CHAPTER 3 · FOUNDATIONS
How to Tell If Something Is a Scam: The S.T.O.P. Method
Most advice on this exact question is a list of things to look for: urgency, requests for gift cards, unfamiliar links. Useful, but a list only works if you remember the right item at the right moment. What actually holds up under real pressure is a fixed sequence you run the same way every time, regardless of which warning sign is or isn’t present.
The Four Steps
- Sense the pressure. Naming the feeling (urgency, fear, excitement) is often the first real signal, before you’ve consciously spotted anything specific.
- Trace the request back to what’s actually being asked for, stripped of the story around it: money, access, or information.
- Odd request check: would this specific ask, from this specific channel, make sense if you removed the urgency entirely?
- Prove it independently, through a contact method you already had, never one provided in the message itself.
Why a Method Beats a List
A list requires you to recognize the specific disguise. A method works regardless of the disguise, because it doesn’t depend on the story being familiar, only on running the same four steps every time. That’s the actual, practical difference between information and a system.
Common Questions
What if I genuinely don’t have time to run through four steps?
In practice, all four steps take seconds once they’re habitual, and “I don’t have time to check” is itself one of the pressure signals the Sense step is built to catch. A legitimate request can almost always wait the length of one verification call.
Does this method work for scams delivered by AI voice cloning or deepfakes?
Yes, and that’s precisely why the Prove step never depends on how convincing the voice or video looked. Independent verification defeats a cloned voice exactly the same way it defeats a spoofed number, since it never relies on judging the message itself.
Try it against your own two weakest habits →