Evidence Basics · 10 min read
8 Text Messages That Look Like Evidence—But Usually Aren’t
Patterns we see over and over when message records are reviewed: everyday phrases that trip naive keyword tools and first-pass readers, and how to tell a real signal from a false one.
The short answer
The messages that look most damning at a glance are frequently the ones that fall apart on a second read. Keyword tools flag a word; a person flags a feeling. Both miss context, and both produce false positives that a careful reviewer — or opposing counsel — will take apart. The usual culprits are predictable once you have seen them a few times. Sarcasm and quoted speech read as sincere assertion. A threat-shaped phrase that turns out to be a film line, a lyric, or an old joke between two people. A reply that reads as cold because the message it answers is missing. Timestamps that appear to show a 3am message when the export was written in another time zone. And an apparent admission that is agreement with something not visible in the excerpt. The defence against all of them is identical: read the surrounding messages before treating any line as meaningful, and keep that context attached when the excerpt travels. These are the patterns we see repeatedly when a large message record is reviewed. Each one looks like a signal and usually is not. Reading the surrounding conversation, and checking who is actually speaking, resolves most of them.
1. "You’re dead wrong" (and other "dead" idioms)
A keyword scan for threat language latches onto the word "dead." But "dead wrong," "dead set," "dead serious," and "dead inside" are ordinary intensifiers and descriptions—not threats. In practice this idiom is one of the most common false positives in threat detection: a wall of "you’re dead wrong" flagged as violent language. How to tell: read the next word. "Dead wrong" is an argument; "you’re dead if you come here" is a threat. The verb and the object matter more than the trigger word.
2. Both people keep texting after "leave me alone"
A boundary ("stop texting me") followed by more messages looks like unwanted contact. But if the person who set the boundary keeps replying, restarts the conversation, or re-engages, that is mutual continuation—not one-sided harassment. How to tell: check whether the other participant answered back during the same window. Unwanted contact is one direction continuing after a clear, unretracted boundary; a two-way exchange is a different thing.
3. Money words with no demand
Phrases like "you owe me," "the rent," or "child support" get flagged as financial coercion. Most of the time they are grievances, logistics, or venting—not a demand tied to a threat. How to tell: financial coercion needs a conditional structure—"pay me or I’ll…". A bare mention of money is a topic, not leverage.
4. Quoted, forwarded, or pasted text
Someone pastes a third party’s message, forwards a screenshot, or copies text from another app—now those words appear in the thread under the wrong name. First-pass tools attribute the words to the sender of the message they sit inside. How to tell: look for reply markers, quotation, "he said," or a change in voice. Words a person quoted are not words a person said.
5. "You’re done" and other break-up language
End-of-relationship phrasing—"you’re done," "I’m done," "we’re over"—reads as finality and sometimes as menace. It is almost always about the relationship ending, not a threat of harm. How to tell: "done" points at the relationship; a threat points at a person and an act.
6. Sarcasm and jokes read literally
"Great job, genius" or "yeah, I’ll totally do that" carry the opposite of their literal meaning. Tools and hurried readers score the words, not the tone, and turn a sarcastic jab into an admission or an insult. How to tell: the surrounding messages usually reveal the register. Sarcasm read out of context is one of the easiest findings to lose on challenge.
7. Vague warnings without a stated act
"You’ll regret this" or "watch what happens" feels threatening but names no act and no target. It sits in an ambiguous zone—worth a human read, not a confident label. How to tell: a supportable threat identifies a harm. A vague warning is a candidate for review, not a conclusion.
8. A screenshot without the thread around it
A single screenshot can look decisive and still be misleading—the message before it changes the meaning, or a later message retracts it. A cropped image is a claim about a conversation, not the conversation. How to tell: work from the export, not the screenshot, and keep the messages before and after any message you rely on.
How to separate a real signal from a false one
Read the messages before and after—context resolves most false positives. Confirm who is actually speaking, including quoted or forwarded text. Ask whether the exchange is one-directional or mutual. Require a stated act and target before calling something a threat. Treat automated flags as candidates for a person to confirm, never as findings.
How Textimony handles this
<a href="/" class="text-gilt hover:underline font-medium">Textimony</a> is built around the gap between a flag and a finding. A multi-model pipeline surfaces candidates, but every candidate keeps its surrounding context, participant attribution, and a link back to the source message—so a reviewer can see the quote, the direction, and what came before and after. The tool measures and organizes the record; a person decides what it means. It does not determine intent, truth, guilt, or any legal or clinical conclusion.
Is "you’re dead wrong" a threatening text message?
No. "Dead wrong", "dead set", and "dead serious" are ordinary intensifiers, and none of them names an act or a target. A keyword tool flags the word "dead" because it matches characters rather than meaning. A threat needs a stated or clearly implied act directed at someone — "you’re dead if you tell him" — and the grammatical difference between that and the idiom is exactly what an automated filter cannot see.
Do these texts show coercion?
A mention of money, or even a blunt demand, is usually not coercion on its own. What distinguishes financial coercion is a conditional structure tying the demand to a consequence — pay this or something happens, comply or access is withdrawn. "Send me the $400 you owe me" is a demand. "Send me the $400 or I tell your employer" is the pattern that matters. Read the surrounding messages before concluding.
Why do keyword tools produce so many false positives?
Because they match words, and threats are made of meaning. "Dead wrong" contains "dead". Someone quoting an abusive message to report it contains the abuse verbatim. Sarcasm inverts the sense of every word in the sentence, break-up language borrows the vocabulary of harm, and a vague warning names no act at all. Each of these trips a keyword filter while carrying none of the intent, which is why a flag is a prompt to read, not a finding.
Are screenshots enough on their own?
Usually not, and this page is largely about why. Every misreading described here — the idiom, the quoted abuse, the sarcasm, the money mention without a condition — becomes more likely when the surrounding messages are gone, because the cropped image removes exactly what would have resolved it. Work from the original export where you can, and keep the surrounding thread for any message you intend to rely on.
Published by
Textimony. Editorial status: Source-linked informational guide. Updated: 2026-07-25.
Sources
Federal Rule of Evidence 901 (authenticating evidence); Federal Rule of Evidence 106 (remainder of or related statements); Federal Rule of Evidence 403 (excluding unfairly prejudicial evidence)