Signal Safety Numbers: How to Know You're Talking to the Right Person
Published: October 7, 2026 Updated: October 8, 2026
Signal encrypts every message, but encryption has a quiet assumption: that the keys on the other end belong to the person you think they do. A safety number is how you check that assumption. It is a fingerprint of the encryption keys behind one conversation. Compare it with your contact, and you know nobody is sitting in the middle. This guide explains what it is, how to verify it, what a changed number means, and how to think about it without paranoia.
from Signal's official site file hosted by Signal, not by us
What a safety number is, in plain words
Every Signal conversation runs on encryption keys. Your phone holds private keys; the other person's phone holds theirs. A safety number is a fingerprint derived from both sets of keys: a long string of digits, shown in groups with a QR code, that is unique to your conversation with that specific person on their specific device.
The logic is simple: if the fingerprint matches on both phones, the keys match, and the encrypted tunnel runs between exactly the two of you. If someone had swapped in different keys in the middle, the fingerprints would not match. You would know.
Three facts that keep this grounded:
- It is per conversation, per device. Your safety number with Ali is different from your safety number with Sara, and it changes if either of you switches phones. It is not one number for your whole account.
- Verification is one-sided. Marking a contact verified applies on your phone only. It is your private note that you checked. Your contact has to do their own check on their phone.
- A checkmark means "I checked." Once verified, a checkmark appears by the contact's name in the chat header. It stays until the number changes or you clear it. It is a memory aid for you, not a badge the other person earns.
What the safety number protects you from
The attack has a name, man-in-the-middle, and a simple shape. When you message someone, your app asks Signal's servers for that person's public key and encrypts to it. If an attacker could slip their own key into that directory lookup, your messages would still be "encrypted". They would just be encrypted to the attacker, who reads them and passes them along. You would never notice from inside the chat.
That is what the safety number defeats. The fingerprint is computed from the actual keys on the actual devices. An attacker substituting keys cannot also forge a matching fingerprint on your contact's real phone. A comparison exposes the mismatch.
Now the honest calibration: this is a very advanced, very unlikely attack. It requires compromising Signal's key directory infrastructure or a privileged insider. That is not the kind of thing that happens to random users. Signal's engineers describe it that way themselves. Safety numbers exist for the people who cannot afford "unlikely": journalists with sensitive sources, activists under surveillance, anyone whose threat model includes a capable, motivated adversary. For everyone else, it is a two-minute check that buys certainty about one conversation. Worth doing for the contacts that matter; not worth losing sleep over.
How to view a safety number
Open the conversation
Open your one-to-one chat with the contact. Safety numbers are per conversation, so start from the right chat.
Open the chat settings
Tap the chat header at the top, or open the overflow menu (the three dots) and go into the chat settings.
Select View Safety Number
You will see the numeric fingerprint in groups, plus a QR code representing the same number.
That is the whole procedure. There is nothing to configure and nothing to enable. Every conversation has a safety number whether you look at it or not.
How to verify it with your contact
Viewing the number proves nothing by itself. Verification means comparing what you see with what your contact sees, through a channel the attacker does not control. In order of reliability:
- Best: scan in person. Open both phones side by side, view the safety number on each, and scan your contact's QR code with your camera. If it matches, you are done. No network involved, nothing to intercept. This is the method Signal's own support page recommends first.
- Good: compare out loud on a call. Read the groups of digits to each other over a voice or video call. Tedious for a long number, but the voice itself authenticates who you are talking to.
- Good: compare visually over a trusted channel. Use the share button to copy the number and send it through a different channel you already trust. Think about which channel that is. Comparing over the same chat you are trying to verify is circular: if the chat were compromised, the "confirmation" would be too.
When the numbers match, tap Mark as verified. The checkmark appears in the chat header by their name. Your contact should do the same on their phone. Remember, verification is one-sided: a checkmark on your phone says nothing about whether they checked.
If the numbers do not match, stop and think before you panic: the overwhelmingly common cause is that one of you is looking at a stale number, or you are comparing with the wrong device. Re-check that you are both viewing the current number for the current conversation, then compare again carefully.
What it means when a number changes
Signal notifies you when a contact's safety number changes. A changed number means exactly one thing technically: the encryption keys on one end are different from before. What that means in human terms is a short list, ordered by likelihood:
| Likely cause | What it means |
|---|---|
| They got a new phone. | New device, new keys, new safety number. The most common cause by far. |
| They reinstalled Signal. | Reinstalling generates fresh keys, which changes the number, even on the same phone. |
| They re-registered their number. | Number changes and re-registrations rotate keys too. |
| Something malicious. | Key substitution by an attacker also changes the number. This is the case the whole system exists to catch. It is also the rarest by orders of magnitude. |
The emotional mistake is treating every change alert as an attack. The security mistake is treating every change alert as routine. The correct response is a 30-second check, not panic and not dismissal. That is what the next section is for.
Changed number? Run this checklist
When the "safety number changed" notice appears, work the list top to bottom. Most cases resolve at step one.
Ask your contact what changed
Message them (on Signal is fine for the question itself) and ask: new phone? Reinstalled the app? Changed numbers? Nine times out of ten the answer is yes, and the mystery is solved.
Match the story to the timing
"I got a new phone yesterday" plus a change alert today is a coherent story. "Nothing changed on my end" plus a change alert deserves step three.
Re-verify the safety number
View the new number and compare it again: in person if you can, over a trusted channel if you cannot. If it matches, mark it verified and carry on.
If the story doesn't add up, slow down
A contact who insists nothing changed, a number that will not verify, pressure to "just accept it and keep talking": that is when you pause sensitive conversation until you can verify out-of-band. Do not send anything you would not want read by a stranger until the number checks out.
For high-risk contacts, have a plan in advance
If you are a journalist, activist, or anyone with a real adversary: agree beforehand what you will both do when a number changes: which channel you will use to re-verify, and what "pause" means. Deciding under pressure is how mistakes happen.
One more scenario people ask about: you changed phones and now all your contacts see change alerts about you. That is normal. From their side, your keys changed. Tell the people who matter ("new phone, re-verify me when we meet") and the alerts resolve themselves as everyone re-checks.
Good habits if you're actually at risk
Most readers can stop at "verify the contacts that matter." If your work or situation puts you in the small group that needs more, these are the habits security trainers actually teach: proportionate, not paranoid:
- Verify once, at the start. When a sensitive contact relationship begins, verify in person and mark it. One careful check beats ten anxious re-checks.
- Treat change alerts as a to-do, not an alarm. The checklist above is the whole response. Run it the same way every time and you will neither miss a real incident nor burn out on false ones.
- Agree on the out-of-band channel early. "If my number ever changes, I'll call you on this number / we'll meet here to re-check." Write it down somewhere that is not the chat itself.
- Layer it with the basics. Safety numbers verify who; disappearing messages limit how long sensitive content exists; screen lock and screen security protect the device. No single setting is the whole plan.
- Know what verification cannot do. A matching safety number proves you are talking to the holder of those keys. It does not prove the person is who they claim to be in real life, and it does not help if their whole phone is compromised. Verification is one layer, and an important one, but only one.
And the final calibration, because this topic attracts fear: for the overwhelming majority of users, a changed safety number will always turn out to be a new phone. Verify the people who matter, run the checklist when something changes, and get on with your life. That is the entire philosophy: certainty where it counts, calm everywhere else. The encryption explainer covers the machinery underneath if you want the full picture.
FAQ
What is a Signal safety number?
It is a fingerprint of the encryption keys securing your conversation with one specific contact on their specific device. If the number matches on both phones, the encrypted chat runs between exactly the two of you with nobody in the middle.
How do I verify a safety number?
Open the chat, tap the chat header or the overflow menu, open chat settings, and select View Safety Number. Compare it with your contact (ideally by scanning their QR code in person), then tap Mark as verified on your phone.
Why did my contact's safety number change?
Almost always because they got a new phone, reinstalled Signal, or re-registered their number. All of these generate new keys. Ask them what changed; if the story fits, re-verify the new number and carry on.
Should I worry when a safety number changes?
Treat it as a 30-second check, not an emergency. Ask your contact what changed, and re-verify the number if anything is unclear. A genuine attack is possible but extremely rare; a new phone is the usual explanation.
Does the checkmark mean my contact verified me back?
No. Marking a contact verified applies on your side only. The checkmark in your chat header is your own note that you checked. Your contact needs to verify on their phone separately.
Can I verify a safety number without meeting in person?
Yes. Compare the numbers out loud on a voice or video call, or share the code through a different channel you already trust. Avoid confirming over the same chat you're trying to verify. That's circular.
Keep reading
- the machinery underneath: how Signal encryption works
- the protocol in plain language: Signal protocol explained
- verify without sharing your number: Signal usernames
- the complete privacy setup: Signal privacy checklist