You pick up your phone and there’s a text with a verification code from something called “Link.” Or an email lands in your inbox asking you to confirm your identity for a Link account you’re sure you never created. It feels odd, maybe a little unsettling, and for a lot of people the first thought is the same: is someone trying to scam me?
Take a breath, because in most cases this is normal and harmless, and there’s a plain explanation behind it. Link is a digital wallet built by Stripe, one of the biggest payment companies on the internet, and it uses short codes sent by email or text as a security check. The confusing part is that you can end up with a Link profile tied to your details without ever feeling like you signed up for anything. This article explains why these messages appear, how to tell a genuine one from a fake, what to do the moment one arrives, and how to switch them off for good if that’s what you want.
The short answer, before anything else
If you received an email or SMS from Link and you don’t believe you have an account, it nearly always comes down to one of three reasons:
- You used Link at least once before, even during a single online purchase, and a site or device is now remembering you.
- Someone typed your phone number or email by mistake at checkout, so their code was delivered to you instead of them.
- It’s a phishing attempt, where a scammer sends a fake code hoping you’ll hand over access.
The code by itself isn’t the threat. A verification code only proves that the person using Link controls a particular email address or phone number. It turns into a problem in one situation only: when you share it with someone else or type it into a fake website. Hold on to that single idea and everything below falls into place.
What Link actually is, and why it may already have your details
Link is Stripe’s one-click checkout wallet. It lets you save a card, a US bank account, or a “buy now, pay later” option one time, then reuse those saved details at any of the hundreds of thousands of online stores that process payments through Stripe. Rather than retyping your card number, billing address, and contact details on every site, Link fills them in automatically. It runs on the web and through apps on iOS and Android, and a large share of purchases on Stripe-powered sites now flow through it.
Here’s the part that trips people up. You don’t have to go to a website and deliberately “open a Link account.” When you check out on a store that uses Stripe and enter your email and phone number, Link can attach your saved payment details to those contacts in the background. The next time you visit any other Stripe-powered site, it may recognise you and offer to check you out in one click. So when someone insists “I don’t have a Link account,” the more accurate version is usually “I don’t remember ever creating one.” Both statements can be true at once, and that’s exactly why the whole thing feels mysterious.
It also explains the timing. A purchase you made months ago on a completely unrelated website can be the reason a code turns up on your phone today. Nothing new has to happen on your end for an old, half-forgotten checkout to trigger a fresh verification message.
Why Link sends a code in the first place
The entire purpose of the code is to confirm identity. Whenever Link is used on a new device, a different browser, or a site it hasn’t seen before, it sends a one-time passcode to the email address or phone number on file. On phones that support it, it can also lean on Face ID or a fingerprint. Only once that check passes will it autofill the saved payment information.
This is ordinary, sensible security, and you’ve almost certainly seen it elsewhere. It’s the same approach your bank or email provider uses when they text a code before letting you sign in from an unfamiliar location. The code proves that whoever is trying to pay genuinely controls the contact details attached to the wallet. Delivered to the right person, it’s a tiny speed bump that protects saved cards from misuse. Delivered to the wrong person — you — it’s confusing, but it stays harmless as long as the code never leaves your hands.
There’s a useful takeaway hiding in this. The code is designed to slow down a stranger, not to help one. Anyone asking you to speed it along to them is working against the very thing it was built to do.
The most common reasons the message reached you
You’ve used Link before, perhaps without noticing
This is the single most likely explanation. If you ever paid through Link, even one time, your email and number are on file, and some device may still be signed in or “remembered.” Link’s own help guidance points to this directly: an unexpected text often means you’re being remembered on another device where you used Link in the past.
Two simple actions clear it up. First, you can log out of Link on all devices, which wipes those remembered sessions so they stop firing off codes. Second, you can review your own record. Signing in to your Link activity page shows the past purchases made through Link, and seeing them listed often jogs the memory about where the profile came from in the first place — a concert ticket, a clothing order, or a one-off subscription you’d long forgotten.
Someone entered your number or email by mistake
People mistype phone numbers constantly. If a stranger enters their own number wrong at checkout and the digits land on yours, Link sends the verification code straight to your phone. You end up holding a code for a purchase you know nothing about, made by a person you’ve never met.
Treat this as a simple wrong number. It isn’t an attack, and there’s nothing on your own accounts that needs fixing. You don’t have to do anything except leave it alone. The other person will just request a fresh code once they notice their mistake and type the correct number. The only genuinely bad move here would be replying with the code, which is something you should never do for any reason.
It’s a phishing or “smishing” attempt
The reason to keep a little awareness is this third possibility. Scammers understand that codes from payment services look official and time-sensitive, so they send fake ones on purpose. SMS-based phishing is common enough to have earned its own name: smishing. A message might copy Link or Stripe branding, carry a link to a lookalike website, or be paired with a follow-up call or text from someone urging you to read the code aloud. This is the scenario where staying alert pays off, so it’s worth learning the tell-tale signs.
How to tell a real Link message from a fake one
The cleanest test is a single question: did you start the action? A genuine code shows up at the exact moment you are signing in, making a payment, or setting up Link on a new device — an action you kicked off yourself. You then enter that code on a page you opened on your own. That’s the code doing precisely what it was built to do.
A message deserves suspicion when the sequence runs the other way. If a code appears from nowhere and then someone messages, calls, or emails asking you to read it, forward it, or “confirm” it, stop right there. No legitimate company will ever ask you to share a code it just sent you. A real link verification code text is meant only for you to type in yourself, and it typically expires within a few minutes, which means it’s worthless to anyone except the person who triggered the login.
Several other warning signs tend to cluster on fake messages. Look out for web addresses with strange spelling, extra words, or odd characters; pressure to act this instant; a claim that an “unauthorised payment” has been found that you must cancel; a page missing the padlock or https that marks a secure connection; or a checkout screen that simply doesn’t match a brand’s usual look.
It also helps to recognise the scripts scammers reuse. One pretends to be Link, Stripe, or your bank, claims a suspicious charge was spotted, and asks for your code to “cancel” it. Another comes from a fake buyer or seller on a marketplace who says they need a code to prove you’re a real person. A third is the friendly-sounding “so sorry, I entered your number by accident — could you forward me that code?” Every one of them ends the same way: the moment you share the code, they’re in. Because these tricks shift and rebrand over time, it’s worth keeping half an eye on General News about the latest smishing campaigns making the rounds, so a new twist doesn’t catch you off guard.
What to do the moment a code arrives
If you started whatever the code is for, there’s nothing to worry about — just enter it on the page you already have open and carry on.
If you didn’t start anything, the safest response is to do nothing at all. Don’t reply, don’t tap any link, and don’t type the code anywhere. Replying, even with something as innocent as “wrong number,” signals to a scammer that your number is active and can invite more messages. In most cases, deleting the text and moving on is the right call.
If the codes keep coming, add a few steps. Log out of Link on every device to clear the remembered sessions. Check your Link activity to see whether any real purchases are tied to your details. If you find a saved profile you don’t want, you can remove it, which the next sections cover. And if you receive a code you truly didn’t request more than once, treat it as a possible hint that someone holds part of your login information and is testing it — change the password on the related account and switch on two-factor authentication, ideally through an authenticator app rather than text messages.
There’s also value in reporting. In the United States you can forward junk or scam texts to 7726, which spells “SPAM,” so your mobile carrier can look into the sender. If any money changed hands or you shared something sensitive, contact your bank right away and file a report with the FTC at reportfraud.ftc.gov. Reports like these feel small, but when many people flag the same number or web address, carriers and investigators can shut it down faster.
What Link stores about you, and what it doesn’t
Link keeps the things it needs to fill in a checkout: the card or bank account you saved, your billing and shipping address, your email, and your phone number. It does not hand your full card number to the stores you buy from — that’s the tokenisation covered further down — and it doesn’t need your online banking password to charge a saved card. If you connected a US bank account, that connection is permission-based, which means the business receives a secure token rather than your actual login details.
Knowing what’s on file makes the clean-up choices easier. If the only thing bothering you is the texts, opting out of SMS is enough. If you’d rather nothing at all be stored, deleting the saved information is the fuller option. It’s also worth remembering that by giving any service your phone number, you’re generally agreeing to receive security texts, receipts, and account notices, so tidying up old accounts you no longer use is a sensible habit that reaches well beyond Link.
How to stop the messages or remove your information
If you’d rather not deal with Link at all, you have a handful of clear options.
Log out everywhere. On the Link website you can sign in and log out of all devices, which ends the “remembered” sessions responsible for surprise codes.
Delete your saved information. If you don’t want any payment details stored, you can delete the Link account tied to your email. Link’s official support site has a dedicated page for removing saved payment information; you enter your email address and follow the steps it lays out.
Opt out of SMS. You can opt your phone number out of Link text messages through Link’s support pages, and replying STOP to a Link text also stops them. One trade-off is worth knowing up front: once you opt out, you won’t be able to use Link’s one-click checkout anymore, because the code is exactly how it confirms it’s you. Replying HELP to a text gets you assistance if you’re stuck.
None of this calls for technical skill. It mostly comes down to proving you own the email address or phone number, then deciding what, if anything, you want kept on file.
Is Link itself safe to use?
For the core payment system, the answer is yes. When you pay with Link, the store never sees your real card number — Link swaps it for a token, so even a merchant data breach can’t expose your actual card. Stripe, the company behind Link, holds PCI DSS Service Provider Level 1 certification, the strictest tier in the card industry, alongside other recognised security standards. The identity code you receive is part of that protection, not a weakness in it.
The honest risk with Link, as with almost any payment tool, isn’t the technology — it’s the phishing that swarms around it. Fake texts, copycat websites, and smooth-talking messages are all designed to coax your code out of you. The system can be genuinely strong and you can still be caught out if someone convinces you to give away access. That’s why one plain habit — never sharing a code with anyone — protects you more than any single setting ever will.
If you like straightforward, no-jargon explainers like this one, Toolsimpli tackles a lot of everyday “wait, is this a scam?” questions in the same simple style, which can save you a second-guessing spiral the next time a strange message pops up.
When to relax, and when to look closer
A single unexpected code that you never acted on is almost always nothing — a mistyped number or an old, forgotten checkout coming back around. You can delete it and get on with your day without a second thought.
Look a little closer if the pattern changes. Repeated codes you didn’t trigger, a code that lands right as someone is pressuring you to act, or codes arriving alongside login alerts from your other accounts can all point to someone already knowing part of your details and probing to see what works. In that case, resetting your passwords and turning on stronger two-factor protection is time well spent, and it usually takes under an hour to sort out across your most important accounts — email, banking, and your main social profiles first.
Most people who get one of these messages sit firmly in the calm category. An email or text from Link almost always means one ordinary thing: you used it before, someone mistyped a number, or a scammer is casting a wide net and hoping you’ll bite. Working out which one you’re dealing with takes only a moment, and the rule that keeps you safe in every version of the story never changes — the code is yours, and it stays with you.
Frequently Asked Questions
Does getting a Link code mean my account was hacked?
Usually not. Most codes come from an old checkout being remembered or someone mistyping their number. It only hints at trouble if you keep getting codes you didn’t request, which can mean someone is trying to log in — a good moment to change your password.
Is it safe to ignore a Link code I didn’t ask for?
Yes. If you didn’t start a login or payment, ignoring it is the safest choice. Don’t reply, click links, or share the code. The other person can simply request a new one with the correct number.
Can someone steal money using my Link code?
Not on its own. The code is useless unless you hand it over or type it into a fake site. Never share it, and never enter it anywhere you didn’t navigate to yourself.
How do I stop Link texts for good?
Reply STOP to the message, opt your number out on Link’s support pages, or delete the Link account tied to your email. Keep in mind that opting out also disables one-click checkout with Link.
Why did I get a Link code if I’ve never knowingly used Stripe?
You may have paid through a Stripe-powered store without realising Link saved your details, or someone entered your number by mistake. Both are common, and neither means you did anything wrong.