Real Verification Badge vs Badge Phishing
How to tell a genuine platform verification notification from a phishing attempt that uses the badge as bait to steal your account credentials.
Last reviewed: 1 June 2026
Verification badges are a normal part of social platforms, and the genuine process is unremarkable: you apply from inside your account settings, the platform reviews it, and the answer appears in your own notifications when you next log in. Badge phishing works because the badge carries status, and because the message arrives at a moment when it feels earned. Your following has grown, or your account has been oddly quiet, and then a message says you qualify, or that your badge is approved and only needs confirming. The sender name is nearly right, and the page it opens looks exactly like the login screen you know. The distinction that matters is where the request lives: real verification never begins in a direct message, an email link or an outside login page.
Side-by-side comparison
| Real verification badge | Badge phishing | |
|---|---|---|
| Origin | Notification appears inside the platform's own notification centre — not via DM or email | Arrives as an unsolicited DM, email, or message from an account that mimics the platform |
| Action required | Directs you to your existing account settings to complete verification | Provides a link to an external site that asks for your username and password |
| Eligibility contact | You applied for verification; the platform contacts you after review | Message arrives unsolicited, claiming your account 'qualifies' |
| Fee | Official verification processes through platforms are free or a disclosed subscription | Charges a fee to 'process' your badge application |
| Link destination | URL matches the platform's own domain exactly | Link leads to a lookalike domain (e.g. twitter-verified.com instead of twitter.com) |
Common red flags
- Unsolicited DM or email offering or approving a verification badge
- External link that asks for your platform username and password
- Fee required to 'process' your badge
- Sender account has a similar but not identical name to the platform
- Message creates urgency ('badge expires in 24 hours')
Verification steps
- Log into the platform directly and check your notifications — not via any link in the message
- Check the platform's official verification programme page for the real process
- Report the message as phishing using the platform's built-in reporting tool
- Enable two-factor authentication on your account immediately
What not to do
- Don't enter your credentials on any page reached through an unsolicited verification link
- Don't pay any fee in connection with a platform verification badge
- Don't click links from accounts impersonating platform support
A safe response
Do not tap the link. Open the app or type the platform's address yourself, check your own notifications and settings, and see whether anything is genuinely pending. Report the message using the platform's reporting tool and block the sender. You owe them no reply at all. If you already entered your details, change that password immediately from a device you trust, turn on two-factor authentication, then review the account's active sessions and connected apps and remove anything you do not recognise. Change the password anywhere else you used the same one. If you have lost access, use only the platform's own recovery page, never a paid recovery service.
Frequently asked questions
I entered my password on the page before realising. What do I do first?
Change that password now from a device you trust, then enable two-factor authentication so a stolen password alone is not enough. Next, sign out all other sessions, review connected apps and remove unfamiliar ones, and check that the recovery email and phone number on the account are still yours, since attackers change these first. Change the same password anywhere else you used it. Warn contacts if messages may have been sent from your account.
Does paying for a subscription badge make me more of a target?
A visible badge and a larger audience do tend to attract more impersonation and phishing attempts, because the account is worth more to an attacker and because badge-related messages feel plausible to you. The protection is the same either way: two-factor authentication using an app or hardware key rather than SMS, a recovery email that is itself well protected, and a firm habit of never following account or billing links from messages.
Do platforms ever contact you about verification via DM?
No legitimate platform will send unsolicited verification offers through direct messages or personal email. All genuine verification processes begin in your account settings or through a formal application page on the platform itself.