CYBER WELFARE

Protect your Digital Privacy

Signs of a fake bank email: how to spot one before you click

A fake email pretending to come from your bank usually looks perfectly ordinary at first glance. It has the right logo, the right colours, a polite tone and a clearly visible button. The difference is not in how it looks, but in a handful of details you only see if you know where to look: where the link really leads, which address the message really comes from, what it is asking you to do and how much of a hurry it is in.

This post brings together the signs of a fake bank email: what they mean, where you can see them, and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): traces suggesting that something is not what it seems. Here we use them preventively, to recognise phishing — a message designed to get you to enter your credentials, card details or codes on a fake website — before it causes any harm.

It is the diagnostic deep dive on the recommendation about emails pretending to be your bank: reaching your bank only through channels you trust is the prevention; recognising the signs is how you notice, in time, a message trying to make you take a different route.

What the signs of a fake bank email are

A sign, or indicator, is an observable detail suggesting that a message may not come from the sender it claims to be.

It is not proof. It is a reason to stop and check, always through a channel you choose yourself: your bank’s official app, the website reached from a saved bookmark or by typing the address, the phone number printed on the back of your card. A sign may have a harmless explanation — a genuine message written in a hurry — or it may point to a scam attempt.

The value of these signs lies in timing: recognising them before you click means there is nothing to put right afterwards.

Why they matter more when the message is about your account

An email pretending to come from an online shop or a streaming service is after your password. An email pretending to come from your bank is after something more immediate: the credentials to get into your account and the codes to authorise payments. If the attacker gets both, they can act within minutes.

There is a second reason. Bank messages touch a nerve: the thought of a frozen account, an unauthorised payment, a cloned card. It is precisely this worry, which is entirely understandable, that scammers use to shorten the time between reading and clicking. Bank phishing techniques are built around this lever.

Finally, these messages are often sent in bulk. If you do happen to bank with the bank named in the email, that is not a sign it is genuine: out of thousands of recipients, some will always be customers of that bank.

Technical indicators

These are details you can observe in the message itself, by looking beyond the surface. First, three terms: the domain is the part of an address that comes after the @ in an email, or after “www.” in a website, and identifies who runs it; an attachment is a file sent with the message; a one-time passcode (OTP) is the single-use code your bank sends you by text message or through its app to confirm a sign-in or a payment.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
The sender’s name and real address do not matchThe display name is the bank’s, but the actual address is something elseAnyone can type any display name; the address is harder to fakeBy tapping or clicking the sender’s name to see the full addressDo not reply; check in the official app or website
A lookalike but different domainThe address imitates the bank’s with one letter changed, a hyphen or an extra wordIt is a common way to look genuine at a quick glanceIn the sender’s address, read calmly from right to leftTreat the message as suspicious even if everything else looks right
A link leading somewhere other than what it showsThe button text says one thing, the real destination is anotherThis is the point where the message takes you away from official channelsBy hovering the mouse over the link without clicking; on a phone, by pressing and holding to see the previewDo not open the link; reach your bank from your bookmark or the app
Unexpected attachmentsA file presented as a statement, a receipt or a form to fill inIt may contain harmful software, or a form asking for your detailsIn the body of the message or the list of attachmentsDo not open it; check in your online banking whether that document actually exists
A request for credentials, a PIN or one-time passcodesThe message asks you to enter or share sign-in details or confirmation codesAs a rule, banks do not ask for these by email, and many say so explicitlyIn the text, or on the page the link leads toDo not enter anything; no code should be given to anyone who asks for it
A reply-to address different from the senderPressing “Reply” would send your answer to a different addressIt is used to collect replies outside the bankIn the recipient field when you start a reply, without sending itDo not reply; close the message
A warning from your email serviceYour inbox flags that the message may not come from the stated senderThe email service runs automatic checks you cannot see by eyeA banner or note at the top of the messageTake the warning seriously and check through the official channel

Signs you can observe yourself

These do not require you to examine addresses or links: you notice them simply by reading the message with a little attention.

SignalWhat it meansWhy it mattersHow you noticeWhat to do
Urgency and tight deadlinesThe message tells you to act “within 24 hours” or “immediately”Pressure leaves less time to thinkHighlighted deadlines, countdowns, words such as “final notice”Pause: a genuine message from your bank will also be in the app, with no rush
Threats of blocking or closureYour account or card will supposedly be suspended unless you actFear pushes people to act without checkingPhrases such as “your account will be blocked” or “access restricted”Open the official app or website and see whether there really is a notice
A generic greetingThe message opens with “Dear Customer” rather than your nameIt may point to a mass mailing to unknown recipientsIn the first line of the messageWeigh this detail together with the others; on its own it is not enough
A request that does not fit your usual experienceYou are asked to “confirm your details”, “release a transfer” or “update your card”Banks handle these tasks in your online banking, not by emailBy comparing it with the messages you normally receiveDo not follow the instructions; look for the same request in the app
A payment you do not recogniseThe message reports a payment or sign-in you did not makeIt is meant to frighten you into clicking to “cancel” itAmounts, places or shops that mean nothing to youCheck your transactions in the app; if there is nothing there, the message was the bait
Mistakes, odd formatting, a tone that feels offClumsy translations, unusual characters, vague signaturesOne more clue, though less and less common in carefully crafted messagesBy rereading it calmlyAdd it to your tally of signs, without making it your only test
A phone call following the emailShortly after the message, someone rings “from the fraud team”It is a way of making the request for codes seem credibleAn unexpected call that refers to the emailHang up and call your bank back yourself on its official number
A message from a bank you do not useYou receive alerts from a bank you have no relationship withIt is the clearest sign of a mass mailingThe bank’s name has nothing to do with youReport it as phishing and delete it

A concrete example

Sarah is at the bus stop when an email arrives: “We have detected suspicious activity on your account. To avoid it being blocked, please confirm your details today.” Bank logo, the right colours, even a button shaped like the ones in the app. Sarah does have an account with that bank.

Her first instinct is to tap the button. Then she notices the greeting: “Dear Customer”. It is not enough to decide anything, but it is enough to make her slow down. Instead of tapping the button she presses and holds it, and the preview shows an address with the bank’s name followed by a hyphen and a word that has nothing to do with it.

At that point she closes the email, opens her bank’s app from her phone’s home screen and looks at the notifications. No alert, no suspicious sign-in, nothing unusual in her transactions. She reports the message as phishing through her email service and deletes it.

None of the signs, on its own, was proof. Taken together — urgency, the threat of a block, a generic greeting, a link heading somewhere else — they told a consistent story. And the decisive check did not happen in the message, but outside it, in a channel Sarah had chosen herself.

What to check right away

In the message, without interacting with it

  • the sender’s full address, not just the display name;
  • where the links really lead, using the preview and without opening them;
  • any attachments you were not expecting;
  • what you are being asked for: details, codes, a payment, an “update”.

In your bank’s official channels (the app, the website from your bookmark, the number on the back of your card)

  • notifications and messages in your online banking;
  • recent transactions on your account and card;
  • the status of your card and of your authorised devices.

If you find a suspicious indicator

  1. Do not click, do not reply, do not open attachments. Closing the message carries no risk at all.
  2. Check through a channel you choose: the official app, the website from your bookmark or a typed address, the official phone number.
  3. Report the message as phishing through your email service; many banks also give an address for forwarding suspicious emails, which you will find on their security pages.
  4. Delete the message once you have reported it, so you cannot open it by mistake later on.
  5. If you have already clicked or entered details, contact your bank straight away on its official number: in these cases time matters.

The full sequence, with the steps in the right order if something has already happened, is in the post on what to do after a bank phishing email.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: trusting details that guarantee nothing, and getting alarmed over perfectly normal messages.

SituationWhy it is not enough to decide
Logo, colours and layout identical to your bank’sCopying a company’s visual style is easy: a polished message is not genuine for that reason alone
The message includes your first name and surnamePersonal details may come from breaches at other services; your name alone does not prove where the email came from
The site opened by the link shows the padlock in the browserThe padlock means the connection is encrypted, not that the site belongs to your bank
The last digits of your card or account are correctThey may have been obtained elsewhere, or guessed from among the most common ones
An email from your bank that contains linksGenuine messages can contain them too; the point is not to use them to get into your account
A genuine email telling you about a new sign-inIf the service tells you about a sign-in you made yourself, that is the system working

The rule of thumb: no detail in the message, taken on its own, proves it is genuine. Confirmation always comes from outside, from the channel you reach by yourself. The padlock in particular is useful and deserves attention — we explain it in the recommendation on browsing only over HTTPS — but it does not tell you who is on the other side.

When to run these checks

You do not need a demanding routine. You just need the habit to kick in at the right moments.

MomentWhat to check
Whenever an email is about your account, cards or paymentsThe sender, the links and the request, before doing anything
Whenever you get a phone call linked to an emailHang up and call the official number yourself, without giving any codes
Once a monthNotifications in your online banking and your account transactions, from the app or from the bookmarked website
When you change your phone number or email addressUpdate your contact details with the bank through your online banking, so genuine messages reach you where you expect them
After news of a phishing campaign or a data breachPay closer attention to messages over the following days, even if they do not seem related

Keeping your bank’s bookmark in the browser toolbar and the official app somewhere easy to reach makes checking quicker than clicking the link: it is the safe shortcut that replaces the risky one.

Two important warnings

A sign is not proof. A generic greeting, a typo or an unfamiliar layout can also turn up in a genuine message. You do not need to be completely certain that a message is fake: it is enough not to use it as a way in, and to check through the official channel.

No signs is not a guarantee. The most carefully crafted phishing messages contain no mistakes, use your name and come from domains that look very like the real ones. That is why protection does not rest on spotting every scam, but on the habit described in the recommendation: you always reach your bank through its own channels, never through the links in an email. The signs help you stop; the habit means you do not have to guess.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to read a sender’s real address and preview a link without opening it
AwarenessUnderstanding that a message can look exactly like your bank and still not come from your bank
Secure BehaviourAlways checking through a channel you choose, without replying and without clicking

Reference level: FL2 — Beginner. This is the level at which you recognise the most common signs of a deceptive message and stop before acting, even without knowing the technical details of how it was put together.

Conclusion

Spotting a fake bank email does not take specialist skills. It takes shifting your attention from how the message looks to three simple questions: where does it really come from, where does it really lead, and what is it asking me to do?

What to do right now. Open your inbox, find the most recent email from your bank and look at the sender’s full address and the preview of one of its links, without opening it. You will know what a genuine message looks like, and it will be easier to notice one that is not. Then save your bank’s website as a bookmark, if you have not already. To see where you stand on the other aspects of your digital security too, you can take the digital resilience self-assessment.

Related resources

Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.