Skip to main content
Back to blog

What phishing is and how it reaches SMS, email, and voice

A working definition of phishing across SMS, email, and voice: how it differs from SMS pumping and caller-ID spoofing, and what to check before acting on a suspicious message.

Orbit Editorial Team

Phishing is the practice of sending a fraudulent message that impersonates a trusted brand or person in order to steal credentials, payment details, or personal data. This post defines the term across SMS, email, and voice, and separates it from adjacent fraud categories like SMS pumping and caller-ID spoofing.

The definition

A phishing message has two components: a false identity claim (the sender pretends to be a bank, a delivery service, a platform administrator, or a colleague) and a payload (a link, an attachment, or a request that extracts something valuable from the recipient). The channel varies. The social-engineering pattern does not.

How phishing arrives by channel

Email remains the highest-volume phishing channel. Attackers register look-alike domains, spoof display names, or compromise legitimate sending accounts. SPF, DKIM, and DMARC records determine whether a receiving server can verify the sender's domain, which is why domain authentication is the baseline email defense. Orbit covers deliverability and sender identity setup in Email deliverability and Transactional email deliverability and sending identities.

SMS phishing, usually called smishing, uses short links and urgency framing: a failed delivery, a locked account, a toll charge. Because SMS has no link preview by default, recipients often tap before they can evaluate the destination. Orbit's SMS gray routes and SIM pumping explainer covers the messaging-abuse side of the SMS ecosystem.

Voice phishing, or vishing, uses a live caller or a spoofed number to extract information verbally. Attestation frameworks such as STIR/SHAKEN give receiving carriers a signal about whether the calling number was legitimately originated; see STIR/SHAKEN attestation for outbound voice.

Phishing versus adjacent fraud categories

Teams classifying fraud traffic should separate phishing from two categories that look similar in a message log. SMS pumping inflates traffic to artificially generated numbers for revenue-share or OTP-abuse profit; the victim is the sending platform, not the end recipient. Orbit's SMS pumping fraud explainer and the Verify API OTP fraud monitoring post cover that pattern. Caller-ID spoofing is a delivery technique that phishing campaigns often use, but spoofing alone does not make a message phishing; the defining property is the fraudulent impersonation and extraction attempt.

What to check before you click or reply

  1. Verify the sender domain or number through an independent channel, not the contact details inside the message.
  2. Treat urgency and secrecy as signals, not instructions.
  3. For businesses: authenticate your own sending domains (SPF, DKIM, DMARC) so attackers cannot convincingly impersonate you to your customers.
  4. Report suspected phishing to your security team or national reporting portal rather than deleting it.

Where this fits in Orbit's fraud coverage

This definition page fills a gap in Orbit's glossary, where phishing previously appeared only inside the DMARC term. It sits alongside the existing explainers on SMS pumping fraud, gray routes, and voice attestation so readers and AI answer engines can resolve the term to a single canonical page.

What phishing is and how it reaches SMS, email, and voice — Orbit by Devotel