What one bank debit SMS actually contains
The technique
The alert is the bank's receipt, not the app's
People treat the payment app as the record because it is where they tapped. The app initiated the payment; the bank moved the money, and only the bank's alert exists for every debit whatever caused it.
Here is an illustrative alert of the kind Indian banks send for a UPI debit. Wording varies by bank; the fields barely do.
XX-BANKNM: Rs 349 debited from A/c XX4821 on 25-09-26 to VPA freshbasket.shop@bankhandle. UPI Ref 426812345678. Avl Bal Rs 18,452. Not you? Report to your bank.
The sender ID is a registered header, not a phone number; the part after the hyphen identifies the sender. A ten-digit mobile number claiming to be your bank is not a bank alert. Then the verb, which matters more than it looks: debited, spent and withdrawn mean money out; credited means money in; eligible, pre-approved and offer mean nothing happened. The account is masked to four digits.
The counterparty varies most. For UPI it is the payee's virtual payment address; for a card, the merchant name as the network carries it, often cut short; for an auto-debit, the mandate holder. Then the date, a reference (for UPI a 12-digit number that also appears in any email alert for the same payment) and, in many formats, the balance after the debit.
- Sender
- XX-BANKNM, a registered header
- Event
- debited
- Amount
- ₹349
- Account
- XX4821
- Counterparty
- freshbasket.shop@bankhandle
- Date
- 25-09-26
- Reference
- 426812345678, 12 digits
- Balance after the debit
- ₹18,452
Illustrative format. The sender, address, reference and balance are invented. Field order and wording differ between banks, and some banks leave the balance out.
- Five of the six things a tracker needs arrive in every alert. The sixth, what the payment was for, is worked out from the counterparty field
- The balance field lets a tracker test its own completeness, which no payment app history can do






