"Your account will be suspended. Confirm your information here: securite-clientweb-verif[.]info"
On a screen, this message gives itself away quickly. The eye catches on the odd sender, the endless domain name, the misplaced dot, the irregular spacing, the slightly blurry logo. In under two seconds, an experienced user has spotted three anomalies without even putting them into words.
Now listen to it. A screen reader announces: "Your account will be suspended. Confirm your information here, colon, h-t-t-p-s colon slash slash securite dash clientweb dash verif dot info". The delivery is linear, neutral, with no hierarchy. None of the visual anomalies exist any more. All that remains is a sentence, and a sentence is judged on its content — exactly what the scammer worked hardest on.
This is a blind spot that prevention campaigns almost never mention: virtually all anti-smishing advice relies on visual cues. For blind and partially sighted people — or simply for those using their phone in very large type with tired eyes — that advice quite simply doesn't work.

A wider audience than you'd think
According to figures from the Fédération des Aveugles et Amblyopes de France and DREES surveys on disability, around 1.7 million people in France report a vision impairment, of whom close to 200,000 are blind or severely partially sighted. On top of that comes a far larger population: people over 70 affected by age-related macular degeneration (AMD), cataracts or glaucoma, who don't necessarily use assistive technology but struggle to read their phone, holding it at arm's length under a lamp.
These users are not offline. Since the arrival of VoiceOver on iPhone and TalkBack on Android, the smartphone has become a major tool for independence: reading text messages, calling a taxi, identifying a banknote, having a photo described. INSEE notes that mobile phone ownership among people with disabilities has caught up with that of the general population.
The logical consequence: they receive exactly the same volume of fraudulent text messages as everyone else. Scammers buy lists of numbers; they don't know — and don't try to find out — who is behind them. There is no targeting here. What changes is the success rate.
What synthetic speech erases
To understand the problem, you have to spell out what the auditory channel removes compared with the visual one.
| Classic warning sign | Perceived by eye | Perceived via screen reader |
|---|---|---|
Deceptive domain name (impots-gouv[.]services) | Immediate, the structure leaps out | Read as a string of syllables, with no hierarchy |
| Badly copied typography or logo | Immediate | Non-existent |
| Spelling mistakes | Immediate | Often smoothed over by pronunciation |
| Sender shown as a long number (+33 6…) | Visible at a glance | Read out, but lost in the flow |
| Shortened link (bit.ly…) | Instant suspicion | Means nothing to the ear |
| Layout in capitals conveying urgency | Visually aggressive | Neutralised by flat intonation |
The most serious issue concerns URLs. The brain reads a web address from right to left: you look first for the main domain just before the first slash. It's a spatial reflex. Spoken aloud, that structure disappears: secure.ameli.fr and ameli.secure-verif.fr produce an almost identical stream of sound to an untrained ear, even though the second has nothing to do with the French health insurance service.
Second problem: homoglyph characters. Scammers replace an "l" with a capital "I", an "o" with a zero, or use visually identical Cyrillic letters. Visually, this is sometimes detectable. Aurally, it is completely invisible — the synthesiser pronounces the expected word.
Third problem: mistakes. A sentence with a botched agreement jumps off the page. Read out by a synthetic voice, the faulty grammar evaporates entirely.
Verbosity: the setting that changes everything
There is, however, a highly effective and surprisingly little-known countermeasure: turning up your screen reader's verbosity.
By default, VoiceOver and TalkBack are set for fluency. You can configure them to announce a great deal more:
- Spell out links character by character rather than pronouncing them as words. It's slower, but a fraudulent domain becomes audible;
- Announce punctuation ("dot", "dash", "slash") systematically, by setting the punctuation level to "All";
- Flag capital letters, which reveals "I" characters substituted for "l";
- Announce non-standard characters or language changes, which exposes the use of mixed alphabets.
On iPhone, these settings are found in Settings → Accessibility → VoiceOver → Verbosity. On Android, in Settings → Accessibility → TalkBack → Verbosity preferences. Practical tip: don't stay in maximum mode permanently — it's exhausting — but know how to switch to it as soon as a message contains a link or a request for information.
Many users, incidentally, work with a bone conduction headset so they can listen to their screen reader without cutting themselves off from surrounding sounds; it's a good companion when you want to take the time to spell out an address in the street without broadcasting its contents to everyone around you.
The move that makes a text message readable: braille
For users who have one, a refreshable braille display changes everything. Where speech synthesis flattens, braille renders the character string exactly as it is: every dot, every dash, every capital is physically present under the finger. A fraudulent URL becomes analysable again, exactly as it would be by eye.
The problem is financial. A refreshable braille display costs several thousand euros, even if the French disability compensation benefit (PCH) can cover part of it via the MDPH. Many users simply don't have one.
A free, intermediate solution: "character by character" reading mode. On both VoiceOver and TalkBack, a vertical swipe gesture lets you change the text navigation mode (word, character, line). Switching to character mode and going through a link before tapping it takes twenty seconds. It's the single most worthwhile move in this whole article.

Mild low vision: the zoom trap
People with low vision are no better off, for the opposite reason. When you read at 300% magnification, you only see a fragment of a line at a time. The reading field is reduced to a few words. Yet spotting a scam largely depends on seeing the whole picture: it's the juxtaposition of sender, tone and link that raises the alarm, not each element taken in isolation.
A user at high magnification therefore reads their text message through a tunnel. They see "Assurance Maladie", then, three swipes later, a link they no longer mentally connect to the context. Add eye strain: after twenty minutes of screen time, vigilance drops.
A few adjustments genuinely help:
- Turn on high contrast and bold text in the accessibility settings rather than pushing the zoom to the maximum;
- Use a portable electronic magnifier for paper documents received in parallel (letters from institutions, bank details): this avoids mixing up channels and mistaking a genuine letter for a fake SMS;
- Keep a daylight-spectrum desk lamp near the chair where you check your phone: poor lighting doubles reading time and halves critical attention;
- Avoid reading sensitive messages on the move, standing up on a bus. That's where mistaken taps happen.
Some people prefer to separate their uses altogether: a smartphone for the internet, and a big-button mobile phone for everyday calls. That's not a step backwards, it's a deliberate reduction of the attack surface — fewer apps, fewer linked accounts, fewer clickable links.
The real shield: content rules, not form rules
Since cues based on form are inaccessible, vigilance has to be rebuilt on what remains perfectly audible: the content of the message. These rules have the advantage of being universal and owing nothing to sight.
No public authority, no bank and no telecoms operator will ever ask by text message for a payment, a bank card number, a code received by SMS, a password or a copy of an ID document.
This sentence is repeated word for word by Cybermalveillance.gouv.fr, the DGCCRF and the Banque de France. It is enough to rule out the vast majority of smishing campaigns, without needing to inspect a single pixel.
Three content markers worth memorising, all of which come across perfectly by ear:
- Quantified urgency. "Within 48 hours", "final reminder", "before midnight". A French public authority never imposes such a short deadline by message. It writes a letter.
- The small sum. €1.79, €2.90, €0.99. The trivial amount defuses suspicion; its only purpose is to capture the card number.
- The unexpected channel. You haven't ordered anything, declared anything, requested anything. A message that arrives with no prior trigger is suspect by design.
The callback rule: never follow the message
The central reflex, accessible to everyone, comes down to one sentence: never use the contact channel supplied by the message itself.
In practice, you close the text message and reach the organisation by a route you already control:
- The number saved in your contacts or printed on the back of your bank card;
- The official app installed on your phone, opened manually;
- A bookmark saved in advance in your browser.
This is where preparation counts. Saving in advance, in plain form, the numbers for your bank, your health insurance office, your telecoms operator and your town hall spares you having to look them up in a hurry — the very moment when people tap. Many users also keep a large-print address book or a braille one listing these reference contacts, kept off the phone. When in doubt, you read the notebook, not the message.
For those juggling multiple passwords, a password manager compatible with screen readers brings an unexpected security benefit: it won't auto-fill credentials on a fraudulent site, because the domain doesn't match. The refusal to fill becomes an alert you can perceive without sight.

Reporting: 33700 is accessible
France's national scheme for reporting unwanted text messages works both ways and requires no complex visual manipulation.
- By forwarding: forward the suspicious SMS to 33700, free of charge. The service then replies with a message asking for the sender's number, which you send back in turn.
- Via the website: the 33700 platform allows online reporting and is compatible with screen readers.
- For clear-cut attempted fraud: the Pharos platform (internet-signalement.gouv.fr) and the Cybermalveillance.gouv.fr website, which directs you to local providers.
If money has been taken, the process is the same as for everyone else: immediately stop the payment with your bank, file a complaint, and invoke articles L133-18 and following of the French Monetary and Financial Code, which provide for reimbursement of an unauthorised transaction.
An important point for family members and carers: a visually impaired person who falls victim to smishing has not been "careless". The opposite assumption is common and unfair. They were deprived of information that the interface failed to convey to them. The responsibility lies with the design, not the user.
What the industry should improve
It needs saying plainly: the bulk of the work should not fall on potential victims.
- Messaging apps could explicitly announce a link's real domain to the screen reader, before it is even opened, rather than reading out the raw URL.
- Public prevention campaigns would benefit from offering audio-described versions: most of the awareness visuals distributed by operators and banks are screenshots… with no alt text.
- Verified business senders under the RCS standard, with their identity checked upstream, are a promising avenue: structured authenticity information can be conveyed by a screen reader, unlike a logo.
In the meantime, vigilance can be rebuilt on three simple pillars: set your screen reader to spell out links, judge a message on its content rather than its appearance, and never call back through the channel it offers. Three habits that require no sight at all — and that protect sighted people just as well.



