Skip to main content

How to Verify a MINDEF Call, SMS or Email

· 8 min read
NSVault Editorial Team
Practical guides for Singapore NSFs and NSMen

An unexpected call, SMS or email that mentions enlistment, a call-up or an account problem can feel too urgent to ignore. That urgency is exactly why verification must happen before you click, reply or disclose anything.

The safest response is not to decide from the caller ID alone. Preserve the contact, open an official MINDEF or CMPB route independently, and ask that channel whether action is actually required.

This guide is unofficial. Current OneNS records, official notices, MINDEF or CMPB replies, and Police or ScamShield instructions override it. The official sources below were checked on 31 August 2026.

Phone beside a verification checklist, shield token and official-contact notebook
Quick version
  • Do not click a link, open an attachment, reply or call back from the message while you are still checking it.
  • Save the number, sender, time, subject line and a screenshot without forwarding sensitive content publicly.
  • Open CMPB, OneNS or MINDEF yourself from a known official address. Do not use the contact details supplied by the suspicious message.
  • MINDEF says it will never ask you to reveal a password or OTP, or ask for bank-account details.
  • A familiar sender name is a clue, not proof. Sender details and caller IDs can be spoofed.
  • If the contact is genuine, complete the task through the independently opened official route.
  • If you disclosed credentials or lost money, act immediately: secure affected accounts, contact the bank where relevant, and follow ScamShield and Police reporting guidance.

Stop Before You Reply

Treat the first minute as a pause, not a verdict.

Do not:

  • tap an embedded link or QR code;
  • open an unexpected attachment;
  • reply with personal particulars;
  • read out a Singpass password, OTP, bank login or card detail;
  • install an app or screen-sharing tool;
  • transfer money to “verify” an account; or
  • call a number supplied inside the same suspicious message.

MINDEF's current scam guidance says not to click links or open attachments in suspected spoofed messages and not to reply. It also states that MINDEF/SAF will never ask for passwords, OTPs or bank-account details.

That boundary is stronger than trying to memorise every legitimate number. A message can include accurate NS terminology and still be fraudulent.

Preserve The Message Without Following It

Keep enough evidence for a useful verification:

  • date and time;
  • displayed sender or phone number;
  • the complete email address and domain, not only the display name;
  • subject line and exact request;
  • any link shown, without opening it;
  • attachment name and extension, without opening it; and
  • a screenshot that does not expose it in a public chat or forum.

MINDEF lists urgent or threatening language, unknown email domains, hidden links and risky attachment types among phishing-email warning signs. Its SMS guidance says MINDEF/SAF no longer sends clickable links in SMS messages.

Do not delete the message until the check is complete. Do not forward an attachment to friends “for testing”. If a report is needed, send only what the official channel requests.

Verify Through An Independently Opened Route

Use a route you found separately:

  1. Type or open the official CMPB, MINDEF or OneNS address yourself.
  2. Check OneNS for the claimed call-up, task or account notice.
  3. Use CMPB's published NS Contact Centre details or its official contact page.
  4. Describe the contact, time and claimed action without sharing passwords or OTPs.
  5. Ask whether the task is genuine and which official channel should be used to complete it.

A useful question is:

“I received a [call/SMS/email] at [time] claiming that I must [action]. I have not clicked or replied. Can you confirm whether this contact or task is genuine and tell me the official route to complete it?”

MINDEF says suspected spoofed SMSes or emails may be reported to the NS Contact Centre with a screenshot for verification. CMPB publishes the current hotline, overseas number and contact@ns.gov.sg on its own contact page.

Avoid relying on a copied contact list from an old forum post. Official hours and routes can change.

What The Sender ID Can And Cannot Prove

Singapore government agencies generally use the gov.sg SMS Sender ID, with a limited set of published exceptions for specific services. MINDEF also warns that sender information can be spoofed.

Use sender details as one check, not as permission to disclose information. A real-looking thread does not make a clickable link safe, and an unfamiliar number does not automatically mean a genuine callback is impossible.

The decisive check is whether the claimed task exists in the relevant official record or is confirmed through an independently opened official channel.

If The Contact Is Genuine

Separate verification from completion.

  • For a SAF100 or call-up, open OneNS or the official acknowledgement route yourself.
  • For a medical, enlistment or administrative request, follow the written instruction confirmed by CMPB, MINDEF or your unit.
  • For a missed call, ask what information may be shared about its purpose and whether a new callback or written instruction will be issued.
  • Record the date, case reference and next step.

Do not complete a genuine task through the original link merely because someone confirmed that a task exists. Use the official route named in the confirmation.

The SAF100 acknowledgement guide covers the separate job of acknowledging a real call-up. If you think an ICT exists but no SAF100 appears, use the missing-SAF100 guide.

If You Already Shared Information

Act according to what was exposed.

Password, Singpass or account credentials

Change the affected password through the real service, review recovery details and active sessions, and enable or reset multi-factor authentication where appropriate. Do not reuse the compromised password elsewhere.

Banking details, card details or money

ScamShield says to contact the bank immediately if an account or card may be compromised or money was lost. Use the bank's official app, website or number, not the suspicious message.

Malicious app or device access

Stop interacting with the scammer. Use another trusted device to secure important accounts if necessary, and follow current ScamShield or Cyber Security Agency guidance for a potentially compromised device.

Report and preserve evidence

ScamShield's current response guide says victims should contact the bank, file a Police report, secure accounts and report to the relevant platform. Keep the message, URLs, numbers, transaction records and steps already taken.

Call the ScamShield Helpline at 1799 if you are unsure whether a contact is a scam. Use 999 for urgent Police assistance.

Common Mistakes

  • Calling back the number in the suspicious message instead of opening an official contact page.
  • Assuming a familiar display name proves identity.
  • Clicking only to “see where the link goes”.
  • Sharing an OTP because the caller already knows your name or NRIC fragment.
  • Posting screenshots with personal, unit or call-up details in a public forum.
  • Treating an absent OneNS record as final proof without asking the official channel.
  • Treating a genuine task as proof that the original link is safe.
  • Waiting after bank or account credentials have already been exposed.

Frequently Asked Questions

How can I tell whether a MINDEF call is genuine?

Do not decide from caller ID alone. Preserve the call details, open CMPB, MINDEF or OneNS independently, and use the official NS Contact Centre or relevant unit route to confirm the claimed task before sharing information or calling back.

Will MINDEF ask for my OTP or bank login?

MINDEF's current guidance says MINDEF/SAF will never ask you to reveal a password or OTP, or ask for bank-account details. End the interaction and verify through an independently opened official route.

What should I do after missing a genuine call?

Use the official contact route to confirm the purpose and next step. If it concerns a call-up or administrative task, check the relevant OneNS record and complete the task through the official channel rather than an unverified callback number.

Official References

Bottom Line

Do not let urgency choose the channel. Pause, preserve the contact, verify the claimed task through a separately opened official route, and complete it there. If credentials or money were exposed, move immediately from verification to account protection and reporting.