We always read a text message in the wrong order. First the text itself, the promise or the threat it contains, then — sometimes far too late — the line above it: the one telling us who is writing. Yet that line holds almost all the useful information.
Because in France, a message can arrive under at least five different technical identities: a standard mobile number starting with 06 or 07, a geographic number, a four- or five-digit short code, a name written out in letters ("AMELI", "Colissimo", "BANQUE"), or an international number. Each of these formats follows its own rules, costs the sender a different amount, and offers a wildly uneven level of assurance.
Knowing how to tell them apart is no substitute for caution, but it changes everything: it lets you sort in three seconds, before you've even read the body of the message, what is plausible and what is not.

The five faces of an SMS sender
1. The standard mobile number (06 / 07)
This is what a private individual looks like. A genuine French mobile number allocated by ARCEP to an operator, then to a subscriber. You can reply to it, you can call it.
A company or a government body normally has no reason whatsoever to text you from an 06 or 07 for an official notification. When it happens — "Your parcel is on hold, settle the charge here" signed off by an 07 — the sender is either a private individual or, far more often, a fraudster equipped with prepaid SIM cards or an automated sending device (the notorious "SIM boxes").
Remember this simple rule of thumb: an institutional message sent from a personal mobile number is an anomaly, whatever its content.
2. The short code (4 to 5 digits)
Short codes are allocated and regulated in France by ARCEP, as part of the national numbering plan. They fall into broad families recognisable by their prefix:
| Format | Use | Real-world example |
|---|---|---|
| 3xxxx (5 digits) | SMS services, including MAN (Multi-Access Number) | Tracking notifications, alerts |
| 36xxx / 38xxx | SMS Multi-Access Number, including 38028 (Signal Spam / 33700) | Spam reporting |
| 7xxxx / 8xxxx | Premium-rate SMS, games, votes, donations | Donations to a charity |
| 1xx | Emergency and social services (112, 114, 115, 119) | 114: emergency services by SMS for deaf and hard-of-hearing people |
Two short codes are worth committing to memory in France:
- 33700: the reporting service for unwanted texts and calls, operated by French carriers. You forward the fraudulent message to it, then send back the sender's number when asked.
- 114: the emergency number reachable by SMS, intended for people who are deaf, hard of hearing, or otherwise unable to speak.
One important point: short codes are leased from aggregators, not bought outright. The same five digits can therefore be used successively by several advertisers. A short code you've "seen before" is no proof of authenticity — it only indicates that the sender went through a declared professional channel.
3. The alphanumeric sender (a name instead of a number)
This is the most deceptive format, and the one to understand first. When your phone displays "AMELI", "SFR" or "LIVRAISON" at the top of a conversation, it is not showing a verified identity: it is showing a character string supplied by the sender itself in a technical field of the message, known as the sender ID or OADC (Originating Address).
Technically, that field is purely declarative. Nothing in the SMS protocol certifies it. That is what makes sender spoofing possible: impersonating a brand name so that the message appears in the right place.
And that is where the most effective trap in French smishing comes into play: conversation threading. If a fraudulent message uses exactly the same sender ID as a legitimate message received earlier, your messaging app may slot it into the same thread as the organisation's genuine messages. The phishing text then appears right below the real appointment reminder or delivery code. Context does the rest of the work.
A conversation thread authenticates nothing. A fraudulent message can slip into an existing legitimate conversation if it reuses the same sender name.
Since 2023-2024, France has put a countermeasure in place: the MAN registry and the obligation for carriers to filter out alphanumeric sender IDs not declared in a register. The idea is to accept in France only sender names registered by identified companies. The scheme has cut the volume of outright spoofing, but it has not eliminated it: campaigns get around the filter by using international routes, or by registering credible generic names ("INFO-COLIS", "SECURITE") that are not protected trademarks.
4. The geographic number (01 to 05, or 09)
Receiving a text from an 01 or an 09 is no longer unusual: landline numbers have technically been able to carry SMS for several years now. Some medical practices, garages and small businesses use them for appointment reminders, via their management software.
The 09 range deserves particular attention: these "non-geographic" numbers are used massively in IP telephony, making them easy to obtain in bulk and to discard. A great deal of cold marketing — and a share of the fraud — comes through that channel.
5. The international number
A +44, +212, +48 or +1 on a text supposedly from your French bank is a major inconsistency. Smishing campaigns often use cheap international routes precisely because they partly escape national filters.
One nuance, though: some perfectly legitimate foreign services (a booking platform, an American messaging service sending a verification code) do write from an international number. The criterion is not "international = fraud", but "international when the organisation is purely French = fraud".
What your phone doesn't show you
No mainstream operating system displays the full header of a text message. You will not see the identifier of the message centre (SMSC) that routed the message, nor the route it took, nor the real network timestamp. These elements exist — carriers can even work with them, and so can investigators in the event of legal proceedings — but they never make it to your screen.
What you can do, however:
- Long-press the message then display the details: on Android, the "Details" menu sometimes shows the raw sender, the network reception time and the type (SMS, MMS, RCS).
- Check the channel: an RCS message appears with a read receipt and often a verified brand logo (RCS Business Messaging). A message claiming to come from a major brand as a plain SMS, when that same brand usually writes to you over RCS with a logo, should raise a flag.
- Look at the length: a text longer than 160 characters is concatenated. That is not a fraud signal in itself, but automated campaigns often use calibrated, repetitive phrasing.

The three-question test
Before clicking on anything, three questions are enough in the vast majority of cases.
1. Does the sender format match the organisation it claims to be?
A French government body or large company writes from a short code, a declared alphanumeric sender, or over verified RCS. Not from an 07, not from an odd-looking "+33 7", not from a foreign number.
2. Does the message demand urgent action involving a payment or an identity check?
The three winning combinations of fraud in France remain: a small sum to pay (customs charges, parcel redelivery, a fine), an "update" of bank details, and an "account verification" using a code received elsewhere. Urgency is the active ingredient.
3. Does the link point to an official domain?
French public bodies use .gouv.fr domains or well-known brand domains. A shortened link, a compound domain (ameli-remboursement-fr.com), a misleading subdomain (ameli.fr.securite-connexion.net): all of these are disqualifying. It's worth noting that reading a long URL on a six-inch screen is a painful exercise; many readers benefit from using an adjustable phone stand to examine a suspicious message at eye level rather than at arm's length, or simply from viewing the message on a larger screen.
Verifying without clicking: the parallel channel method
The most effective rule against smishing fits in a single sentence: you never verify a message using the message itself.
In practice:
- A text from your bank? Open the banking app, or call the number printed on the back of your card.
- A text from the health insurance service? Log into your Ameli account by typing the address yourself, or use the official app.
- A text from a courier? Take the tracking number and enter it on the courier's website, without going through the link.
- A text from the tax authorities? Go to impots.gouv.fr and your personal account area.
This discipline takes ten extra seconds. It neutralises just about everything, including very polished campaigns.
For households wanting to formalise these habits — particularly with teenagers or relatives who are less comfortable with technology — a few pages of a cybersecurity guide for beginners left near the family computer often achieve more than a long lecture: seeing the mechanisms written down in black and white makes them concrete.
Reporting: what it actually changes
Many readers assume a report vanishes into thin air. In reality, two channels work in France:
- 33700 (unwanted texts, calls and messages), a scheme run by the carriers. You forward the message to 33700, then reply with the sender's number. Heavily reported numbers get blocked, and identified senders can face penalties.
- cybermalveillance.gouv.fr and the THESEE platform for filing an online complaint about internet fraud. Signal Spam rounds out the system on the email side.
ARCEP and the DGCCRF also monitor breaches of marketing rules. And on the personal data front, the CNIL regularly points out that SMS marketing requires explicit prior consent: an unsolicited commercial message you never agreed to is already an irregularity in itself — even if it isn't fraudulent.

Reducing your exposure
Identifying a sender is a defensive skill. You can also play upstream, by limiting the number of dubious messages that reach you in the first place.
Filter on the phone. iOS offers filtering of unknown senders (Settings → Apps → Messages → "Filter Unknown Senders"), which sorts messages from numbers not in your contacts into a separate tab. On Android, Google Messages has spam protection that was significantly strengthened in 2025-2026, with scam pattern detection and link masking in suspicious messages.
Compartmentalise your numbers. Use a secondary number — a second line on a plan, a dedicated eSIM, a number from an online service — for commercial sign-ups, classified ads and deliveries. Your main number stays reserved for family and friends, your bank and government services. A no-commitment prepaid SIM card is more than enough for this role and costs just a few euros.
Secure what protects your accounts. SMS remains the weak link in two-factor authentication, because it depends on a number that can be hijacked. Moving sensitive accounts to an authenticator app, or to a physical FIDO2 security key, strips SMS of its master-key role. That is the single step that makes a successful smishing attack far less costly.
Look after your reading hardware. A mundane but real detail: a good share of accidental taps come from a scratched screen, a wet finger, or reading on the metro. A tempered glass screen protector and a bit of light are enough to cut down on mis-taps.
The special case of political and institutional texts
Spring 2026, during the municipal elections, was a reminder that a perfectly legal text message can be perfectly irritating. Campaign messages sent from alphanumeric senders drew plenty of reactions, and many recipients wondered how their number had been obtained.
Two things to distinguish here:
- A fraudulent text seeks to obtain money or credentials. Report it to 33700 and delete it.
- An unsolicited but lawful or semi-lawful text falls under marketing law. Here the lever is the GDPR: ask the sender where the data came from, exercise your right to object, and refer the matter to the CNIL if refused. The keyword "STOP" remains mandatory in commercial texts — but it has no value, and no benefit, against a fraud campaign, where replying merely confirms that the number is active.
Three seconds, five formats
With practice, reading the sender becomes automatic. A familiar short code: plausible. A brand name in an already existing thread: plausible, but the link still needs checking. An 07 signed off by a government body: bin it. A +48 signed off by a French bank: bin it. An 09 with a shortened link: bin it.
SMS was never designed to prove who is speaking. It was designed, back in 1992, to carry 160 characters through a leftover signalling channel. Thirty-four years later, it carries medical appointments, banking codes and official summonses — without ever having acquired an authentication mechanism worthy of the name. It falls to the recipient to bridge the gap, and that starts with reading the first line before all the others.



