What To Do After a Scam

I Replied to a Scam Email — What Should I Do?

Replying to a scam email is not a disaster, but it does mark you as a live target. Here is how to shut the conversation down and protect what matters.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Stop replying immediately — do not send a final message, an insult, or an 'unsubscribe'. Block the sender and mark the thread as phishing so your provider filters similar messages. If your reply contained personal details such as your full name, address, date of birth, workplace, or account numbers, treat that information as public: change relevant passwords, add two-factor authentication, and consider a credit freeze. If you sent money or card details, contact your bank today. Expect more attempts, including a second scammer offering to recover your money.

Warning signs to look for

  • The sender replied within minutes and became friendly or urgent very quickly
  • You were asked to continue the conversation on WhatsApp, Telegram, or by text
  • You were asked for a photo of your ID, a card, or a document
  • You were asked to buy gift cards, send cryptocurrency, or accept a package
  • A different person now claims they can recover money you lost

What your reply actually told them

Most scam campaigns go out to millions of addresses, and the first job of the message is simply to find people who respond. Your reply confirmed three things: the address is real, a human reads it, and that human engages. That is why replies are usually followed by a rapid escalation in attention — more messages, a phone call, or a switch to a chat app where there are fewer safeguards. It does not, by itself, give anyone access to your accounts or money.

Stop the conversation the right way

Do not send a closing message. Every further reply, including angry ones, confirms engagement. Instead, block the sender, then use your email app's 'Report phishing' or 'Report junk' option rather than plain delete, so the provider learns from it. If the conversation moved to a phone number or messaging app, block it there too. If you are receiving calls, let unknown numbers go to voicemail for a few weeks; the pressure usually fades once you become unresponsive.

Take stock of what you shared

Write down exactly what was in your replies. Name and email alone is minor. Home address, date of birth, employer, or family details raise the risk of a convincing follow-up impersonation. Account numbers, card details, a copy of your ID, or a password require immediate action: change passwords for the affected services from a trusted device, enable two-factor authentication, and call your bank for anything financial. In the United States, IdentityTheft.gov will build a step-by-step recovery plan around the specific items that were exposed.

Watch for the second wave

People who engage once are added to lists that are resold. The follow-ups are often better tailored: a fake bank fraud department that already knows your name, a 'refund' for a service you never bought, or a recovery agent promising to retrieve lost money for an upfront fee. Treat every unexpected message about the original scam as part of the same scam, and verify anything that matters by contacting the organisation yourself.

Reduce the follow-up volume

Adding a filter that sends messages from the sender's domain straight to spam helps. So does turning off automatic loading of remote images, which stops senders from confirming that a message was opened. If the volume becomes unmanageable, some people move important correspondence to a fresh address and retire the old one gradually. Do not close an email account you use for account recovery without first updating those recovery settings.

Report it

Report the exchange to the FTC at reportfraud.ftc.gov and, if money was involved or attempted, to the FBI's Internet Crime Complaint Center at ic3.gov. Forward the original message to reportphishing@apwg.org. Reports rarely recover money on their own, but they feed the investigations and takedowns that shorten a campaign's life.

Before you reply to anything like it again

If a message ever seems plausible enough that you are drafting a reply, that is the moment to have it checked instead. Forward the original to check@spamcheck.com and you will get a plain-English answer about what the sender is really doing — usually well before any deadline the message claims.

Frequently asked questions

Can a scammer hack me just because I replied?
No. A reply does not give anyone access to your device or accounts. The damage from replying is that it confirms you are a responsive target, and that anything you wrote is now in their hands.
Should I tell them I know it is a scam?
No. Any response, including a hostile one, marks the address as active and often increases the volume of attempts. Block and report instead.
I sent them my phone number. How bad is that?
Expect scam calls and texts. Do not answer unknown numbers, never share verification codes with a caller, and ask your mobile provider about adding a port-out PIN to protect against SIM-swap attempts.
They say they will publish embarrassing material unless I pay. What now?
Do not pay and do not reply. These sextortion-style threats are sent in bulk and the claimed material almost never exists. Keep the message, report it to the FBI at ic3.gov, and block the sender.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides