StayCyberSafe
← Articles

Scams

How to tell if an email is a scam

The advice most people have been given — check for typos, hover over the link — is incomplete, and on a phone it barely works at all. Here's what I actually look at, in the order I look at it.

Triaging suspicious emails is a good chunk of my job. People forward me something that felt off, and I work out whether it's a real threat, a clumsy marketing email, or something in between. After enough of these you stop reading the message and start reading the shape of it.

The standard public advice hasn't kept up. "Look for spelling mistakes" made sense when scams were written by people working in a second language with no tools. Plenty are now written with the same AI writing assistants everyone else uses, and they read perfectly well. Meanwhile most email now gets opened on a phone, where you can't hover over anything.

So here's the actual sequence. It moves from the cheapest checks to the most effortful, and most scams fail well before the end.

01

Were you expecting it?

This is the single most useful question, and it costs nothing. Almost every successful scam arrives unsolicited and asks you to act.

A delivery notice for a parcel you didn't order. An invoice from a company you don't use. A password reset you didn't request. A message from a colleague asking for something slightly outside how they normally ask. The content might be flawless — it's the fact that it turned up uninvited and wants something that matters.

The corollary is worth saying too: if you just clicked "forgot password" on a site and a reset email arrives ten seconds later, that email is almost certainly real. Context cuts both ways, and being able to relax about the legitimate ones is half the value of this.

02

What is it actually asking you to do?

Every scam has an action it needs from you. Find it, because that's the part the attacker can't remove.

  • Enter credentials on a page it links to
  • Pay something, or change bank details on an existing payment
  • Open an attachment or install something
  • Reply with information — a phone number, a code, a document
  • Scan a QR code, which is now common precisely because it moves you onto a phone where the other checks are harder

An email with no action isn't usually a scam; it's just email. And when you isolate the action, the strangeness often becomes obvious. Your bank does not need you to confirm your password. The tax office does not take payment in gift cards. A supplier changing their bank account by email, right before a payment is due, is the single most expensive pattern in this entire category.

The urgency tell

Nearly all of these come with a reason you must act now — an account closing, a delivery being returned, a fine escalating, a manager who's about to go into a meeting. Urgency exists to stop you doing exactly what this article describes.

Treat a deadline as a reason to slow down. Real organisations cope fine with you taking ten minutes to check.

03

Look at the real sender address

The name you see at the top of an email is display name — free text that the sender chooses. Anyone can set it to "Commonwealth Bank" or to your CEO's name. It proves nothing whatsoever.

What matters is the actual address behind it. On a phone, tap the sender's name to expand it. On a desktop client, it's usually shown next to the name or one click away. If your mail app makes this genuinely hard, that's worth knowing about your mail app.

Then read the domain — the part after the @ — carefully:

service@paypal.com
service@paypal.com.account-verify.io
service@paypa1.com
The second is a subdomain of account-verify.io, which has nothing to do with PayPal. The third swaps the letter l for the digit 1.

One honest caveat, because it's the kind of thing that gets left out: a legitimate-looking sender domain is weaker evidence than most people assume. Real accounts get compromised, and an email genuinely sent from a real supplier's real mailbox will pass every technical check there is. Sender address is good at catching bad scams and poor at catching good ones.

04

Read the link the way a computer does

Link text is decoration. www.yourbank.com.au written in an email can point anywhere at all. What matters is the destination, and specifically one part of it.

To see the destination: on desktop, hover and read the status bar. On a phone, press and hold the link — don't tap — until a preview appears showing where it goes. That press-and-hold is the mobile equivalent of hovering, and most people have never been told it exists.

Then find the real domain using one rule:

Start after https://, read forward to the first single slash, and take the last two words before it.
https://westpac.com.au/login/verify
https://westpac.com.au.secure-id.net/login
https://login-westpac.com/au/verify
Everything to the left of the real domain is decoration the attacker controls. A hyphen is not a full stop — login-westpac.com is one domain someone registered, not a part of westpac.com.au.

Two pieces of link advice to retire

"Check for the padlock." The padlock means the connection is encrypted, not that the site is honest. Phishing pages get free certificates like everyone else, and most have had padlocks for years. It tells you nobody is eavesdropping while you hand your password to a criminal.

"Look for typos." Still occasionally useful, but far weaker than it was. There's a well-known theory — from a Microsoft Research paper on advance fee scams — that obvious errors are sometimes deliberate, filtering for the most credulous targets so the scammer doesn't waste time. My honest position is that it's a plausible explanation for some campaigns and gets over-applied to all of them. Either way: a well-written email is not a safe email.

05

Does the channel make sense?

Organisations have habits, and scams frequently get them wrong in ways that are obvious once you're looking.

  • Banks don't email asking you to confirm a password, PIN or full card number.
  • Government agencies don't demand immediate payment by gift card, crypto, or bank transfer to a personal account.
  • Internal IT doesn't usually contact you from an outside address — and if your organisation tags external mail, a message claiming to be from a colleague that carries an external banner is a genuine red flag.
  • Nobody legitimate needs the six-digit code that just arrived on your phone. Not your bank, not support, not a colleague. That code is the last thing standing between an attacker and your account.
06

When you can't tell, verify somewhere else

Sometimes you'll work through all of the above and still not know. That's not a failure — some phishing is genuinely well made, and some legitimate email is genuinely badly made. Marketing departments produce things that look far worse than professional phishing.

The way out isn't to look harder at the email. It's to stop using the email as your source of truth.

The one habit worth building

Contact the organisation using details you already had — the number on the back of your card, the app you already have installed, the site you type in yourself, the colleague's number in your phone.

Never the phone number, link, or reply address in the message you're checking. If the email is a scam, every contact detail in it goes to the scammer, and they are perfectly happy to reassure you.

This works no matter how convincing the message is, requires no technical knowledge, and doesn't get outdated when attackers change tactics. If you take one thing from this article, take this one.


If you've already clicked

Worth saying plainly: this happens to people who know better, including people who do this for a living on a bad day. Feeling stupid about it is the thing that causes real damage, because it delays telling someone. Speed matters far more than blame.

  1. If you entered a password, change it now — on the real site, typed in yourself. Change it anywhere else you reused it, which is the part people skip and the part that usually matters most.
  2. Turn on two-factor authentication for that account if it isn't already. It blunts a stolen password considerably.
  3. If it was a work account or device, tell your IT or security team immediately. We would far rather hear about it in the first ten minutes than find it ourselves three weeks later. Nobody in a security team is impressed by someone who never clicks anything; we're relieved by people who report quickly.
  4. If money moved, call your bank straight away and report it to Scamwatch. Fast reporting occasionally allows a transfer to be stopped.
  5. If you only clicked a link and closed it without entering anything, you're very likely fine. Watch for anything unexpected, but don't spiral over it.

The short version

Was I expecting this? What does it want? Who really sent it? Where does the link really go? And if the answer is still unclear — verify through a channel the email had no part in choosing.

You don't need to become suspicious of everything. Most email is exactly what it appears to be, and living in a state of low-grade alarm about your inbox is its own kind of harm. The point is to have a quick sequence you can run when something feels off, so that the feeling turns into an answer instead of a background worry.

Something here unclear, or an email you're not sure about? I'd rather be asked than have someone guess — contact@staycybersafe.online.

This is general information, not advice about your specific situation. If money or a work account is involved, your bank or your security team should hear about it before you finish reading anything on the internet.

Stay in the loop

Occasional updates when there's something genuinely worth reading. That's it.

Your email address and the date you gave it — that's everything stored, and it's only ever used to send you these updates. Never shared, never sold. Unsubscribe any time by replying or emailing me. Full privacy policy.