No contact discovery and spam
What this criterion guarantees: Nobody can find you or reach out to you unless you want them to.
Without it: Anyone who knows your number can contact you: spam, phishing and, in the worst cases, attacks that require no action on your part.
At a glance
• Olvid — ✅ Good
• Signal — 🟠 Partial
• WhatsApp — ❌ Poor
• Telegram — ❌ Poor
• Matrix-based — ❌ Poor
• SimpleX — ✅ Good
• Threema — 🟠 Partial
Many online scams rely on a seemingly harmless capability: being able to send a message to anyone. Spam is its most visible manifestation. But this capability also makes targeted attacks possible, such as phishing, where the attacker impersonates a trusted identity, and “CEO fraud,” where they typically pose as an executive to get an employee to make an urgent wire transfer. Email illustrates the problem perfectly: anyone can write to anyone, and everyone sees it every day in their inbox. A secure messaging app should protect its users from these attacks, and that protection starts with a design choice: whether or not to let a stranger reach you.
What is contact discovery?
Most messaging apps make it possible to find a user from an identifier, such as a phone number or a username. This is what is known as contact discovery. It provides an answer, convenient at first sight, to the question: how do you get in touch with someone? It is one of the reasons why some messaging apps collect your phone number and ask for access to your address book, as we saw in the minimal personal data criterion. But this discovery capability inevitably exposes you, since anyone can then find you and reach out to you without your consent.
Three independent protections
Against a malicious stranger, a messaging app can put up three barriers, independent of one another:
- no discovery: the attacker cannot find you; first contact can only happen if you initiate it;
- contact-request confirmation: nothing can be sent to you until you have accepted the connection;
- end-to-end authentication: you know for certain who is reaching out to you, which prevents impersonation.
The following table shows how these barriers combine, and what their absence allows:
| Messaging app | Contact discovery | Contact-request confirmation | End-to-end authentication | Risks |
|---|---|---|---|---|
| yes | no | no | Zero-click attacks, very easy social engineering, spam. | |
| Signal | yes | yes | no | Very easy social engineering, spam. |
| - | yes | yes | yes | Social engineering possible but complex, invitation spam. |
| Olvid | no | yes | yes | Social engineering even more complex (the target user must initiate the invitation), no spam. |
The row with “yes” in all three columns matches no solution in this benchmark: Olvid is the only one to offer end-to-end authentication, and it offers no discovery. It nevertheless shows that even end-to-end authentication is not enough. As long as a stranger can reach out to you, invitation spam and social engineeringarchived remain possible. The absence of discovery is therefore a protection in its own right, which overlaps with none of the others.
The extreme case: zero-click attacks
When the messaging app additionally allows content (messages, attachments, calls) to be sent directly to someone who has accepted nothing, merely being reachable becomes a technical entry point. That content is indeed processed by the application before any action by the user: decompressing an image, generating a preview, handling an incoming call, etc. A flaw in any of these steps is then enough to compromise the phone without the victim having to do anything, not even open a message: this is what is known as a zero-click attack. This kind of attack does happen in practice. In 2019, a flaw in WhatsApp’s calling featurearchived allowed the Pegasus spyware, from the company NSO Group, to be installed through a simple WhatsApp call, even one left unanswered. The vulnerable code ran before the call was picked up. The only prerequisite was knowing the target’s phone number. WhatsApp attributed these attacks to NSO Group and took legal action. In 2025, a US federal jury found NSO Group liablearchived for the targeting of about 1,400 users, among them journalists, lawyers and human rights defenders.
A deliberate trade-off
The absence of discovery comes at a cost, since a user cannot be found from their number or their name, and first contact must go through an exchange initiated by the person you want to reach, or through an introduction by a mutual contact. It is a trade-off of the same kind as those already encountered in the analysis of other criteria: a little less convenience, in exchange for the outright removal of an attack surface.
The risk of mass enumeration
Independently of the risk of attacks and spam, the existence of a contact discovery mechanism also exposes all the users of a messaging app to the possibility of mass enumeration. A 2020 studyarchived, conducted by a team of security researchers and covering WhatsApp, Signal and Telegram, showed that all three allowed an enumeration of their entire user base. One might have expected the problem to be solved five years later, but a new 2026 studyarchived shows that it was still present at WhatsApp in 2025: the researchers were able to enumerate the accounts of all three billion users, and to access their phone number, first and last name, profile picture and “about” text.
Applying this criterion
A messaging app gets a ✅Good if it puts up two barriers against a stranger: no discovery (nobody can find you from an identifier) and contact-request confirmation (no content reaches you until you have explicitly accepted the connection). A solution that puts up only the first of these barriers, and therefore lets a stranger reach out to you as soon as they know your identifier, for lack of contact-request confirmation, gets a 🟠Partial; for this first barrier, it does not matter whether being undiscoverable is the application’s native behavior or the result of a setting, as long as the protection is then complete. The reverse is not true, since contact-request confirmation alone, without the absence of discovery, does not improve the result, the connection request already being a solicitation, all the more so when it carries a text chosen by the stranger.