Is it safe to use a virtual number?
Virtual numbers are safe for most sign-ups, with real limits. What's safe, what isn't, when a service blocks one, and how to use one without getting burned.
Pre-launch — you can read everything, but ordering isn't open yet. Where we are
OTP stands for one-time password: a short numeric code that works once and expires quickly. Amazon sends them for two completely different reasons — to confirm it is really you signing in, and in some countries to confirm a delivery was handed to the right person.
This is the familiar one. You enter your password, Amazon texts or emails a code, you type it in. It is a second factor: the password is something you know, the code proves you also hold the phone or mailbox on the account.
Amazon sends one when you sign in from an unfamiliar device or location, when you change account details, when you have two-step verification switched on, and sometimes when its own risk checks flag an attempt. None of those are unusual on their own.
In some countries Amazon confirms a handover with a code instead of a signature. You receive it as the parcel approaches, the driver asks for it at the door, and entering it marks the delivery complete. It is a proof-of-delivery mechanism, not a security check on your account, and it is why the same three letters can mean two different things in the same inbox.
Whether you see these depends on where you are and on the type of order — high-value items and cash-on-delivery orders are the usual cases. If you have never seen one, your market probably does not use them.
| Sign-in OTP | Delivery OTP | |
|---|---|---|
| Arrives when | You (or someone) sign in | A parcel is about to be handed over |
| Proves | You hold the phone on the account | The parcel reached the right person |
| You give it to | Nobody — you type it in yourself | The delivery driver, at the door |
| If unexpected | Someone has your password | Check the order in the app |
Note the third row. The delivery code is the only one you ever say out loud, and only to a person physically handing you a parcel. Every other request to read a code aloud is fraud.
OTP-relay fraud works like this: the attacker already has your password. They start a sign-in, which makes Amazon text you a genuine code — genuinely from Amazon, from the usual sender. Then they phone you, claiming to be Amazon security or a courier, and ask you to confirm “the code we just sent”. You read it out. They complete the sign-in.
The code being real is what makes it work. There is nothing to detect in the message itself, so the rule has to be about the conversation, not the text:
Check the number on the account is current, give it a minute before requesting another, and try the email option if one is offered. If codes reach you from other services but not this one, the problem is likely in the route rather than your phone — why SMS codes don't arrive explains where in the chain that happens.
A short window, and Amazon does not publish the exact figure — treat it as minutes, not hours. If it has expired, request a fresh one rather than retrying the old code.
For an account you intend to keep, no — and we rent numbers and still say that. The number on an account is how you recover it. Put a rented number there and the day you are locked out is the day you discover someone else can rent it next. Temporary numbers are for one-off verifications you will never need to repeat.
An OTP is one way to do two-factor authentication, not the whole idea. An authenticator app generates codes on your device without a message being sent at all, which removes the SMS route — and the relay scam — entirely. Where a service offers it, it is the stronger option.
What does SMS mean? covers the messaging standard these codes travel on, and what is SMS explains why “delivered” is a weaker word than it looks.
Every route shows its price and its data state up front — and where we have nothing yet, it says so.
Every route below is one click away. Open a country to see its services, or jump straight to a service hub.