What this category covers

This section explains what security and verification tools are used for: the one-time codes, CAPTCHA challenges, authenticator apps, PINs and encryption terms you meet while trying to log in, pay for something or prove who you are.

Most people arrive here mid-task. A code has arrived and it is not clear why, a site is asking you to identify traffic lights, or a bank message uses a word you have not seen before. Each guide answers the immediate question first and then explains where that step fits into keeping an account safe.

One rule runs through every guide in this section, and it is worth stating before you read any of them.

Nobody legitimate will ever ask you for a one-time code, a PIN or a password. Not your bank, not a delivery company, not a government department, not a colleague, and not anyone from “the fraud department”. A request for one of those is the fraud.

That single sentence prevents more losses than any technical control. If you take nothing else from this section, take that.

Browse by topic

Most searched questions

How to choose the right guide

If a code has just arrived and you did not request it, read the OTP guide first. An unexpected code usually means somebody is trying to get into your account with a password they already have — which means the password needs changing, not the code sharing.

If a website is blocking you with a challenge, start with the CAPTCHA guides. If you are trying to make an account harder to break into, the two-factor and authenticator guides are the right place. And if you have met an unfamiliar term in a bank or government message, the verification basics section defines the vocabulary without assuming technical background.

Safety, accuracy and South African context

South African readers face a specific and well-documented pattern: SIM-swap fraud, SASSA and bank impersonation, and WhatsApp account takeovers that begin with a “wrong number” message asking you to forward a code.

The practical defences are unglamorous and effective:

These guides never ask you to enter, forward or confirm a code, and they will not tell you it is acceptable to share one under any circumstance. Where a guide describes how a security feature works, it follows the official documentation of the service concerned.

Related UsedFor categories

Frequently asked questions

I received a code I did not ask for. What does that mean? Usually that someone is attempting to log in as you. Do not share or enter it. Change that account’s password, and switch on two-factor authentication if it is not already on.

Is an authenticator app safer than SMS? Generally yes. Authenticator codes are generated on your device and are not exposed to SIM-swap fraud or message interception.

Can my bank ever ask for my OTP? No. Neither can SASSA, SARS, a courier, or an employer. There is no legitimate exception.

Why do CAPTCHAs keep appearing? Often because of a VPN, an unusual network or heavy traffic from your connection. It reflects how the site scores the request, not something wrong with your device.

Does encryption keep me safe from scams? No. Encryption protects data in transit. It does nothing about a person persuading you to hand over a code, which is how most losses actually happen.