A fake email pretending to come from your bank usually looks perfectly ordinary at first glance. It has the right logo, the right colours, a polite tone and a clearly visible button. The difference is not in how it looks, but in a handful of details you only see if you know where to look: where the link really leads, which address the message really comes from, what it is asking you to do and how much of a hurry it is in.
This post brings together the signs of a fake bank email: what they mean, where you can see them, and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): traces suggesting that something is not what it seems. Here we use them preventively, to recognise phishing — a message designed to get you to enter your credentials, card details or codes on a fake website — before it causes any harm.
It is the diagnostic deep dive on the recommendation about emails pretending to be your bank: reaching your bank only through channels you trust is the prevention; recognising the signs is how you notice, in time, a message trying to make you take a different route.
What the signs of a fake bank email are
A sign, or indicator, is an observable detail suggesting that a message may not come from the sender it claims to be.
It is not proof. It is a reason to stop and check, always through a channel you choose yourself: your bank’s official app, the website reached from a saved bookmark or by typing the address, the phone number printed on the back of your card. A sign may have a harmless explanation — a genuine message written in a hurry — or it may point to a scam attempt.
The value of these signs lies in timing: recognising them before you click means there is nothing to put right afterwards.
Why they matter more when the message is about your account
An email pretending to come from an online shop or a streaming service is after your password. An email pretending to come from your bank is after something more immediate: the credentials to get into your account and the codes to authorise payments. If the attacker gets both, they can act within minutes.
There is a second reason. Bank messages touch a nerve: the thought of a frozen account, an unauthorised payment, a cloned card. It is precisely this worry, which is entirely understandable, that scammers use to shorten the time between reading and clicking. Bank phishing techniques are built around this lever.
Finally, these messages are often sent in bulk. If you do happen to bank with the bank named in the email, that is not a sign it is genuine: out of thousands of recipients, some will always be customers of that bank.
Technical indicators
These are details you can observe in the message itself, by looking beyond the surface. First, three terms: the domain is the part of an address that comes after the @ in an email, or after “www.” in a website, and identifies who runs it; an attachment is a file sent with the message; a one-time passcode (OTP) is the single-use code your bank sends you by text message or through its app to confirm a sign-in or a payment.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| The sender’s name and real address do not match | The display name is the bank’s, but the actual address is something else | Anyone can type any display name; the address is harder to fake | By tapping or clicking the sender’s name to see the full address | Do not reply; check in the official app or website |
| A lookalike but different domain | The address imitates the bank’s with one letter changed, a hyphen or an extra word | It is a common way to look genuine at a quick glance | In the sender’s address, read calmly from right to left | Treat the message as suspicious even if everything else looks right |
| A link leading somewhere other than what it shows | The button text says one thing, the real destination is another | This is the point where the message takes you away from official channels | By hovering the mouse over the link without clicking; on a phone, by pressing and holding to see the preview | Do not open the link; reach your bank from your bookmark or the app |
| Unexpected attachments | A file presented as a statement, a receipt or a form to fill in | It may contain harmful software, or a form asking for your details | In the body of the message or the list of attachments | Do not open it; check in your online banking whether that document actually exists |
| A request for credentials, a PIN or one-time passcodes | The message asks you to enter or share sign-in details or confirmation codes | As a rule, banks do not ask for these by email, and many say so explicitly | In the text, or on the page the link leads to | Do not enter anything; no code should be given to anyone who asks for it |
| A reply-to address different from the sender | Pressing “Reply” would send your answer to a different address | It is used to collect replies outside the bank | In the recipient field when you start a reply, without sending it | Do not reply; close the message |
| A warning from your email service | Your inbox flags that the message may not come from the stated sender | The email service runs automatic checks you cannot see by eye | A banner or note at the top of the message | Take the warning seriously and check through the official channel |
Signs you can observe yourself
These do not require you to examine addresses or links: you notice them simply by reading the message with a little attention.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| Urgency and tight deadlines | The message tells you to act “within 24 hours” or “immediately” | Pressure leaves less time to think | Highlighted deadlines, countdowns, words such as “final notice” | Pause: a genuine message from your bank will also be in the app, with no rush |
| Threats of blocking or closure | Your account or card will supposedly be suspended unless you act | Fear pushes people to act without checking | Phrases such as “your account will be blocked” or “access restricted” | Open the official app or website and see whether there really is a notice |
| A generic greeting | The message opens with “Dear Customer” rather than your name | It may point to a mass mailing to unknown recipients | In the first line of the message | Weigh this detail together with the others; on its own it is not enough |
| A request that does not fit your usual experience | You are asked to “confirm your details”, “release a transfer” or “update your card” | Banks handle these tasks in your online banking, not by email | By comparing it with the messages you normally receive | Do not follow the instructions; look for the same request in the app |
| A payment you do not recognise | The message reports a payment or sign-in you did not make | It is meant to frighten you into clicking to “cancel” it | Amounts, places or shops that mean nothing to you | Check your transactions in the app; if there is nothing there, the message was the bait |
| Mistakes, odd formatting, a tone that feels off | Clumsy translations, unusual characters, vague signatures | One more clue, though less and less common in carefully crafted messages | By rereading it calmly | Add it to your tally of signs, without making it your only test |
| A phone call following the email | Shortly after the message, someone rings “from the fraud team” | It is a way of making the request for codes seem credible | An unexpected call that refers to the email | Hang up and call your bank back yourself on its official number |
| A message from a bank you do not use | You receive alerts from a bank you have no relationship with | It is the clearest sign of a mass mailing | The bank’s name has nothing to do with you | Report it as phishing and delete it |
A concrete example
Sarah is at the bus stop when an email arrives: “We have detected suspicious activity on your account. To avoid it being blocked, please confirm your details today.” Bank logo, the right colours, even a button shaped like the ones in the app. Sarah does have an account with that bank.
Her first instinct is to tap the button. Then she notices the greeting: “Dear Customer”. It is not enough to decide anything, but it is enough to make her slow down. Instead of tapping the button she presses and holds it, and the preview shows an address with the bank’s name followed by a hyphen and a word that has nothing to do with it.
At that point she closes the email, opens her bank’s app from her phone’s home screen and looks at the notifications. No alert, no suspicious sign-in, nothing unusual in her transactions. She reports the message as phishing through her email service and deletes it.
None of the signs, on its own, was proof. Taken together — urgency, the threat of a block, a generic greeting, a link heading somewhere else — they told a consistent story. And the decisive check did not happen in the message, but outside it, in a channel Sarah had chosen herself.
What to check right away
In the message, without interacting with it
- the sender’s full address, not just the display name;
- where the links really lead, using the preview and without opening them;
- any attachments you were not expecting;
- what you are being asked for: details, codes, a payment, an “update”.
In your bank’s official channels (the app, the website from your bookmark, the number on the back of your card)
- notifications and messages in your online banking;
- recent transactions on your account and card;
- the status of your card and of your authorised devices.
If you find a suspicious indicator
- Do not click, do not reply, do not open attachments. Closing the message carries no risk at all.
- Check through a channel you choose: the official app, the website from your bookmark or a typed address, the official phone number.
- Report the message as phishing through your email service; many banks also give an address for forwarding suspicious emails, which you will find on their security pages.
- Delete the message once you have reported it, so you cannot open it by mistake later on.
- If you have already clicked or entered details, contact your bank straight away on its official number: in these cases time matters.
The full sequence, with the steps in the right order if something has already happened, is in the post on what to do after a bank phishing email.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: trusting details that guarantee nothing, and getting alarmed over perfectly normal messages.
| Situation | Why it is not enough to decide |
|---|---|
| Logo, colours and layout identical to your bank’s | Copying a company’s visual style is easy: a polished message is not genuine for that reason alone |
| The message includes your first name and surname | Personal details may come from breaches at other services; your name alone does not prove where the email came from |
| The site opened by the link shows the padlock in the browser | The padlock means the connection is encrypted, not that the site belongs to your bank |
| The last digits of your card or account are correct | They may have been obtained elsewhere, or guessed from among the most common ones |
| An email from your bank that contains links | Genuine messages can contain them too; the point is not to use them to get into your account |
| A genuine email telling you about a new sign-in | If the service tells you about a sign-in you made yourself, that is the system working |
The rule of thumb: no detail in the message, taken on its own, proves it is genuine. Confirmation always comes from outside, from the channel you reach by yourself. The padlock in particular is useful and deserves attention — we explain it in the recommendation on browsing only over HTTPS — but it does not tell you who is on the other side.
When to run these checks
You do not need a demanding routine. You just need the habit to kick in at the right moments.
| Moment | What to check |
|---|---|
| Whenever an email is about your account, cards or payments | The sender, the links and the request, before doing anything |
| Whenever you get a phone call linked to an email | Hang up and call the official number yourself, without giving any codes |
| Once a month | Notifications in your online banking and your account transactions, from the app or from the bookmarked website |
| When you change your phone number or email address | Update your contact details with the bank through your online banking, so genuine messages reach you where you expect them |
| After news of a phishing campaign or a data breach | Pay closer attention to messages over the following days, even if they do not seem related |
Keeping your bank’s bookmark in the browser toolbar and the official app somewhere easy to reach makes checking quicker than clicking the link: it is the safe shortcut that replaces the risky one.
Two important warnings
A sign is not proof. A generic greeting, a typo or an unfamiliar layout can also turn up in a genuine message. You do not need to be completely certain that a message is fake: it is enough not to use it as a way in, and to check through the official channel.
No signs is not a guarantee. The most carefully crafted phishing messages contain no mistakes, use your name and come from domains that look very like the real ones. That is why protection does not rest on spotting every scam, but on the habit described in the recommendation: you always reach your bank through its own channels, never through the links in an email. The signs help you stop; the habit means you do not have to guess.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read a sender’s real address and preview a link without opening it |
| Awareness | Understanding that a message can look exactly like your bank and still not come from your bank |
| Secure Behaviour | Always checking through a channel you choose, without replying and without clicking |
Reference level: FL2 — Beginner. This is the level at which you recognise the most common signs of a deceptive message and stop before acting, even without knowing the technical details of how it was put together.
Conclusion
Spotting a fake bank email does not take specialist skills. It takes shifting your attention from how the message looks to three simple questions: where does it really come from, where does it really lead, and what is it asking me to do?
What to do right now. Open your inbox, find the most recent email from your bank and look at the sender’s full address and the preview of one of its links, without opening it. You will know what a genuine message looks like, and it will be easier to notice one that is not. Then save your bank’s website as a bookmark, if you have not already. To see where you stand on the other aspects of your digital security too, you can take the digital resilience self-assessment.
Related resources
Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:
- How to recognise phishing when it is built to be convincing
- Online Banking Security: A Separate Address for the Bank
Related content
- Emails pretending to be your bank — the recommendation this belongs to
- Bank phishing techniques — the mechanisms behind these signs
- What to do after a bank phishing email — what to do, in the right order
- Impact of bank phishing — what gets hit when a fake message succeeds
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



