When a sweeper we'll call Dana saw a Facebook post offering a $500 patio set from a regional garden-center chain she shopped at twice a year, her group chat did what group chats do: "Scam." "They always are." "Report it and move on." What none of her friends did — and what Dana did in about six minutes — was verify the promotion through channels that live outside Facebook entirely. She never inspected a badge or a page-creation date. She used a phone and her own eyes. Three weeks later she was loading a bistro table into her trunk. ☎️

She called the store and asked a human

Dana's first move wasn't online at all. She pulled the garden center's number from its Google Business Profile — the listing that shows hours and directions, which a Facebook impostor has no control over — and dialed the actual store, not any number printed in the post. When a real employee picked up, she asked plainly: "Are you running a $500 patio-set giveaway on your Facebook page right now?" The clerk laughed and said yes, it was the manager's summer promotion, and entries closed Friday. That thirty-second call did what no amount of screenshotting could: it confirmed the promotion existed against a phone line the scammer couldn't answer.

This works because a cloned page can copy a logo in seconds but can't reroute a business's real phone. If the store had said "we're not running anything like that," Dana would have known instantly the post was a fake riding on the brand's name. The trick is sourcing the number independently — from Google Maps, a prior receipt, or the sign on the building — rather than trusting a phone number the post itself hands you, since a scam post will happily list a line that rings straight to the fraudster.

She read the comments like evidence, not decoration

Most people scroll past the comment section; Dana read it like a case file. Under a real local giveaway, the replies come from recognizable neighbors — accounts with years of history, profile photos, and posts about the same town — and many of them tag a friend ("@Marcy we need this!"). Just as telling, the brand itself replies to ordinary questions in the thread: someone asks about store hours or whether the cushions are weatherproof, and the page answers like a business that actually runs the account. That mundane back-and-forth is almost impossible to fake at scale.

A fraudulent clone reads completely differently, and Dana knew the pattern. Scam threads are either locked so no one can comment, or they're carpeted with generic "Congrats, you're our winner!!" replies from empty accounts posted minutes apart, with zero genuine customer questions and no real answers from the page. This giveaway had none of that — it had a woman debating between the gray and the beige set, and the store weighing in. The presence of real, boring, on-topic conversation was Dana's strongest signal that a real business was behind the post.

Her real edge: she was already a customer

Here's what separated Dana from her doubting friends — they were strangers to the brand, guessing from the outside, while she had a relationship to measure against. She was on the store's email list and had a loyalty account, so she knew what their real messages looked like: the sender domain, the tone, the logo. When the win notice arrived, it came from that same familiar address and matched the branding she'd seen in a dozen prior emails, not a lookalike Gmail.

Being an existing customer turned verification into simple pattern-matching. A prize alert only feels suspicious when you have nothing authentic to compare it to; Dana had a whole history. Her friends called it a scam because to them every message from the brand looked equally unfamiliar — so a fake and a real one were indistinguishable. Dana could tell them apart because she'd been paying attention to the genuine article all along.

Skip the badge-squinting: call the store on a number you found yourself, read the comments for real neighbors, and trust the brand you already know.

This is an illustrative composite, not a specific real person.