How do you report a spam text message?

Direct Answer

How do you report a spam text message? In the United States, forward it to 7726, which spells SPAM on the keypad and is free on AT&T, T-Mobile and Verizon.

Your carrier will usually reply asking for the sender's number, because a forwarded text does not reliably carry the original sender with it. Answer that second message or the report cannot be matched to anything.

Report it inside your phone as well. On an iPhone, a thread from an unknown sender shows a Report Junk option; on Android, Google Messages offers Report spam. Those go to Apple or Google and to your carrier.

Report the fraud itself to the FTC at reportfraud.ftc.gov, and to the FBI's Internet Crime Complaint Center at ic3.gov if you lost money.

Tell the organization being impersonated. Banks, delivery carriers, toll authorities and government agencies almost all publish an address for forwarded scam messages, and they act on what arrives there.

Do not reply and do not tap the link. A reply confirms the number is live and reaching a real person.

Why This Problem Exists

  • A forwarded SMS does not carry the original sender reliably, which is why 7726 has to ask a second question before a report becomes useful.
  • Reporting and blocking are different actions. Blocking stops one number from reaching you and tells nobody anything, while reporting is what reaches the carrier and the impersonated brand.
  • Most people have somewhere obvious to report a suspicious email at work and nowhere obvious to report a suspicious text.
  • Scam numbers rotate constantly, so a single report usually matters more for the pattern behind the number than for the number itself.
  • Reporting asks for a few taps at the moment someone is annoyed and just wants the message gone, so most suspicious texts are deleted instead of reported.

How It Works Today (Current State)

  • 7726 is the closest thing to a universal reporting route in the United States, it is free, and it is run by the carriers rather than by any vendor.
  • It asks for the message first and the sender's number second, then closes the exchange with a thank-you. It does not tell you what the message turned out to be, and it does not come back to you again.
  • Apple and Google both collect junk reports, and neither tells the person who reported anything about what came of it either.
  • The FTC report feeds Consumer Sentinel, a database law enforcement can query. That matters in aggregate and it produces no answer for the person who filed it.
  • IC3 is the one route that can sometimes act on the money itself, and only when a loss is reported quickly, so it is worth doing the same day rather than the same month.
  • The largest published analysis of 7726 traffic, covering roughly 1.35 million reports and 530,000 unique messages, found 40.27 percent were actual scams while 36.47 percent were not fraudulent at all, with marketing spam accounting for 35.12 percent.
  • That gap is the real work. Separating a genuine scam from an aggressive marketer is triage, and none of these routes show anyone the result of it.
  • The organization being impersonated is the only recipient with both a reason to care and something it can do, and it is also the hardest one to find an address for.
  • For someone who received the message at work, none of these routes tell their own security team anything, so an attack aimed at their employer stays invisible to the people responsible for it.

Better Approach (Actionable Framework)

  • Report first, then block, then delete. In that order, because blocking first can remove the thread you still need.
  • Send the sender's number when the carrier asks for it. Without it the report cannot be tied to a campaign.
  • Screenshot the message before deleting it if it names your employer, an executive, a payment, or an account you hold.
  • If the message reached you at work, send it to your security team as well, not only to your carrier.
  • Treat any verdict you get back as evidence about risk rather than proof of who sent the message. No one can authenticate a third party's message after the fact.
  • Check on the organization through a number or app you already have, never through a number or link inside the message itself.

Key Takeaways

  • 7726 is the free carrier route, and it needs the sender's number to be worth anything.
  • Blocking is not reporting.
  • The FTC and the impersonated organization both want the report, and both act on volume.
  • Close to six in ten reported messages turn out not to be scams, which is why triage matters more than raw reporting volume.
  • Every free route ends with an acknowledgement rather than an answer, so the person who reported never learns what the message was.

Where SmishAlert Fits

Reporting to a carrier helps the carrier. Reporting to the organization being impersonated is the one route where that organization learns its own customers are being targeted in its name, while the campaign is still running.

SmishAlert gives an organization a reporting route of its own, so a suspicious message reaches the people accountable for it rather than a queue that never reports back.

A report comes back with a plain verdict and the reasoning behind it, rather than an acknowledgement.

On iPhone, messages from unknown senders are screened before anyone taps anything. On every other channel and platform, reporting is one tap on a screenshot or a forward.

Each report is recorded, so a security or fraud team can see when the same campaign is reaching several people at once.

When a message or link is confirmed malicious, the next unknown-sender check on any protected iPhone marks it automatically.

An individual can install SmishAlert on their own iPhone from the App Store and report messages the same way.