Who texted me from that number?
A five or six digit sender is a short code, leased by an organisation to send texts at scale. Some belong to your bank. Some belong to nobody. Here is what we know about the ones people ask about.
21581 is Credence Resource Management’s real debt-collection short code. Expect Credence’s name, a placed-account message, and HELP showing 855-880-4791.
Look it up →28581 is a real Cash App short code for sign-in codes and security alerts. Links, callback numbers, or anyone asking for the code signal fraud.
Look it up →31354 is Fabletics, used for VIP sale, order, and membership texts. Fakes swap in lookalike checkout links or bogus $89.95 credit claims and fee lures.
Look it up →41593 is leased by ITR at irsissues.org, not the IRS. IRS texts use 91040 or 34381, so refund or lien threats need checking.
Look it up →49388 is Synchrony Financial's short code for account texts, passcodes, fraud alerts, and payment reminders. Spoofs relay OTPs or use fake domains.
Look it up →53849 is Bank of America's legitimate Zelle notification code. Real texts are narrow confirmations, with STOP or HELP, not login links or reversal steps.
Look it up →58189 is a legitimate Zelle short code for payment and enrollment texts. Fraud texts copy it, then push replies, fake links, or spoofed bank calls.
Look it up →64013 is Qmatic’s queue and appointment short code. Real texts carry a ticket, place in line, check-in, or Mobile Ticket by Text context, not login alarms.
Look it up →86006 is Bank of America's real fraud and claims alert code for checking and money market accounts. Real texts ask YES/NO, not login details.
Look it up →90831 is a real U.S. Bank short code for ReliaCard and Focus Card balance, transaction and help texts. Frozen-account links are the scam pattern.
Look it up →Checking a text, not a number?
The scam library breaks down the messages themselves, by brand and by channel.
Open the scam library