read 10 September 2026.
  5. Chase — Chase Self-Service Short Message Service (SMS) Terms and Conditions: the twenty-two short codes the bank publishes as its own, each with the programme it belongs to, and the instruction that a message which looks suspicious should not be replied to but checked by calling the number on the back of the card or on the statement. Read alongside a widely-read page that names this bank as the operator of a sender number which does not appear on that list — www.chase.com, read 10 September 2026.
  6. CTIA Short Code Registry — Registry Vetting Process: that CTIA’s vetting agents vet all short code leaseholders, their Brand Clients and associated Content Providers at least once annually, and that complete vetting results are available to CSC Registrants through their short code portal access — that is, to the companies that lease codes and not to the people who receive messages from them — www.usshortcodes.com, read 10 September 2026.
  7. CTIA — Short Code Monitoring Program Handbook, version 1.9, effective 2 August 2023: the customer care requirement that message senders must respond to the HELP keyword with the programme name and contact information, and the compliance tables requiring the programme brand name or product description in that reply — api.ctia.org, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026 · last checked 11 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.