Link Verification Code Text: What It Means and What to Do
A Link verification code text is a one-time passcode sent by Stripe Link, the saved-checkout feature used by thousands of online stores. If you didn’t request it, the most likely explanation is that someone mistyped their own phone number at checkout. The code expires in a few minutes on its own. Never read it out to anyone.
That covers the common case. But “verification code” texts arrive from several different systems, they look almost identical, and one of the scenarios behind them is genuinely serious. This guide explains which service sent yours, how to tell an accident from an attack, and how to stop the messages permanently.

What a verification code actually is
A verification code – also called a one-time passcode or OTP – is a short number, usually four to eight digits, that a service sends to prove you are the person holding the phone. It is the “something you have” half of two-factor authentication. Your password is something you know; the code is something only you should be able to receive.
Three things are true of almost every legitimate verification code:
- It is short-lived. Most expire in 5 to 15 minutes.
- It is single-use. Once entered, it is dead.
- It arrives from a short code – a five- or six-digit sender like 22395, 787473 or 31061 – rather than a normal phone number. Short codes are the bulk-messaging channels that providers such as Twilio and Vonage use to deliver SMS at scale, which is why the same short code can carry messages from dozens of unrelated companies.
That last point is the reason a code can arrive from a number you have never seen and still be entirely genuine.
Why you got a “Link” verification code specifically
Link is Stripe’s one-click checkout. When a shopper saves their card and phone number with Link on any Stripe-powered store, they can check out on every other Stripe store without re-entering card details. To confirm it is really them, Link texts a code to the saved number.
So a Link verification code text means one of two things:

- You have a Link profile and a checkout was started with your number.
- Someone else typed your number by mistake at a checkout screen.
Stripe’s own support documentation points squarely at the second explanation, noting that these texts commonly arrive because “someone else entered their own number incorrectly.” A single transposed digit sends the code to a stranger. It happens constantly, and nothing on your end is compromised when it does – the person who mistyped simply never receives their code and tries again.
The other codes people mistake for Link
Because the wording is so similar across services, it is easy to attribute a code to the wrong company. These are the three that get confused with Link most often.
Shop verification code text
A shop verification code text comes from Shop Pay, Shopify’s equivalent of Link. It behaves the same way: your number is saved for accelerated checkout, and a code confirms the purchase. The mistyped-number problem is at least as common here, partly because browser autofill will happily re-enter a wrong number every time that person shops.
Shop Pay is the one service in this group with a clean, official way out – see the section on stopping the texts below.
Messenger verification code
A Messenger verification code is sent by Meta, and the meaning is different in an important way. Link and Shop Pay codes are about completing a purchase. A Messenger code is about accessing an account – a login, a password reset, or adding your number to a profile.
That distinction matters. An unrequested checkout code is usually a wrong number. An unrequested login code means someone is actively trying to get into an account, and it deserves closer attention.
Codes from 22395, 787473 and similar short codes
These are delivery channels, not companies. The short code 22395, for example, is a shared code carrying messages for many different businesses. Identifying the sender from the number alone is usually impossible – read the message body instead, which almost always names the service.
You didn’t request it. What does that mean?
Here are the three explanations, ordered from most to least likely.
1. Someone mistyped their number (most common by a wide margin)

One code, arriving once, naming a service you don’t use, is almost always a fat-fingered digit at somebody else’s checkout. Nothing was accessed. Nothing is at risk. The code expires and the incident is over.
The tell: it is a checkout or sign-up code, it arrives in isolation, and no follow-up contact occurs.
2. Someone is trying to get into your account
If the code is for a service you do use – especially a login or password-reset code – then somebody has entered your username or phone number on a login screen. They may already have your password and be stuck on the second factor.
The tell: it names an account of yours, or you receive several codes in a short window.
Two-factor authentication is doing its job in this scenario. The code is the wall the attacker cannot climb – as long as you don’t hand it over.
Also check out: Microsoft account security alert Email
3. You are being set up for a verification code scam
This is the dangerous one, and it has a very specific shape. The scammer already holds some of your details. They trigger a real code to your phone. Then they contact you – posing as your bank, a fraud department, a delivery service, a marketplace buyer – and ask you to read the code back to “confirm your identity” or “cancel the request.”
The code is real. The text is real. Only the caller is fake. And the moment you read it out, they complete the login.
The Federal Trade Commission is blunt about this pattern. In its consumer alert on verification codes, the FTC states: “Never give your verification code to someone else. It’s only for you to log into your account.” And more directly still: “Anyone who asks you for your account verification code is a scammer.”
There is no legitimate exception. No real bank, retailer, or support agent will ever ask you to read back a code they just sent you.
What to do right now
- Do nothing with the code. Don’t enter it anywhere. Don’t forward it. Let it expire – that takes care of itself in minutes.
- Don’t tap links in the message. Genuine verification texts rarely contain links. One that does is worth treating as phishing.
- Check the account yourself, the safe way. If the code names a service you use, open a browser and type the address in manually. Never navigate from the text. Once inside, look at recent login activity, active sessions, and whether the recovery email or phone number has been changed.
- If anyone contacts you about the code, stop engaging. The FTC’s advice is unambiguous: “don’t engage. Hang up. Block their number. Stop texting them.” Then call your bank or the service using the number printed on your card or statement – never a number the caller supplies.
- Change the password if the code was for a real account of yours, and turn on an authenticator app instead of SMS where the service supports it.
- Report it. Verification code scams can be reported to the FTC at ReportFraud.ftc.gov.
How to stop the texts for good
If codes keep arriving for a service you have never used, the fix is to remove your number from that service’s system.
Stripe Link
Deleting the Link profile attached to your number stops the checkout codes. Stripe lets you remove saved payment information and delete the account itself through Link’s support pages. Note that changing the phone number on a Link account resets it and clears the data saved against the old number.
Shop Pay

Shopify runs a dedicated opt-out form. Submit your number – with the country code – at shop.app/pay/phone-optout and your number and stored data are removed from Shop Pay, which ends the codes. Opting out of Shop Pay does not close a Shop account or stop you shopping on Shopify stores; it only removes the accelerated-checkout payment method. Shopify documents the process in its Shop Help Center.
Everything else
Replying STOP to a short code halts marketing messages from that sender, though transactional security codes may continue. Where a service offers it, switching from SMS codes to an authenticator app removes the phone number from the equation entirely – and is more secure regardless.
When to treat this as an emergency

Escalate immediately if any of the following apply:
- A burst of codes – several within minutes, or from multiple services at once. That is an active, automated attempt against your accounts.
- Someone contacts you asking for the code. Confirmed scam, every time.
- Your phone loses signal unexpectedly and stays dead while codes are in play. This can indicate a SIM swap, where an attacker has ported your number to their own device to intercept codes. Contact your carrier from another phone straight away.
- A password-reset or account-change confirmation you didn’t initiate lands in your email.
In those cases, change the password on the affected account from a device you trust, revoke active sessions, and contact the provider directly.
Frequently asked questions
Is a link verification code text a scam?
The text itself is almost always genuine – sent by Stripe Link because a checkout used your number. It only becomes a scam when someone contacts you and asks you to share the code. The message is safe to ignore; a request for the code never is.
What happens if I ignore a verification code?
Nothing. The code expires within a few minutes and cannot be used afterwards. Ignoring an unrequested code is the correct response.
Why do I keep getting verification codes I didn’t ask for?
Repeated codes from the same service usually mean someone has saved your number in their account or their browser autofills it at checkout. Use that service’s opt-out to remove your number. Repeated codes from different services in a short window is a different problem – treat that as an attempted account takeover.
Can someone hack my account with just the code they sent to my phone?
Only if you give it to them. The code alone is useless without your password, and it is delivered to your device, not theirs. Handing it over is the only way it becomes dangerous – which is exactly why scammers ask for it.
Should I reply STOP to a verification code text?
For marketing messages, yes. For security codes, STOP often won’t stop them, because they are transactional rather than promotional. Use the service’s opt-out form instead – Shop Pay and Link both have one.
The short version
A verification code you didn’t request is usually somebody else’s typo, occasionally a failed break-in, and rarely the opening move of a scam. You can tell them apart by asking two questions: does it name a service I actually use? and is anyone asking me for it?
If nobody is asking, ignore it and let it expire. If somebody is asking – no matter how convincing, no matter who they claim to be – that is the scam, and the answer is always no.
Is a freelance tech writer based in the East Continent, is quite fascinated by modern-day gadgets, smartphones, and all the hype and buzz about modern technology on the Internet. Besides this a part-time photographer and love to travel and explore. Follow me on. Twitter, Facebook Or Simply Contact Here. Or Email: info@axeetech.com
