How to spot a scam email or text
Phishing is how most people get caught out. Not a dramatic hack — an ordinary-looking email about a parcel, a bank transfer or a subscription renewal, arriving on a busy day.
Scam messages have got much better. The old clues — bad spelling, odd fonts — still catch some, but plenty of modern attempts are word-perfect. Here's what actually gives them away.
The reliable warning signs
Almost every scam message needs you to do something quickly and without checking. That need shows.
- It creates urgency: your account will be closed, a payment failed, a delivery will be returned today
- The sender's address doesn't match the company — check the part after the @, not the display name
- A link that doesn't go where it says (hover over it on a computer, press and hold on a phone to preview)
- It asks you to confirm a password, PIN, card number or one-time code — no genuine organisation does this
- An attachment you weren't expecting, especially a .zip, .html or a document that asks you to enable content
- A payment or bank detail change arriving by email alone
The convincing ones people fall for
The scams that work don't look like scams. These are the ones we see catching sensible people.
- A reply inside a real email conversation, sent from a supplier's genuinely hacked mailbox
- A renewal invoice for antivirus or a subscription you really do have, with a phone number to call to cancel
- A text from "your bank" that lands in the same message thread as their real texts — scammers can fake the sender name
- A shared document notification from a colleague's compromised account
- A text about an unpaid road toll, parcel fee or DVLA refund — small amounts, so people just pay
How to check safely
The rule is simple: never use the contact route the message gave you.
- Open a browser and type the company's address yourself, or use their official app
- Phone the number on your card, your paper statement or the company's real website
- If it's from a person, ring them on the number you already had — not one in the email
- For a delivery, check with the retailer you actually ordered from
If you've already clicked
Clicking a link is not usually a disaster on its own. Entering details is the moment that matters — and speed helps a great deal.
- Entered a password? Change it immediately on that account, and anywhere else you used the same one
- Entered card or banking details? Ring your bank now — most have a 24-hour fraud line
- Approved a code or app prompt you didn't trigger? Change the password and remove any unknown devices from the account
- Downloaded or ran something? Disconnect from the internet and get the machine checked before using it again
- Report it: forward scam emails to report@phishing.gov.uk and text scams to 7726, free on every UK network
Making yourself a harder target
Two things blunt phishing almost completely. Two-factor authentication means a stolen password isn't enough on its own. A password manager only offers to fill your details on the genuine website, so a convincing fake simply stays blank — which is a quiet, reliable warning you'll notice before you type.
Monitored antivirus adds the last layer, blocking known scam sites and malicious downloads before the page even loads.