TL;DR
- To save evidence after a scam call, start with the receiving number, the number shown on caller ID, any callback number the caller supplied, and the exact date and time. Those are the specific call details the FTC asks people to include when reporting unwanted or scam calls. See the FTC's current phone-scam reporting guidance.
- Preserve the voicemail, call-log entry, texts, emails, screenshots, website addresses, and a factual timeline. Caller ID alone is weak evidence because a scammer can make a different name or number appear on the display. The FTC explains caller ID spoofing and phone-scam response.
- If money moved, save the transaction date, amount, receiving account or identifier, receipt, and payment method. Contact the provider immediately instead of waiting until the evidence folder feels complete. The FTC lists recovery contacts by payment method.
- Keep original files in a secure location. The FBI's Internet Crime Complaint Center says complainants should retain original documents because an investigating agency may request them later. Read the IC3 evidence and complaint FAQ.
- A report confirmation does not replace the underlying evidence. Save both, and keep a short log of whom you contacted, when, and what response you received.
- Do not call the scammer again to collect better evidence. First reduce the risk to your money, accounts, phone number, and devices, then document and report through contact details you found independently.
A scam call can be brief, but the useful evidence often sits in several places: the phone log, a voicemail, a text that arrived during the call, a payment app, an email receipt, and your memory of the script. Saving only a screenshot of the displayed number leaves out the details that a carrier, bank, regulator, or investigator may need.
The goal is not to build a dramatic case file. It is to preserve original records, separate facts from recollection, and make fast protective actions possible. If the call involved only an unwanted pitch, the evidence set can be small. If you sent money, disclosed identity data, installed software, or lost control of your phone number, the response needs to expand.
This guide explains how to save evidence after a scam call without treating caller ID as proof of identity. For background on common scripts, compare the patterns in our scam call reference. When you are ready to submit the incident, use the separate robocall reporting guide to choose the correct complaint route.
What evidence should you save first after a scam call?
Start with information that can disappear or become harder to retrieve: the call-log entry, voicemail, related messages, and transaction details. Capture them before blocking, clearing notifications, replacing a phone, closing an account, or deleting an app. A clean copy made now is more reliable than a reconstruction made days later.
Use this first-pass checklist:
- Your number that received the call.
- The caller ID name and number exactly as displayed.
- Any different number the caller told you to call, text, or add to an app.
- The date, local time, time zone, and call duration.
- Whether the call was answered, missed, screened, or sent to voicemail.
- The original voicemail audio and any available transcript.
- Text messages, emails, social messages, QR codes, attachments, and links connected to the call.
- The organization, agency, relative, employer, or business the caller claimed to represent.
- The action demanded, including a payment, password, one-time code, remote-access installation, account transfer, or secrecy request.
- Any money sent or information disclosed.
The FTC asks for the number that received the call, the caller ID number, any callback number, and the date and time when a person reports an unwanted call. It asks people who lost money or have details about a scammer to use ReportFraud.ftc.gov rather than only the streamlined unwanted-call form. The FTC distinguishes these reporting paths and lists the requested call details.
Do not crop every screenshot down to the suspicious number. Keep a version that shows the surrounding screen, date, thread, account name, or app context. A cropped copy can be useful for a report, but the fuller original helps explain where the item came from. Avoid editing the original file. If you need to redact private information for sharing, make a separate redacted copy.
Why is the displayed phone number not proof of who called?
Caller ID records what your device received as display information. It does not authenticate the human or organization behind the call. Scammers can spoof a government switchboard, a bank number, a local area code, or even your own number. The FTC's phone-scam guidance states that scammers can make any name or number appear on caller ID.
That limitation changes how you label evidence. Write "caller ID displayed this number," not "the call came from this number." Write "the caller claimed to be from the bank," not "the bank called." The difference protects the accuracy of your report and reduces the chance that an uninvolved subscriber is blamed for a spoofed call.
An area code also does not establish the caller's location. Number portability, internet calling, and spoofing separate the displayed digits from the caller's current place. Our guide to checking whether a call is spoofed explains how to verify an organization through a contact route you find yourself.
How do you preserve a voicemail, call log, or message correctly?
Preserve the original where it already lives, then make a backup you can access without changing the original. A voicemail may be stored by the carrier or on the device, so retention and export options differ. If the phone offers Share, Save, Export, or Download, use it and keep the resulting audio file with a screenshot of the voicemail entry.
Phone by Google, for example, says supported visual-voicemail users can expand a voicemail and use the Send option to share the audio recording. It also notes that availability varies by device, carrier, country, and region. Check Google's current voicemail instructions for supported Android phones. If your device has no export option, ask the carrier how to preserve the message before assuming it will remain available.
For each item, retain context:
- Call log: capture the full entry, including date, time, duration, call direction, and displayed number.
- Voicemail: keep audio and transcript if both exist. Treat automated transcripts as aids, not perfect quotations.
- Text or chat: save the whole relevant thread, sender identifier, timestamps, links as visible text, and profile or account name.
- Email: preserve the electronic message and full header when possible, not only a screenshot of the visible body.
- Website: save the complete URL and screenshots of the page, payment instructions, account name, and error or confirmation messages. Do not revisit a suspicious link solely to improve the screenshot.
- File or app: note the filename, app name, download source, and time. Do not reopen a suspicious attachment on another device for documentation.
The IC3 FAQ prefers electronic copies of emails and says printed copies should include full header information. Its evidence examples also include phone bills, payment receipts, web pages, mail receipts, and technical logs. IC3 instructs complainants to retain original documents securely rather than assuming the complaint submission stores the evidence for them. Review the FBI's full evidence examples before discarding records.
Should you record a scammer who calls again?
Do not re-engage for the purpose of recording. Another call can expose more information, give the scammer another chance to pressure you, or lead you to follow a link or payment instruction.
An existing voicemail is different: it is already part of the received communication. Preserve it. If your phone created a call-screening transcript or recording automatically, save what already exists and record how it was produced. Do not edit the audio or remove pauses. A copy for convenient playback is fine as long as the original remains available.
If a threat suggests immediate danger, contact emergency services. For a non-emergency crime report, use the official website or non-emergency contact for the relevant local law-enforcement agency. USAGov advises people to find the local agency's contact information independently rather than relying on details supplied during the suspicious call. See USAGov's current crime-reporting routes.
What should a scam-call timeline contain?
A useful timeline is a sequence of observable events, not an essay about what you think the scammer intended. Write it while the call is fresh. If you are uncertain about a word, amount, or time, say so. Never make a remembered detail look exact just because a complaint form asks for it.
For each event, record:
- Date, time, and time zone.
- Channel: call, voicemail, text, email, payment app, website, remote-access tool, or in-person follow-up.
- Displayed identifier and any alternate contact identifier.
- The claim made by the caller.
- The action requested and any deadline or threat stated.
- Your response, including information disclosed or software installed.
- Payment method, amount, transaction identifier, and recipient details, if applicable.
- Protective action taken, such as calling a card issuer through the number on the card.
- Report or case number received.
- Whether the entry comes from an original record, a screenshot, or memory.
Use direct wording. "Caller said my electricity would be disconnected today unless I paid by gift card" is more useful than "caller was aggressive." If you remember only the gist, label it as a paraphrase. If two records conflict, keep both and note the discrepancy rather than choosing the version that seems stronger.
The FBI says IC3 complaints depend on accurate and complete information. Its form asks for complainant contact information, financial loss and transaction information, identifiers associated with the subject, specific incident details, and email headers where applicable. The IC3 FAQ describes the information requested in a complaint.
What common documentation mistakes weaken a report?
The first mistake is treating the caller ID number as a verified identity. The second is deleting a voicemail after copying a few words into a complaint. The third is mixing several calls into one undated narrative. These errors make it harder to distinguish what happened from what was inferred later.
Other failure modes include:
- Editing or annotating the only copy of a screenshot.
- Forwarding sensitive evidence into a public group or social post.
- Saving a payment-app nickname but not the transaction identifier.
- Photographing a gift card but discarding the card or receipt.
- Listing the date without the time zone when accounts or recipients cross regions.
- Reopening suspicious links to capture a cleaner page.
- Installing another tool recommended by a supposed recovery specialist.
- Assuming an FTC, FCC, bank, or police submission automatically stores every original file.
- Writing conclusions such as "the bank employee stole the money" when the evidence supports only impersonation of the bank.
Keep an evidence index if the incident produced many files. A simple table with filename, source, date captured, original location, and short description is enough. Do not rename the only original. If you rename a working copy, preserve the old filename in the index.
Which payment evidence matters if you sent money?
Payment evidence needs to identify the route, timing, amount, sender, recipient, and reference number. Save the confirmation page or receipt, relevant statement entry, emails, messages containing instructions, and the contact record for the provider's fraud department. Do this while contacting the provider. Documentation should not delay a request to stop, reverse, freeze, or trace a transaction.
| Payment or loss type | Save now | Immediate contact | Main limitation |
|---|---|---|---|
| Credit or debit card | Receipt, statement entry, merchant descriptor, amount, date, and messages | Issuing bank or card company through a trusted number | A displayed merchant name may differ from the actual recipient |
| Bank debit or wire | Account entry, transfer reference, recipient details, routing information, amount, and time | Your bank's fraud department | Recovery may depend on timing, authorization facts, and destination |
| Payment app | Transaction ID, recipient handle, linked funding source, screenshots, and chat | App provider and the linked bank or card issuer | A username or profile image does not prove legal identity |
| Gift card | Physical card, front and back copy, store receipt, card number details, and messages | Gift card issuer | Sharing the card number or PIN may allow rapid redemption |
| Cryptocurrency | Transaction hash, wallet addresses, asset type, amount, date, time, platform, and communications | Exchange or wallet provider, then IC3 when appropriate | Blockchain records do not by themselves identify the person controlling a wallet |
| Cash or mailed item | Receipt, tracking, destination, carrier, package details, and messages | Delivery carrier or postal inspector through official channels | Interception may not be possible after delivery |
The FTC advises people who paid a scammer to contact the company used to send the money and ask whether the transaction can be reversed or refunded. Its guidance covers cards, bank transfers, gift cards, wire services, payment apps, cryptocurrency, and mailed cash, and it specifically tells gift card victims to keep the card and receipt. Use the FTC's payment-method response table for the current route.
For cryptocurrency, the FBI identifies wallet addresses, amount and asset type, transaction hash, and transaction date and time as particularly useful details. It also asks for communication platforms, domains, phone numbers, and other identifiers connected to the scheme. The IC3 cryptocurrency page lists the current complaint details.
Do not publish a transaction receipt to crowdsource help. Receipts can expose account numbers, addresses, email accounts, barcodes, or other identifiers. Share through the secure channel chosen by the bank, provider, regulator, or investigator. Keep a redacted copy for any conversation that does not require the full record.
What if you disclosed personal information or remote access?
Evidence collection becomes secondary to containment when a caller obtained credentials, a Social Security number, a one-time code, control of a phone number, or remote access to a device. Record what was disclosed and when, but take protective action without waiting for a perfect inventory.
If credentials were shared, change them through the real service and change reused passwords elsewhere. If the phone number or carrier account was taken over, contact the carrier through a trusted channel. If identity information was exposed or used, IdentityTheft.gov creates recovery steps based on the situation. The FTC's recovery site tells victims to contact companies where fraud occurred, close or freeze affected accounts, change credentials, and keep notes about contacts and responses. Follow the current IdentityTheft.gov recovery steps.
Save security evidence that already exists:
- Password-reset or login-alert emails.
- Notices that a recovery email, phone number, PIN, or mailing address changed.
- Carrier messages about a SIM, eSIM, port, or account change.
- Names of remote-access apps installed and the time of installation.
- Bank alerts, declined transactions, new payees, or account changes.
- Device security scan results produced during the cleanup.
- Confirmation letters from companies that closed, froze, restored, or corrected an account.
Do not leave a compromised device connected merely to preserve its state unless a qualified investigator or incident responder directs you to do so. For consumer incidents, stopping access and securing accounts comes first. The FTC tells people who gave a scammer remote access to update security software, run a scan, delete identified problems, and take steps to protect personal information. Follow the FTC's current device-access response. If the matter involves a business network, regulated data, or a large financial loss, the organization's security or legal team may need a formal evidence-preservation process.
How should you organize and store scam-call evidence?
Use one incident folder with restricted access, a backup, and a small index. Keep originals separate from the copies you redact, resize, annotate, or upload. A clear structure prevents accidental deletion and makes it easier to answer a bank or agency without sending unrelated personal data.
A practical folder can contain:
01-call-recordsfor call-log captures, voicemail, and transcripts.02-messagesfor texts, email files, headers, and chat exports.03-paymentsfor receipts, transaction details, and statements.04-accountsfor security alerts and recovery confirmations.05-timelinefor the factual chronology and evidence index.06-reportsfor submitted copies, confirmation emails, case numbers, and follow-up notes.
The folder names are suggestions, not an official standard. The controls matter more: secure access, preservation of originals, a backup, and enough context to understand each file. If a family member helps, give them only the access they need. If you print documents, store them away from household papers that might be discarded.
Record every external contact in the timeline. The CFPB's consumer guidance for documenting a money-transfer problem recommends keeping notes about whom you spoke with, when, and what they said, along with documents or screenshots showing what happened. See the CFPB's current documentation checklist.
What ordered process should you follow from evidence to report?
Use the same sequence whether the call claimed to be from a bank, government agency, utility, employer, family member, or technical-support company. Expand the payment and identity steps only when they apply.
- End contact and protect what still exists Stop replying, do not call the displayed number back, and avoid links or remote-access instructions while leaving the call log, voicemail, and related messages intact.
- Capture the call identifiers Save the receiving number, displayed caller ID, callback number, exact date and time, duration, voicemail, and screenshots that preserve the surrounding context.
- Write a factual timeline Record what the caller claimed, requested, threatened, or promised, what you disclosed, what actions you took, and which details are exact records versus memory.
- Preserve payment and account records Keep receipts, transaction identifiers, statements, gift cards, messages, email headers, website addresses, and any security alerts without exposing them in public posts.
- Act through trusted channels Contact the bank, card issuer, payment service, gift card company, carrier, or affected organization using contact details you independently verify.
- File reports and retain confirmations Choose the FTC, FCC, IC3, IdentityTheft.gov, local police, or another appropriate channel, then save the report number, submission copy, date, and follow-up notes.
The order is deliberate. Evidence can disappear, but financial or account harm can also continue. Capture the few unstable records first, then act. Do not spend hours formatting screenshots before contacting the payment provider.
Where should you report the call, and what should you keep afterward?
Choose the channel based on harm and subject, not on a promise that one agency will recover money. ReportFraud.ftc.gov is the broad federal route for consumer scams and losses. DoNotCall.gov has a streamlined path for unwanted calls when no money was lost. The FCC accepts unwanted-call, text, and spoofing complaints, but states that it does not resolve individual unwanted-call complaints; it uses the information for policy and possible enforcement. The FCC explains the scope of its complaint process.
IC3 is relevant when the scheme involved internet communication, online accounts, payment apps, cryptocurrency, malicious sites, or other cyber elements. IdentityTheft.gov is the recovery route when identity data was exposed or misused. Local police may be appropriate for a local crime, threats, or when a bank or insurer requests a report. A state attorney general may accept consumer-fraud complaints. The CFPB points consumers to the FBI, FTC, state attorney general, or local police and warns them to use independently verified contact information. See the CFPB's current scam-reporting overview.
After every submission, save:
- A copy or PDF of what you submitted.
- The confirmation or report number.
- Submission date, time, and channel.
- The agency or company name and verified contact route.
- The name or identifier of any representative.
- Promised next step or stated review period, quoted accurately.
- Any request for more documents and what you sent.
- The outcome or closure notice.
Do not assume silence means the report failed. The FTC says it cannot respond to every unwanted-call report, while the FCC says individual unwanted-call complaints are not resolved one by one. Those limitations should shape expectations, not stop accurate reporting. The FTC describes how reports support call blocking and enforcement analysis.
FAQ
Should I delete a scam voicemail after reporting it?
No. Export or otherwise preserve the original voicemail and keep a separate working copy. A report confirmation is not a substitute for the recording, and an investigator or payment provider may ask for the original later.
Is a screenshot of caller ID enough evidence?
No. A screenshot proves what your phone displayed, not who placed the call. Save it with the date, time, receiving number, callback number, voicemail, messages, payment records, and your factual timeline.
Should I record the scammer if they call again?
Do not re-engage just to make a recording. Another conversation creates more risk and gives the scammer another opportunity to apply pressure. Preserve an existing voicemail or device-made recording instead.
Where should I store scam-call evidence?
Keep originals in a secure location you control, make a backup, and use a working copy for reports. Restrict access because the files may contain account details, identity data, or private communications.
What if I already blocked the number or cleared the call log?
Write down what you still remember, check voicemail, messages, carrier records, payment accounts, email receipts, cloud photo backups, and reports you already filed. Label recalled details as memory rather than presenting them as exact records.
Does saving evidence guarantee that I will recover money?
No. Good records can support a report, a fraud review, or an investigation, but they do not guarantee recovery. Contact the payment provider immediately because speed and the payment method affect what may still be reversible.
Conclusion
Save evidence that identifies the communication, the demand, your response, and any resulting payment or account change. Keep the original voicemail, call log, messages, receipts, and security alerts, then connect them with a factual timeline. Label caller ID as displayed information rather than verified identity.
Act before the folder is perfect. Contact financial providers and secure affected accounts through independently verified routes, file the report that fits the incident, and keep every confirmation with the original records. Careful documentation cannot promise recovery, but it gives each reviewer a clearer account and prevents avoidable evidence loss.
Sources
- Federal Trade Commission: Phone Scams
- Federal Trade Commission: What To Do if You Were Scammed
- Federal Trade Commission: National Do Not Call Registry FAQs
- Federal Communications Commission: Unwanted Calls/Texts Complaints
- FBI Internet Crime Complaint Center: FAQ
- FBI Internet Crime Complaint Center: Cryptocurrency
- IdentityTheft.gov: Recovery Steps
- Consumer Financial Protection Bureau: Scam or Fraud Help
- Consumer Financial Protection Bureau: Sending Money Problems
- USAGov: Report a Crime
- Google Phone Help: Check and Share Voicemail