Amazon's Alexa for Shopping now checks if a message is really from Amazon

Amazon has added a new anti-phishing feature to its Alexa for Shopping AI assistant: customers can now ask it whether an email, text message, or phone call claiming to be from Amazon is real. To answer, the assistant compares the message against a record of every message Amazon has sent, while also analyzing its content, formatting, and sender. Amazon says the assistant will confirm a message is genuine only when it is completely certain. In an example Amazon shared, a customer asks Alexa for Shopping, "Did Amazon just text me an OTP from 98626? Message came around 4:50pm." The assistant replies, "This was a genuine One Time Password from Amazon," confirming the code was legitimate. If the assistant instead determines a message did not come from Amazon, it tells the customer to check their orders in the Amazon app and to contact Amazon support directly, rather than responding to the suspicious message. The feature builds on an option Amazon introduced earlier this year that lets customers forward suspicious messages to verify@amazon.com to have them checked. The verification tool arrives alongside another recent addition to Alexa for Shopping, an "Update Me When" feature that tracks and notifies customers about new product releases.
Key facts
- Alexa for Shopping can now tell customers whether an email, text, or call claiming to be from Amazon is genuine.
- The assistant checks the message against a record of every message Amazon has sent and analyzes its content, formatting, and sender.
- Amazon says it will confirm a message is real only when it is completely certain.
- In Amazon's example, the assistant confirmed a one time password text as genuine when asked.
- If a message is flagged as fake, the assistant tells customers to check the Amazon app and contact support rather than reply.
Why it matters
Impersonation scams that spoof Amazon's name in emails, texts, and calls are a persistent way to trick customers into handing over payment details, account credentials, or one time passwords. By putting a verification check directly inside the shopping assistant customers already use, Amazon is trying to give people a fast way to confirm a suspicious message before they act on it, instead of relying on customers to spot the fakes themselves or dig through a separate reporting channel.
Who it affects
The feature is aimed at Amazon customers who use Alexa for Shopping and receive messages purporting to be from Amazon, including order updates, delivery notices, and one time passwords sent during account actions. It gives them a way to ask the assistant directly rather than guessing whether a message is legitimate.
How to use it
A customer asks Alexa for Shopping about a message they received, describing it much as they would to a person, for example naming the sender code and roughly when it arrived. The assistant checks it against Amazon's record of sent messages and its content, formatting, and sender, then reports back whether it is genuine. If the assistant cannot confirm a message is real, it directs the customer to check their orders in the Amazon app and to contact Amazon's support team directly rather than respond to the message itself. The source does not specify a launch date, availability by region, or which AI system performs the comparison.
How solid is it
The account comes from Amazon's own description of the feature, illustrated with a single example exchange Amazon provided rather than an independently verified incident. No specific launch date, regional availability, or underlying technology is disclosed, and no named individual at Amazon is quoted; all statements are attributed to the company.
Risks and caveats
The feature only ever confirms a message as genuine when the assistant reports being completely certain, which suggests it is designed to err toward flagging uncertain cases rather than falsely clearing a scam. Amazon has not disclosed how the comparison works technically, so its accuracy and coverage against novel phishing attempts are not independently verifiable from what has been published.
“This was a genuine One Time Password from Amazon.”
— Alexa for Shopping, in Amazon's example response