Text message short codes, explained
A five-digit number texts you and there is no name attached to it. Here is what those codes are, how to find out who is behind one in about ten seconds, when replying STOP helps and when it does the opposite.
A short code is the five- or six-digit number businesses text from — alerts, delivery updates, two-factor codes, marketing lists. To find out who owns one, text HELP to it: compliant codes must reply with the programme name and a support contact. To leave a legitimate list, text STOP. Do not reply to scam texts from ordinary ten-digit numbers, since a reply only proves your line is live — forward those to 7726 and delete them.
1. What the five- or six-digit number actually is
Short codes exist because carriers wanted a separate lane for business messaging: your bank’s fraud alert, the delivery notification, the two-factor code, the pharmacy reminder, the marketing list you joined at a checkout. In the United States they are leased through the registry iconectiv operates under the CTIA short-code programme, at roughly $500 a month for a randomly assigned code and $1,000 for one a brand picks, starting on a three-month term. That matters to you only as context: a code costs real money to hold and can be pulled by the programme, which is why long-running fraud from a genuine short code is uncommon.
2. Why the sender is often not who you expect
Most companies do not run their own messaging. They hire a provider, and that provider’s code sends on behalf of dozens of brands, so the number you see has no obvious link to the name in the message. The same brand can also use one code for security alerts and another for marketing, and both can change when a contract does. This is why matching a code against a list you found online tells you very little, and why the check below is worth more than any directory.
3. The check that takes ten seconds: text HELP
Every compliant US short code must answer the keyword HELP with the name of the programme and a support contact — a toll-free number or an email address at minimum. That reply is a live answer from whoever is actually running the code, which is more current than any published list. Treat it as a name to verify rather than a verdict: go to the company through your own bookmark, app or the number on your card and confirm the message is real there. Never use a link inside the text to do the checking, because a convincing fake link is the entire product.
4. Getting off a list you are actually on: STOP
For a legitimate programme, one word ends it. Sending STOP — or CANCEL, UNSUBSCRIBE, END, QUIT — obliges the sender to remove you and to send nothing beyond a single confirmation. If messages continue after that, the programme is in breach of the rules it operates under, and the sender’s own support contact plus a complaint to the FCC is the escalation. Keep the confirmation message; it is the evidence that you opted out and when.
5. When STOP is the wrong move
The rules bind real programmes. They do not bind a stranger texting you about an unpaid toll, a stuck parcel, a job offer or a wrong-number message that turns friendly and then talks about crypto. Those usually arrive from an ordinary ten-digit number or an email-to-text address, and replying anything at all — including STOP — confirms a person reads that line, which is worth more to a spammer than the reply costs them. Delete, block, and forward the text to 7726 instead. The same logic runs through the spam-call guide: never engage to make it stop, because engagement is the signal being harvested.
6. Reporting, and what it does
Forwarding a scam text to 7726 hands your carrier the content and the sending number, which feeds the network-level filtering that silences these before they reach anyone. It is threshold-based, so it works in aggregate rather than instantly, and the senders rotate numbers to stay ahead of it. Add a report at reportfraud.ftc.gov when money, card details or an account login were involved, and if you clicked a link and entered anything, treat it as a credential exposure: change that password, change it anywhere you reused it, and check what else is already circulating with our post-breach checklist.
7. Why new senders keep finding you
Opting out one programme at a time is worth doing and never finishes, because the supply is upstream of you. Your mobile number sits on people-search listings, in marketing and lead-generation databases, and in files traded after breaches, and each of those is a fresh source for whoever buys next month’s list. Cutting the source is the part that compounds: our guide to removing your phone number covers where it is published and how to get it taken down, and the data-broker opt-out guide has the free, site-by-site route. Brokers re-list within weeks, so the removal has to be repeated rather than done once.
The three keywords worth remembering
Everything else is a variation on these.
Identifies the code. The reply must name the programme and give a toll-free number or support email. Verify that name through your own bookmark before acting on anything.
Leaves the list. CANCEL, UNSUBSCRIBE, END and QUIT do the same. One confirmation message is allowed; anything after that breaks the rules the programme runs under.
Reports the fakes. Forward the message here and your carrier’s spam team gets the content and the sender. Works in aggregate, so report every one rather than the worst one.
iPhone: Settings → Apps → Messages → Filter Unknown Senders. Android: spam protection in Google Messages. Both move strangers into a separate tab instead of your inbox.
Find out who is publishing your number
Every new list starts with your number being available somewhere. PersProtect checks 499 broker and people-search sites for it, files the removals, and keeps re-checking so the listings do not come back. The scan is free.
See where my number is listed — free →Short codes and spam texts, answered
What is a text message short code?
A short code is the five- or six-digit number some businesses text from instead of a normal phone number: bank alerts, delivery updates, two-factor codes, appointment reminders and marketing lists. In the United States they are leased through the industry registry that iconectiv runs under the CTIA short-code programme, and they cost roughly $500 a month for a random code or $1,000 for a chosen one, on terms of three months and up. That price and the vetting behind it are the reason a code is a mild trust signal: it is expensive to hold and easy to take away.
Why am I getting texts from a 5-digit number I do not recognise?
Usually because a company you actually deal with sends through a code you have never noticed, or because a list you joined was sold on. Sometimes it is a service texting on behalf of a brand, so the name in the message and the owner of the code are different. And sometimes it is not a short code at all: plenty of scam texts arrive from ordinary ten-digit numbers or from email-to-text addresses, which look unfamiliar for the simple reason that nobody has ever used them before.
How do I check whether a short code is legitimate?
Text the word HELP to it. Every compliant US short code has to answer with the programme name and a way to reach support, either a toll-free number or an email address, and the reply itself tells you who is behind the code. Then verify that answer independently: open the company’s site or app from your own bookmark, or call the number on the back of your card, and confirm the message there. What you should not do is tap the link in the text to check, which is exactly the action the fake ones are built around.
Is it safe to reply STOP?
To a genuine short code, yes, and it is the fastest way out. The industry rules require the sender to drop you from the list on STOP, CANCEL, UNSUBSCRIBE, END or QUIT, and to send at most one confirmation afterwards. To an unknown ten-digit number sending obvious scam texts, no: there is nothing obliging them to stop, and a reply tells them a real person reads that line, which raises its value on the next list. Delete, report and block those instead.
Can scammers send texts from a short code?
It happens, but it is not the common case, because leasing a code means paying monthly and passing a review that a fraud campaign rarely survives for long. Two things are far more frequent: a scam sent from an ordinary number or an email gateway that merely looks official, and a real short code that has been quoted inside a fake message so the text appears to come from your bank. Judge the demand rather than the sender — a link asking you to log in, confirm a payment or read back a code is the warning sign whatever number carried it.
What is 7726 for?
It spells SPAM on a keypad, and it is the reporting channel the major US carriers share. Forward the scam text to 7726 and your carrier’s spam team gets the content and the sending number, which feeds network filtering and can get the sender cut off. It works on a threshold, so one report rarely does anything on its own and the numbers rotate quickly. Report to the FTC at reportfraud.ftc.gov as well if money or personal details were involved.
How do I stop spam texts for good?
Opt out of the real programmes with STOP, report the fakes to 7726, and turn on filtering: “Filter Unknown Senders” in iPhone Messages settings, or spam protection in Google Messages on Android. That handles what is already arriving. The reason new senders keep finding you is that your number is published and resold, so the durable fix is the same one that works for spam calls — get the number off the people-search sites and broker databases carrying it, then keep it off.
Is there a public list of every short code and who owns it?
No reliable one. Codes change hands as leases end, the third-party “short code lookup” lists that rank in search are mostly stale copies of each other, and several are people-search sites collecting your details in exchange for an answer. Texting HELP to the code gives you a current answer from the sender itself, which beats any list.
Unsubscribing one list at a time never ends
See which sites are publishing your phone number right now — free, in about a minute.
Run my free exposure scan →