Spotting common phishing scams
A quick primer on how to identify fraudulent emails and text messages. Learn the red flags to look out for and how to protect your personal information.

Step-by-Step Guide
Examine the sender's full email address
Tap or hover on the sender's display name. A message saying 'Netflix Support' might have a real sender address of 'service-update@netflix-billing-alert.com'.
Identify high-pressure requests
Legitimate organizations (banks, tax office, postal service) will never threaten to suspend your account or fine you within hours unless you click a link right now.
Inspect link URLs carefully
Before clicking any link, hover your mouse over it (or long-press on mobile) to look at the web address. If the main domain name doesn't match the company (e.g. royalmail-package-status.com instead of royalmail.com), do not click.
Never share OTP codes or passwords
No legitimate company will ask you to read out or type in a One-Time Passcode (OTP) sent to your phone to 'verify your identity' after they called you.
Frequently Asked Questions
What should I do if I accidentally clicked a phishing link?
If you entered a password, go to the real website immediately and change your password. If you entered bank details, contact your bank's fraud department right away. Run an antivirus scan if you downloaded any file.
How do scams bypass email filters?
Scammers use compromised legitimate accounts, hide text inside images, or use redirects to dodge automated email scanner algorithms. Never assume an email is safe just because it made it to your inbox.
