Skip to content

Scams & fraud · Updated September 2026

Is this email a scam? How to spot phishing, and what to do

“Phishing” is just the posh word for a fake message that tries to get you to click a link, open an attachment, hand over a password or pay something you don't owe. They're made to look like they come from your bank, a delivery firm, HMRC, Netflix or even someone you know. The good news: once you know what to look for, most of them are easy to spot. Here's the plain version, and exactly what to do if one lands in your inbox.

The five tell-tale signs

The UK's National Cyber Security Centre (NCSC) boils scam messages down to five tricks. A genuine email might use one of them by accident; a scam usually leans on two or three at once.

  • Authority. It claims to be from someone official: your bank, the doctor, a solicitor, a government department.
  • Urgency. You must act within 24 hours, or your account will be closed, you'll be fined, the parcel goes back.
  • Emotion. It's written to make you panic, worry, hope or just be curious enough to click.
  • Scarcity. Something is in short supply: tickets, a refund window, a “limited” offer.
  • Current events. It piggybacks on the news: tax deadlines, energy rebates, a big sporting event, Christmas deliveries.

The simplest rule of all: if a message makes you feel you have to do something right now, that feeling is the scam working. Slow down. A real bank or company will still be there in ten minutes.

Other clues worth checking

  • It doesn't use your name. “Dear customer” or just your email address is a warning sign (though scammers sometimes do know your name, so it isn't proof either way).
  • The sender's address is off. Tap or hover on the sender's name to see the actual email address. “Royal Mail” sending from a Gmail address, or from something like royalmail-parcels-uk.info, isn't Royal Mail.
  • The link goes somewhere odd. On a computer, hover your mouse over a link without clicking: the real web address shows at the bottom of the window. On a phone, press and hold the link to preview it. If it's not the company's normal website, don't go there.
  • It asks for things a real company never asks for by email. Your full password, your PIN, a one-time code, your card details to “confirm” your account.
  • Unexpected attachments. An invoice you weren't expecting, a “voicemail” file, a zipped document. Don't open it.
  • Payment in an unusual way. Gift cards, vouchers, cryptocurrency or a bank transfer to a “new” account are big red flags.

Spelling mistakes used to be the giveaway. They still turn up, but many scam emails are now well written, so don't treat good English as a sign it's genuine.

How to check if it's real, safely

Never use the phone number, link or reply address in the message itself: if it's a scam, they all lead back to the scammer. Instead:

  1. Close the email.
  2. Go to the company yourself: type their web address into your browser, open their official app, or ring the number on the back of your card or on a letter or statement you already have.
  3. Log in the normal way and see whether there's really a problem. If there is, it'll be there too.

The NCSC's own advice is exactly this: don't use the numbers or address in the message, use the details from the organisation's official website.

What to do with a scam email

  1. Don't click, don't reply, don't open attachments. Replying even to say “stop” tells them your address is live.
  2. Report it. Forward the email to report@phishing.gov.uk. That's the NCSC's free Suspicious Email Reporting Service: they check the links and can have scam websites taken down.
  3. Then delete it, or mark it as spam or junk in your email app so similar ones get filtered in future.

Got a dodgy text message instead? Most UK mobile networks let you forward scam texts free to 7726 (it spells “SPAM” on an old keypad). Your network investigates the sender and can block them. Scam calls are a different beast: see is it really your bank calling? and our guides to blocking numbers and registering with the TPS.

If you've already clicked or replied

It happens to careful, clever people every day. Don't be embarrassed; move quickly instead.

  • If you typed in a password: change it straight away on the real website, and anywhere else you use the same password. Turn on two-step verification if it's offered.
  • If you gave bank or card details, or paid something: ring your bank immediately on the number on your card, or call 159, which connects you to most UK banks securely.
  • If you've lost money or been hacked: report it. In England, Wales and Northern Ireland that's Report Fraud (the service that replaced Action Fraud), online or on 0300 123 2040. In Scotland, call Police Scotland on 101.
  • If you opened an attachment: run your security software's full scan, and if the device starts behaving oddly, get it checked before you log in to your bank on it again.

Make the next one easier to ignore

  • Use a different password for every account; a password manager remembers them for you. Our tools page has the ones we rate, including free options.
  • Turn on two-step verification for your email first. Whoever controls your email can reset almost everything else.
  • Treat every unexpected message the same way: close it, and go to the company yourself. It takes a minute and it beats every scam going.

Shopping online? Our guide to spotting a scam website covers the checks to make before you pay.

Want off Google without the faff?

You can do it yourself for free — our free guide shows you how. Or we'll set up a de-Googled Pixel and send it to you, ready to use. No fear-selling, and one flat fee for the work.