Suspicious email guide

Is this email a scam?

Do not use the message to verify itself. Check its sender, claims and requested action through a trusted route you obtained independently.

If money, passwords or security codes are requested: stop. Do not click, reply, call a number in the message or open an attachment. Contact the organisation using its official website, app, statement or card.

Separate the claims from the pressure

Write down what can be checked: who supposedly sent it, which account or payment it concerns, what event allegedly occurred and what deadline is claimed. Urgency, threats, secrecy and authority are risk signals. They are not proof by themselves, but they are designed to shorten the time available for verification.

Check the complete sender—not just the name

Expand the From field and inspect the full address. A familiar display name or logo can be copied. Look for misspellings, unrelated domains and a Reply-To address that differs from the sender. A legitimate-looking domain still does not authenticate this particular message.

Verify outside the email

Open the organisation’s app yourself or type its known address into a fresh browser window. Check the account for the claimed warning or payment. Use a telephone number from an official statement, card or regulator—not from the message or its search advertisement.

Do not test a suspicious link by opening it. On desktop, hovering may reveal a destination, but even a matching-looking address is not enough to establish safety.

Use headers when the decision matters

Full headers can show the technical sending path and authentication results such as SPF, DKIM and DMARC. Passing authentication can support that a domain authorised the message; it cannot prove that the underlying request is honest or that an authorised account was not compromised.

Handle and report it safely

Preserve the original message if your bank, employer or law enforcement may need it. In the UK, suspicious emails can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk. If money or credentials were disclosed, contact the relevant provider immediately using an independently verified channel.

Official guidance

Check the message safely

Separate verifiable claims from pressure signals

Paste the text only after removing names, addresses, account numbers and other personal information. Do not open its links.

0 / 3,000No account required

Never include passwords, codes or financial details.