Is a text saying I have an unread voicemail and to click a link a scam?
Yes. Texts with voicemail notification links are a widespread phishing method — the link leads to a credential-stealing page or malware download.
Last reviewed: 1 August 2026
Explanation
Fake voicemail notification SMS messages are a well-documented phishing method called 'smishing'. The message mimics notifications from network carriers, Google Voice, or iPhone voicemail. The link does not play a voicemail — it opens a page that imitates a login screen to steal your Apple ID, Google account, or mobile carrier credentials. On Android, some variants attempt to install malware disguised as a voicemail app. Genuine voicemail notifications from your carrier do not require you to log in via a link in an SMS; you access them through your phone's built-in dialler.
The lure works because voicemail sits at an odd intersection: rarely used, vaguely official, and just plausible enough that a 'missed message' triggers curiosity. The linked pages adapt to their audience — showing an Apple-styled login to iPhones and a Google one to Android devices — and the malware variants ask for permissions that let them read your messages, including the one-time codes that protect your bank.
If an app was installed from one of these links, act on the assumption it can see your SMS: remove it, run a security scan, and change important passwords from a different device. On any device, credentials entered on the fake page should be changed immediately and reused versions of that password retired everywhere.
Common red flags
- SMS voicemail notification from an unknown sender or short code
- Link domain does not match your carrier's official domain
- Page asks for account login after clicking
- Device prompts you to install an app to hear the voicemail
What to do now
- Do not click the link — delete the message
- Access voicemail through your phone's dialler or official carrier app
- If you clicked and entered credentials, change passwords immediately
- Report smishing to your carrier by forwarding to 7726 (UK/US)
Frequently asked questions
Can clicking the link without entering anything cause harm?
On some devices, visiting a malicious URL can trigger automatic downloads, especially on older Android versions. Avoid clicking even to 'just look'.
I installed the 'voicemail app' it offered. How serious is that?
Serious — these apps typically request SMS access, which exposes your two-factor codes. Delete the app, run a reputable security scan, change key passwords from another device, and watch your accounts for unauthorised logins.