The classic classifieds scam starts with a friendly message. “Is this still available? I’ll pay the full price. My courier will collect it; I’ve sent the payment, just click this link to confirm.” The account is a day old. It will send the same story to forty other sellers this afternoon, and it will be gone by tomorrow, replaced by another.
Content moderation alone loses this race, because the scammer rewrites the message faster than you update filters. The account behind it is cheap too. What is expensive for the scammer is the device they run all those accounts from, and that is where early detection works best.
The anatomy of a chat scam
Most buyer-seller scams share a structure:
- A throwaway account, created with a disposable or freshly made email, often minutes before the first message.
- Many first messages in a short time, to sellers across categories, with near-identical text.
- A payment story: overpayment, a fake courier service, an escrow site, a “verification fee,” or a request to move the chat to another app.
- An off-platform link or contact, where the actual theft happens through a phishing page or a payment request.
- Abandonment: the account is discarded once reported, and a new one appears.
Steps 1, 2 and 5 are about accounts and devices. Steps 3 and 4 are about content. Good detection uses both, scored at the moment the account sends its first message.
Why the first message is the right checkpoint
At signup the scammer has done nothing wrong yet, and blocking every new account is not an option for a marketplace that depends on new buyers. By the tenth message, sellers have already been targeted. The first message is the earliest point where an account reveals intent, and the last point where stopping it prevents all of the follow-on harm.
Treat it as a separate, higher-risk action with its own identify call:
const prynt = await Prynt.load({ apiKey: 'pk_live_…', extendedResult: true }); // Smart Signals + decision
async function sendFirstMessage(listingId, text) {
const { requestId } = await prynt.identify({
tag: { action: 'first_message' },
linkedId: currentUser.id,
content: { text, expectedScripts: ['latin'] },
});
return fetch('/api/messages', {
method: 'POST',
body: JSON.stringify({ listingId, text, requestId }),
});
}
Passing content lets Prynt analyze the message for spam patterns such as links, script mismatches and known spam phrasing, reported as contentSpam with the reason code CONTENT_SPAM (a Pro-plan signal). expectedScripts flags messages written in a script your market does not use, which is a common tell for organized spam. Passing linkedId ties the event to the account, which enables the account-count signals below.
The signals that matter
Device reuse
The strongest single signal. On your server, accountsOnDevice lists every account linked to the device. A first message from a device with five accounts created this week, two of which you already banned, is very likely a scam regardless of how polite the text is.
On paid plans, the risk engine also computes multiAccount (two or more accounts on a device in 30 days) and accountSharing (more than three in 24 hours). If you report bans through POST /v1/outcomes, the device carries a known-abuser reputation into the next account, surfaced as KNOWN_ABUSER.
Velocity
Scammers work at volume. Count first messages per device and per account per hour in your own data, and use Prynt’s velocity signal for bursts of identifications from one device. A new account that has messaged fifteen sellers in twenty minutes is not shopping.
Account age and network
A first message within minutes of signup, from a datacenter, vpn or residentialProxy network, or from a country that does not match the listing’s market, raises risk. None of these is decisive alone; together they are.
Content
contentSpam catches the obvious cases: link-heavy messages, script mismatches and known spam phrasing. Add your own patterns for local payment stories, courier names that scammers impersonate, and requests to move to another messaging app. The off-platform payment steering guide covers those patterns in detail.
A scoring policy for first messages
Decide on the server, before the message is delivered:
const event = await prynt.getEvent(requestId);
const others = event.accountsOnDevice.accounts.filter(a => a.linkedId !== user.id);
const spam = event.smartSignals?.contentSpam?.result;
const newAccount = Date.now() - user.createdAt < 24 * 3600 * 1000;
let action = 'deliver';
if (event.decision === 'block') action = 'drop';
else if (others.length >= 3 && newAccount) action = 'hold_for_review';
else if (spam && newAccount) action = 'require_phone_verification';
else if (event.decision === 'challenge') action = 'delay_delivery';
Some practical notes:
- Hold, don’t bounce. Tell the sender the message is “sending” while it waits in review. A scammer who sees an instant rejection simply rewrites the text.
- Throttle new accounts. A cap on first messages per day for accounts under a week old limits damage even when detection misses.
- Cluster on ban. When you ban an account, look up its device and review its siblings from
accountsOnDevice. Banning the whole cluster at once is what makes the next round of accounts expensive.
Protect the seller, too
Detection will miss some scams, so give sellers context. A gentle banner on messages from very new accounts (“this buyer joined today”), warnings when a message contains a link or asks to move off-platform, and a one-tap report button all reduce harm. Reports are also your best source of labels: feed confirmed cases back through /v1/outcomes.
Where to start
Add an identify call to the first-message action with linkedId and content, start in flag-only mode, and review a week of flagged first messages. If, as is common, a few devices sit behind many of your scam reports, holding first messages from those devices is a quick, measurable win. The marketplace trust and safety guide and the listing spam guide cover the rest of the platform, and the form protection page explains content analysis options.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.