Digital safety 101 – Why an IMEI check is your first line of defense

Last Updated on 3 September 2026

Most digital-safety advice focuses on software: strong passwords, two-factor authentication, keeping apps updated, avoiding phishing links. All of that matters, but it assumes one thing that doesn’t always hold up – that the hardware itself is trustworthy. A phone with a hidden history, whether that’s a theft report attached to it or an ownership lock still tied to a stranger, undermines every software-level precaution built on top of it. Before any of the usual digital-safety steps apply, there’s a more basic one worth doing first: checking the phone’s IMEI.

What an IMEI actually is

Every device that connects to a cellular network – phones, cellular tablets, some IoT hardware – carries an IMEI: International Mobile Equipment Identity, a 15-digit number assigned at the point of manufacture. It’s not the SIM card and it’s not tied to any account; it identifies the specific physical unit, the way a VIN identifies a specific car. The number has a defined structure under the 3GPP standard (TS 23.003): the first eight digits form a Type Allocation Code (TAC), issued by the GSMA and identifying the manufacturer and exact model; the next six digits are a serial number unique to that individual device; the final digit is a check digit, calculated with the Luhn algorithm, used to catch transcription errors. Because the IMEI is embedded in the hardware at manufacture, it isn’t meant to change – a device with a mismatched or altered IMEI is itself a red flag worth taking seriously.

Retrieving the number takes seconds: dial *#06# on virtually any GSM, UMTS, LTE, or 5G device, and it displays instantly. It’s also listed under Settings > About Phone, and printed on the SIM tray or original packaging.

The three things an IMEI check reveals

Blacklist status. When a device is reported lost, stolen, or associated with fraud or an unpaid balance, its IMEI can be flagged in a shared blacklist database. In the US, participating carriers report into a common industry-wide system. A number of other countries run centralized, often government-linked registries for the same purpose – India’s CEIR (Central Equipment Identity Register) is a well-documented example – and the GSMA operates a broader international IMEI database that lets participating carriers around the world exchange blacklist data. This is why a device stolen in one country can end up refused service somewhere else entirely. A blacklisted device is blocked from cellular calls, texts, and mobile data on participating networks, regardless of which SIM is inserted – though it typically still connects over Wi-Fi, which is precisely why the restriction often isn’t obvious until after a purchase.

Carrier lock. A separate, generally less serious issue: the device may be restricted to SIMs from one specific carrier. This doesn’t indicate theft and is often resolvable once conditions like a completed payment plan are met, but it’s still worth knowing before a purchase.

Activation lock (Apple devices). iPhones and iPads with Find My enabled remain tied to the original owner’s Apple ID even after a factory reset, unless that owner explicitly removes the device from their account. A secondhand iPhone still in this state is largely unusable to a new owner – a meaningful theft deterrent when it’s your own device, and a dealbreaker when you’re the one buying.

Why hardware-level checks belong in a digital-safety routine

Standard digital-safety advice tends to start after the point of purchase: set a strong passcode, enable biometric lock, turn on automatic updates, review app permissions. All useful, but a device’s history predates all of it. A phone still carrying a previous owner’s Apple ID lock, for instance, isn’t a security problem software settings can fix – it’s a hardware-and-account-level issue that has to be resolved by the previous owner before the new one can secure the device at all. Similarly, a blacklisted phone isn’t a risk to data or privacy in the way malware is, but it represents a purchase that fails at the most basic level: the device may simply stop functioning as a phone.

Building the IMEI check into a pre-purchase routine – alongside checking a seller’s history and inspecting the device itself – closes the one gap that purely software-focused advice doesn’t cover.

Running the check

The process takes about two minutes and doesn’t require installing anything. Enter the 15-digit IMEI into a lookup tool such as imei.info, and it returns the confirmed device model and specifications (useful for verifying a listing is accurate), blacklist status, and, for Apple devices, activation lock status – typically within seconds, at no cost, with no account required.

IMEI versus serial number

These two numbers are often confused because both appear on the same settings screen. The serial number is manufacturer-assigned (each brand uses its own format) and mainly used for warranty and repair tracking. The IMEI is the network-standard identifier that carriers and blacklist databases actually check against. An IMEI-check tool specifically needs the 15-digit IMEI – entering a serial number instead is the most common reason a lookup returns no result.

A basic pre-purchase checklist

Get the IMEI directly from the seller, ideally read live via *#06# on a video call rather than sent as text ahead of time.

Run the IMEI check before agreeing to any payment method.

Confirm the device model and specs returned by the check match the listing.

For iPhones specifically, confirm activation lock is off before proceeding.

Keep a record of the IMEI after purchase, in case of a future dispute or in case the device is later lost or stolen.

Frequently asked questions

Can an IMEI check detect malware or spyware on a device? No. It only reports network-registered status – blacklist flags, carrier lock, and Apple activation lock. Malware detection requires separate security software and has nothing to do with the IMEI system.

Is it possible to check an IMEI without physical access to the phone? Yes, as long as you have the 15-digit number itself, which a seller can provide by dialing *#06#, reading it from settings, or sending a photo of the SIM tray or box label.

Does a clean IMEI check mean a device is completely safe to buy? It rules out the specific issues the check covers – blacklist status and lock status – but it doesn’t verify physical condition, battery health, or confirm the seller is who they claim to be. It’s one part of a broader due-diligence process, not a replacement for the rest of it.

Are IMEI blacklist databases global and unified? No. Blacklist status depends on which carriers and national systems participate in shared reporting. The GSMA’s international IMEI database and regional systems like India’s CEIR extend coverage significantly, but a device flagged in one country’s system isn’t guaranteed to be flagged everywhere, which is one more reason to run the check directly rather than assume a “clean” result means the same thing in every market.

The takeaway

Digital safety usually starts with the assumption that the device itself is a clean slate. An IMEI check (https://www.imei.info/) tests that assumption directly, for free, in about two minutes, before any password policy or security setting even comes into play. It’s a small, low-friction step – and one of the few in digital security that requires no technical background at all.