A text or email says your lost iPhone has been found. It includes a link to a page that looks exactly like Apple's login screen. That page is fake. If you enter your Apple ID password there, scammers steal it and use it to remove Activation Lock on your phone. Apple does not send texts asking you to sign in to see a found device. The only safe way to check is to open the Find My app or type icloud.com yourself. This post walks you through the warning signs so you never fall for the trick.

Why Scammers Fake Found IPhone Messages

When you lose an iPhone, Activation Lock makes the phone worthless to anyone else unless they can remove it by signing into the owner's Apple ID. Scammers know this. They send fake messages claiming your lost iPhone has been found, hoping you will tap the link and enter your Apple ID password. Once they have your password and any verification codes you provide, they can disable Activation Lock and resell the phone. The message plays on your hope of getting your device back. Recognizing the pattern stops the scam before it starts.

Red Flags in the Message Itself

Scam messages often have small but telling clues. Look for these signs before tapping anything:

  • Sender address: Apple sends account related messages from apple.com or icloud.com addresses. A sender like [email protected] or [email protected] is a red flag.
  • Urgency and emotion: Phrasing like 'Your iPhone was just located' or 'Tap now to claim it before the finder resets it' is designed to rush you.
  • Generic greetings: A real message from Apple would use your name. Scammers often start with 'Dear Customer' or 'Apple User'.
  • Mismatched branding: Logos may be slightly blurry, colors off, or the Apple symbol distorted.

If any of these stand out, do not tap the link.

How to Check the Link Without Tapping

Scammers rely on you tapping without looking. The link in the message will not go to apple.com or icloud.com. Instead it will use a lookalike domain with spellings that are easy to miss in a quick glance. Common tricks include:

  • app1e.com (number one instead of letter l)
  • appIe.com (uppercase i instead of l)
  • icloud-security.com
  • apple-id-verify.net

On a phone you can long press the link to preview the real URL. On a computer hover over it without clicking. If the domain is anything other than apple.com or icloud.com, it is a phishing attempt. You can also paste the suspicious link into a phishing URL checker to have it analyzed automatically. A reliable tool like the free phishing URL checker from scan.now will flag lookalike domains, hidden redirects, and other phishing indicators without requiring you to sign up or pay.

What Apple Actually Does If Your Phone is Found

Apple's Find My network can show the location of a lost iPhone, but Apple does not send you a text or email with a link to sign in and see it. To check a reported location you must open the Find My app on another Apple device or log in at icloud.com by typing the address yourself. Apple also does not ask for your password or verification codes through a text message. If someone finds your phone and reports it through their device, Apple may send you a notification, but it will never contain a clickable link that leads to a login page. The only safe way to proceed is to go directly to the official service.

What to Do If You Already Entered Your Password

If you typed your Apple ID password into a page that came from a suspicious message, act immediately. Change your Apple ID password right away. Use a device you trust and go to apple.com or icloud.com directly. Turn on two factor authentication if it is not already active. Also check your Apple account for any unknown devices or recent changes. If scammers have your password and you gave them a verification code, they may already be inside your account. Changing the password locks them out. Never share your Apple ID password or verification codes with anyone, including anyone who contacts you claiming to be from Apple support.

Additional Steps to Secure Your Account

After changing your password, review your trusted phone numbers and recovery email addresses in your Apple ID settings. Remove any you do not recognize. If you use the same password anywhere else, change those accounts too. Consider running a full scan on your computer or phone for keyloggers or malware that could steal future passwords.

Using Free Scanners to Stay Safe

Beyond checking suspicious messages yourself, you can use free tools to analyze links and files without risk. scan.now offers several passive scanners that require no account. The phishing URL checker evaluates links for lookalike domains and hidden redirects, which is exactly what you need when a message looks questionable. There is also a file scanner that checks documents and archives for malware, and a security headers check that can tell you if a website is using proper protections like CSP and HSTS. Each scan result comes with an explanation of what was found and what it means. You do not need to sign up or pay for any of the scans. Bookmark the site and use it as a first step whenever a message, email, or link makes you wonder if it is real.