Ask the internet whether your phone is tapped and you get a checklist that has barely changed since the 1970s: listen for clicking, watch for the screen lighting up on its own, dial a secret code to reveal the truth.
Nearly all of it is wrong, and being wrong about this is not harmless. People conclude they are safe because they heard no clicking, or panic over a dial code that was showing them something entirely ordinary. Here is what each belief is actually worth.
Myth: you can hear it
The belief: clicking, echoes, static or beeping during calls means somebody is listening.
The reality: this is a genuine memory of analogue telephony, where a physical tap on a copper line could produce audible artefacts. Nothing about a modern call works that way. Your voice is digitised, compressed, packetised and reassembled. Interception happens by copying data, and copying data makes no sound.
What actually causes those noises: codec switching, a weak signal, the handover between cell towers, VoIP jitter, Bluetooth interference, a failing handset microphone.
Worth: nothing at all as evidence.
Myth: a dial code will reveal it
The belief: dialling a sequence such as star-hash-21-hash tells you whether your phone is tapped.
The reality: these are real GSM codes, and they do real things — just not that. The main ones:
- Star-hash-21-hash shows unconditional call forwarding: whether calls are being diverted before they reach you.
- Star-hash-62-hash shows where calls go when your phone is unreachable.
- Star-hash-67-hash shows forwarding when you are busy.
- Hash-hash-002-hash clears all forwarding rules.
- Star-hash-06-hash displays your IMEI, the handset's serial number.
Call forwarding is worth checking. Somebody who had your phone could have set a divert, and that is a real, if crude, interception method. But a forwarding rule is not a wiretap, and an empty forwarding list does not mean nobody is listening. The codes say nothing whatsoever about software on the phone, about your accounts, or about interception at the network.
Worth: mildly useful for one narrow thing. Useless for the question people ask them.
Myth: the screen lighting up means something
The belief: a phone that wakes by itself, restarts, or shows odd characters is being controlled.
The reality: phones wake for notifications, background refresh, incoming silent pushes and ambient display features. Restarts happen after updates and on ageing hardware. Strange characters in a message are usually encoding problems.
There is one historical exception worth knowing: certain attacks have used specially crafted silent messages. But you would not see those, which is exactly the point — the visible weirdness is the ordinary kind.
Worth: close to nothing on its own.
Myth: battery and heat prove it
Covered at length in how to tell if your phone is hacked. A two-year-old battery produces identical symptoms. Worth noticing if it changed abruptly on a newish phone; never a verdict.
Myth: an app can tell you if your phone is tapped
The belief: install a detector and it will tell you.
The reality: on iPhone, no app can scan the system at all — the sandbox forbids it. On Android an app can see more, but nothing on the phone can see interception that happens at the network, because there is nothing on the phone to see.
Apps marketed specifically as wiretap detectors are among the emptiest products in the store. Anti-stalkerware tools that check permissions and installed packages are genuinely useful — but they are looking for software, which is a different question.
Worth: nothing for tapping. Something for stalkerware, if it is honest about which it does.
What is actually true
Lawful interception leaves no trace on your phone
This is the single most important fact in this article, and the least known.
When a law enforcement agency intercepts communications with legal authorisation, it is generally done at the carrier, in the network, not by putting anything on your handset. The phone is not modified. There is no app, no battery drain, no clicking. Nothing you can run on the device will detect it, because nothing about the device changed.
So if your question is "is my phone tapped by the police", the answer is that no checklist on the internet can tell you, and any product claiming otherwise is selling a fantasy. That is not a comfortable answer. It is the true one.
What you can actually detect
Software on the phone. Stalkerware and mercenary spyware do leave traces: permissions, configuration profiles, packages, crash logs, network artefacts. This is detectable, and it is what most people asking about tapping are genuinely experiencing. See Android and iPhone.
Call forwarding. Check it with the codes above. Crude, real, and occasionally what is going on.
Account access. Someone reading your iCloud or Google backups gets your messages without touching your phone. Check your account device lists and recovery addresses.
Linked messaging devices. WhatsApp, Signal and Telegram all support linked devices that stay connected indefinitely. Check that list. It is one of the most common real interception routes and it needs nothing installed on your phone.
SIM swapping. If your service drops unexpectedly and does not come back, that can mean your number was ported to somebody else's SIM. That is urgent: contact your carrier immediately.
What only external analysis can reach
Everything above can be checked from the phone. The limit is structural: a compromised phone is being asked to report on itself, and sophisticated software can lie.
Analysis from a computer over a cable examines the phone's own data — backups, diagnostic logs, network artefacts — without depending on the phone's cooperation. That is how the researchers who publish this work operate, and it is what Haris Shield does.
A realistic checklist
- Check call forwarding with the codes above.
- Check linked devices in every messaging app you use.
- Check your Apple ID or Google account: devices, recovery email, recovery phone.
- Check the permission screens: Accessibility, notification access and device admin on Android; configuration profiles on iPhone.
- Do an external scan from a computer if you want more certainty than the phone can give you.
- Ignore clicking, screen wake-ups and dial-code folklore entirely.
The short answer
You cannot hear a tap. No dial code detects one. No app finds one. Lawful interception happens in the network and leaves nothing on your handset to find.
What you can detect is software on the phone, call forwarding, account access and linked messaging devices — and those, not wiretapping, are what nearly everyone asking this question is actually experiencing.
Sources
- Electronic Frontier Foundation, Surveillance Self-Defense: ssd.eff.org
- Coalition Against Stalkerware: stopstalkerware.org
- Amnesty International Security Lab, Mobile Verification Toolkit: mvt.re