Risk:High — A vague return-warning message linking to vfyMd.com may steal login or payment details by pressuring recipients to act without verification.
Install the app:Open the app and verify suspicious content in one scan.
Online Scam Prevention for Urgent Return Links
If you clicked the link, replied, entered information or opened a downloaded file, contain that exposure first using the recovery steps below. Do not reopen the message to investigate it.
When this applies
Use this online scam prevention guide when an unexpected message vaguely says you must resolve a problem or an item will be sent back. A typical passage is: “Please resolve the problem, or we will send it back,” followed by a link such as `vfyMd.com/9n9Ke2` but no order details or verified sender identity. The wording creates urgency without explaining what purchase, shipment or account is affected. Its automated tone does not establish who sent it or why they are contacting you.
Decision steps in order
- Do not click, copy or forward the link. Preserve evidence with a screenshot that shows the message, sender details and visible domain.
- Check whether you are expecting an order. Open the retailer or carrier through its saved app, bookmark or manually typed official address—not through the message.
- Review your order history for a matching return problem. If no matching notice appears, treat the message as phishing.
- If an issue appears genuine, contact the business using contact information from its official website or your original receipt. Ask whether it sent the exact message.
- Report the message through your email or messaging service’s phishing function, then delete it and block the sender.
What to do if you already responded
- If you only replied, stop communicating and do not provide codes, passwords, payment details or personal documents.
- If you entered a password, change it from the service’s official site, sign out other sessions and enable multifactor authentication. Change any other account using the same password.
- If you submitted card or bank details, call the issuer using the number on the card or official statement and request fraud monitoring or replacement guidance.
- If the link downloaded a file and you opened it, disconnect that device from networks, run its built-in security scan and seek qualified IT help before using it for sensitive accounts.
- Monitor the affected shopping, email and financial accounts for unfamiliar changes or transactions.
Most common warning signals
- The message vaguely says “please resolve the problem or we will send it back” without identifying an order, item or account.
- The visible link uses the suspicious domain vfyMd.com followed by a coded path such as `/9n9Ke2`.
- The text appears automated and provides no verifiable sender identity.
What to do now
- Stop interacting with the message and do not reopen vfyMd.com.
- Change any password entered on the linked page and sign out other sessions.
- Call the card or bank issuer immediately if payment details were submitted.
- Disconnect the device from networks if a downloaded file was opened, then run a security scan.
- Verify any claimed order problem through the retailer’s official app or manually typed website.
- Report the message as phishing, block the sender and delete it.
Further reading
- Online Scam Prevention for Fake Air Bank SMS
- Post-Scam Recovery Steps for Small Businesses
- Marketplace Fraud Warning Signs for Small Firms
FAQ
Could the “resolve the problem or we will send it back” message be genuine?
Do not trust it from the wording alone. Check your order history through the retailer’s official app or a manually typed website address, then contact the business through verified details.
What should I do if I opened vfyMd.com but entered nothing?
Do not revisit it. If you entered nothing and downloaded nothing, close the page, clear the browser tab and report the original message; continue watching for unexpected login alerts.
Is replying to this automated-looking message dangerous?
Yes. A reply confirms that your address or number is active and can invite further phishing attempts, so stop responding, block the sender and disclose no information.