Technology
Fake Emails: Five Things to Check Without Technical Knowledge
For years the standard advice was to look for bad spelling and clumsy grammar. That advice is now actively misleading.
AI-generated phishing has eliminated the grammar mistakes that once helped people spot fakes.
The messages arriving today are well written, correctly branded, and often personalised with details taken from a data breach. What follows are the checks that still work.
1. What is it asking you to do?
Start here rather than with the sender, because it is the fastest filter and it does not require you to examine anything technical.
Almost every fraudulent email asks for one of four things:
- Click a link and sign in
- Open an attachment
- Reply with information
- Make a payment or change payment details
Almost every legitimate email from a bank, a government agency or a service provider asks for none of them. Real notifications tell you something and let you go and check yourself.
If a message wants an action, treat the message as unverified — however it looks.
2. Does it create urgency?
Your account will be closed. Your payment failed. Your benefit is suspended. Confirm within 24 hours.
Urgency exists to stop you checking. Genuine institutions send reminders, not countdowns, and nothing real is lost by going to check through your own route.
3. Where does the link actually go?
You do not need to click to find out.
On a computer: rest the cursor over the link without clicking. The real destination appears at the bottom of the screen.
On a phone: press and hold the link. A preview appears with the full address. Then dismiss it.
What to look for: the part immediately before the first single slash is the actual site. In yourbank.com.secure-login.info/account, the site is secure-login.info, not your bank. Familiar words appearing later in a long address mean nothing.
Look for near-misses — an extra word, a hyphen, .co instead of .com, a letter swapped for a similar one.
4. Is the sender address the real domain?
Display names are free to set. The address behind the name is what matters, and on a phone it is often hidden behind the name — tap it to expand.
A real bank does not send from a free email service. Not from Gmail, not from Outlook.com.
Watch for lookalike domains: an extra hyphen, a different ending, a substituted letter. These are registered in bulk specifically to survive a quick glance.
And be aware of the limit of this check: sender addresses can be forged. A correct-looking address is not proof of anything. A wrong one is proof; a right one is not.
5. Were you expecting it?
Unexpected receipts, unexpected refunds, unexpected delivery problems, unexpected invoices.
The receipt for something you did not buy is one of the most effective formats in use, because it makes people click in alarm rather than in trust. The link goes to "cancel this order" and lands somewhere else entirely.
The habit that makes all of this unnecessary
Checking is a skill and it will occasionally fail, because these messages are getting better.
The habit that does not fail: never act from a message. Go to the source yourself.
If your bank appears to need something, close the email and open your banking app or type the address you already know. If a delivery company reports a problem, go to the carrier's site and enter the tracking number. If a government agency writes, log in through the site you have used before.
This costs about thirty seconds and it makes the sophistication of the message irrelevant, because you never used it.
Never dial a phone number contained in an email. If a message asks you to call, look the number up independently.
Attachments
Do not open an attachment you were not expecting, even from someone you know — email accounts get compromised, and the first thing they are used for is messaging the address book.
If a friend sends an unexpected attachment, contact them another way and ask.
Two things worth setting up
Two-factor authentication on your email account, before anything else. Whoever controls your email can reset every other account you have, which makes it the most valuable target you own.
A password manager, so a leaked password from one place cannot open others. It sounds like a technical step and it is one setup and then less work than what you do now.
If you clicked
Not a catastrophe, and worth acting on immediately.
Entered a password: change it now, from a different device, and anywhere else you used it. Check whether your email has a new forwarding rule — that is the standard first move after a compromise and it is easy to miss.
Entered card details: call the bank, on the number from your card.
Opened an attachment: disconnect that device from the internet and have it checked before using it for anything financial.
Report it at reportfraud.ftc.gov. If money was lost, also ic3.gov, and the National Elder Fraud Hotline is the AARP Fraud Watch Network.
Then see the first two hours after you realise.
For additional public information on consumer fraud and scam prevention, see Federal Trade Commission.