Why Bad Grammar Doesn't Give Scam Messages Away

Sep 07, 2025By Jay Kells
Jay Kells

Why Bad Grammar Doesn't Give Scam Messages Away Anymore

For years I had one rule of thumb that rarely let me down. If a message was full of clumsy grammar, strange phrasing, or a greeting like "Dear Valued Customer" from a company that supposedly had my name on file, I binned it without a second thought. Bad writing was practically a watermark for a scam. I passed that advice on to family members too, telling them the typos were the giveaway, the thing that would always save them if nothing else did.


I don't give that advice anymore, because it stopped being reliable somewhere in the last couple of years, and I think a lot of people are still relying on a rule that quietly stopped working.


What Changed Once Scammers Started Using AI Properly


The shift is simple enough once you say it out loud. Writing convincing English used to be the hard part of running a scam at scale, especially for operations working from scripts translated badly from another language. AI writing tools removed that bottleneck almost overnight. A scammer with no particular skill in English can now generate a message that reads as smoothly as anything a legitimate company would send, complete with correct grammar, natural phrasing, and a tone that matches whatever brand it's impersonating.


That means the entire category of scam that used to announce itself through broken English has largely vanished, or at least stopped being something you can count on spotting. The messages that get through now are fluent, professional, and often genuinely well written. Polish used to be evidence of legitimacy. It isn't anymore, and treating it that way is exactly how people get caught out.


The Message That Actually Caught Me Out


I got a text a while back that I genuinely hesitated over, which almost never happens to me anymore given how much of this I read about for work. It claimed to be from my bank, referenced a recent transaction in a way that felt specific rather than generic, and asked me to confirm my details through a link because of "unusual account activity." The English was flawless. There was no urgency-in-capital-letters, no missing punctuation, nothing that matched the old checklist I used to rely on.

Glowing blue and cyan light streams flowing through dark space with golden bokeh, abstract digital data visualization with depth.


What actually stopped me wasn't the writing at all. It was that I hadn't made any transaction resembling the one it referenced, and that my bank has never once, in years of banking with them, asked me to confirm details through a text link. I closed the message, opened my banking app separately, and confirmed nothing was wrong. If I'd been judging it purely on how well it was written, I'd have had no reason to doubt it at all.


What I Actually Look For Instead Now


Since writing quality stopped being a useful signal, I've had to rebuild the checklist around things that are harder for a scammer to fake convincingly, AI or not. The biggest one is whether the message is asking me to act somewhere other than the official channel I already use, a link in a text rather than logging into the app directly, a phone number in the message rather than the one printed on my card. Genuine organisations very rarely need you to do anything urgent through a link they've just sent you.


I also pay attention to whether the specific detail in the message actually checks out, not just whether it sounds specific. A scam text can reference "your recent order" convincingly without referencing an order that exists. It costs nothing to open the relevant app or account directly and see whether anything matches, and that single step catches far more than reading the prose carefully ever did.


Urgency is still a useful signal, but I look for it in the structure of the request rather than the tone of the sentence. A message that wants a decision made immediately, with a specific narrow action like clicking one link or calling one number right now, is behaving the way a scam behaves regardless of how well it's phrased. I've written before about the checks I use to catch AI-driven scams more broadly, and this fits into the same habit of judging the request rather than the writing.


The Habit That Matters More Than Spotting Bad Writing


If there's one adjustment I'd want everyone to make, it's this. Stop using writing quality as a filter at all, in either direction. A badly written message isn't automatically fake, and a beautifully written one isn't automatically real. The writing tells you almost nothing useful now. What tells you something is whether the request matches how the real organisation actually operates, and whether you can verify the claim independently rather than through the channel the message itself provided.


That's a slower habit than scanning for typos, and it asks a bit more of people than the old rule did. But the old rule is broken, and pretending it still works is worse than admitting it and building something sturdier in its place. I'd rather take the extra thirty seconds to check an account directly than trust a message just because it reads well, because reading well has stopped meaning anything at all.


If you want a fuller rundown of the other basics I'd put in place alongside this, I've pulled them together in a free Safety Toolkit. It's also worth knowing what a real phishing email actually looks like line by line, so you know what you're comparing a suspicious message against. And if you do get caught out, Action Fraud is the place to report it in the UK.