RCS brings modern features such as photos, high-quality video, read receipts, and group chats to your phone’s messaging app. However, seeing “RCS chat” on the screen does not mean every conversation has the same level of security. The first rule of safe use is to assess three things separately: which protocol is carrying the message, whether it is end-to-end encrypted, and whether the other party really is who they claim to be.
Identify the type of conversation first
Eligible RCS conversations between two people using Google Messages can be automatically upgraded to end-to-end encryption. In such a conversation, a lock icon appears near the text field or send button. This protection is designed to prevent intermediaries from reading message content as it travels from the sender’s device to the recipient’s device. If the lock is not visible, the message may be sent as SMS or MMS; the other person may have RCS turned off, be disconnected, or be using an incompatible messaging app.
Business chats involve another important distinction. A verified business profile indicates that a provider has checked the identity of the organization sending the message; it does not indicate that the content is end-to-end encrypted. According to Google’s documentation, verified RCS business conversations may be processed by the business, its messaging solution provider, or the carrier. Read the check mark as “This company’s identity has been verified,” not as “No one can see the content on this channel.”
Check the lock icon before a transaction
There is no need to inspect every message separately in an everyday conversation. Before sharing password-reset information, a private document, an address, or financial details, however, checking the conversation header and send button is a good habit. If you see a warning that the conversation has switched to SMS, stop before sending sensitive content. You can wait for RCS to reconnect or use another encrypted channel approved by your organization.
Encryption does not prove that the recipient is trustworthy. A scammer can also use encrypted RCS on their device. Separately assess behavioral warning signs such as pressure to act quickly, demands for secrecy, requests for gift cards or money, and unexpected files or links. If someone you know makes an unusual request, call them back using their saved number rather than a number shown in the chat.
Verify keys for important contacts
On eligible devices, Google Messages lets you verify a contact’s key. This process checks whether the encryption identity displayed to you matches the one shown to the other person. It is particularly useful for long-term business partners, family members, or people with whom you share sensitive information.
Open the conversation and go to the encryption verification option in the details section. Compare the displayed code with the other person face to face or during a previously verified phone call, not through the same message conversation. On supported devices, you can also use the system key verifier and a QR-based process. The absence of this feature does not necessarily mean the conversation is unsafe; support may depend on the app version, Android version, and device type.
A person changing phones or reinstalling the app may cause the key to change. Do not treat such a change by itself as evidence of an attack, but repeat the verification before continuing a sensitive conversation. Do not verify the new key through an unknown link in the old conversation.
Set safe boundaries for business messages
A verified business profile is a useful signal, but it should not be your only check for payments and account transactions. Instead of tapping a link in the message, open the bank’s, shipping company’s, or retailer’s official app that you previously installed. Do not send a one-time verification code, card PIN, online banking password, or photo of your ID to a chatbot. If a sender you believe to be a legitimate organization requests these details, stop the transaction and call the number published on the organization’s official website.
Read receipts are also a privacy preference. When you read a business conversation, the other party may receive a read notification. If you do not want this, turn off read receipts in the RCS settings. Because replying in a spam conversation may reveal that your number is active, use the block and report-spam tools instead of responding.
The five-minute security check
Update the messaging app and the Carrier Services component, if present. Check the RCS connection status in Google Messages settings and make sure an old or unused number is not still connected. Enable spam protection, but remember that the filter may not catch every harmful message. Verify the keys of people with whom you share highly sensitive information through a separate channel. Finally, show family members that the lock icon and the verified business badge mean different things.
You do not need to disable RCS entirely to use it safely. The right approach is to make three questions a habit: Is the message currently being sent through RCS or SMS, does the conversation show an end-to-end encryption indicator, and can I independently verify the request from the person or organization shown on the screen? These distinctions prevent a false sense of security while allowing you to benefit from useful new features.<figure class="article-inline-image"><img src="/api/media/019ffc1f-1b87-70ce-8c45-2b8636c2bc28?v=9342" alt="Close-up of a person checking the secure chat indicator on a smartphone" width="1200" height="675" loading="lazy"></figure><figure class="article-inline-image"><img src="/api/media/019ffc1f-1be8-7e22-bdaa-21350bf060ac?v=8308" alt="Two users holding their phones side by side to verify a contact" width="1200" height="675" loading="lazy"></figure>