How to Tell If an Email Is Really From Your Bank
Short answer
Ignore the display name and the logo. Expand the sender to read the actual address, and check the domain immediately before the first single slash in any link. The decisive test costs nothing: close the email and sign in through your banking app instead. A genuine alert will be waiting there.
On this page
Bank phishing is the most polished category there is, because the payoff is direct. The emails are usually exact copies of the genuine template, with the correct logo, the correct typography and frequently your name. Looking for sloppiness is a losing strategy.
Two checks survive a good forgery, and a third test settles the matter without inspecting anything at all. All three take under a minute.
Check one — the actual sending address
The name you see in your inbox is a display name, and it can be set to anything. “Barclays Security Team” costs nothing to type. The address underneath is the part that carries information.
- Gmail: tap or click the sender name to expand the header, or the small arrow beneath it
- Outlook: hover or click the sender to see the full address
- Apple Mail: tap the sender name on iOS; on macOS, View → Message → All Headers for the full detail
Then read the domain the way a computer does, from the right. The meaningful part is the last two labels before the first single slash.
| Address | Real domain | Verdict |
|---|---|---|
[email protected] |
hsbc.co.uk |
Plausible |
[email protected] |
secure-verify.com |
Fake |
[email protected] |
hsbc-security.com |
Fake, lookalike |
[email protected] |
login.net |
Fake |
[email protected] |
hsbc.co.uk |
Plausible subdomain |
The third row is the one that catches people. A hyphenated domain containing the bank’s name is a completely separate domain that anyone can register. Banks use subdomains of their own domain, not new domains that mention them.
Banks also legitimately use dedicated mailing providers, so an address at a marketing domain is not automatically fake — which is exactly why this check alone is not sufficient and check three exists.
Check two — where the links actually go
Same rule, applied to the link rather than the sender.
On a computer, hover the link and read the address in the bottom-left status bar. On a phone, press and hold until the preview appears, then dismiss it by tapping elsewhere. Do not tap.
Read right to left again, to the first single slash. In
https://hsbc.co.uk.account-review.net/signin, the domain is account-review.net
and everything before it is decoration chosen to be read left to right.
Two things that are not evidence of fraud on their own: link shorteners and tracking redirects. Legitimate marketing uses both. They do mean you cannot see the destination, which is reason enough not to use the link.
And a padlock on the page proves nothing. Certificates are free and automatic for any domain, including one registered yesterday by a scammer. The padlock means the connection is encrypted; it says nothing about who is at the other end.
Check three — the one that always works
Close the email. Open your banking app, or type the bank’s address yourself from a bookmark. Sign in normally.
If the alert was genuine, it will be in your messages or notifications there. Banks put anything important inside the account precisely because email is not trustworthy.
This works regardless of how good the forgery was, requires no inspection skill, and cannot be defeated by a better-looking email. It is the only check that scales with the quality of the attack rather than against it. The broader version of this principle is in recognising a phishing attack.
If you prefer to ring, use the number printed on the back of your card. Not the number in the email, and not one from a search result, where paid adverts for fake support numbers appear regularly.
The content signals that still mean something
Modern fakes pass most surface checks, but certain requests are diagnostic because no bank makes them.
A request for a one-time code. Nobody from your bank will ever ask you to read out a code they sent you. This is the clearest rule in the whole subject.
“Move your money to a safe account.” No such thing exists. This phrase is the centrepiece of bank impersonation calls and is worth remembering as an absolute.
A full card number, PIN or online banking password requested. Your bank already has these and does not ask.
Threatened account closure within hours. Real banks act on a slower timetable and through more than one channel.
An attachment claiming to be a statement. Statements live inside the account. A password-protected archive, in particular, exists to defeat your mail provider’s scanning.
Conversely, these are not evidence of fraud by themselves: your correct name, your last four card digits, correct branding, a thread containing real messages, and the message arriving at a plausible moment. All of these are obtainable or arrangeable, and relying on them is how good forgeries succeed.
Reading headers, if you want the technical check
Rarely necessary, occasionally satisfying. The full headers show the authentication results your provider calculated.
In Gmail: open the message → the ⋮ menu → Show original. Look for a block
reporting SPF, DKIM and DMARC. In Outlook: ⋯ → View → View message
source, then search for Authentication-Results.
spf=pass dkim=pass dmarc=pass means the message genuinely came from a server
authorised by whatever domain is in the From address. Note the limit: that can be
a pass for a lookalike domain the scammer owns and configured properly. The check
confirms the sender is who the From line claims, not that the From line is the
bank.
A dmarc=fail on mail claiming to be from a major bank is a strong fraud signal,
because those domains publish strict policies. In practice your provider has
usually already filed such messages as spam.
If you already entered something
Order matters, and the first step is not scanning.
Change the online banking password immediately, from a different device, by going to the bank directly. Then ring the number on your card and tell them what happened. If you gave a card number, the card needs blocking and reissuing, and that call is the priority over everything else.
The complete ordered checklist is in what to do after clicking a suspicious link.
Realistic expectations
Expanding the sender address and reading one link destination resolves the large majority of these in under a minute, because most bulk phishing does not bother with a convincing domain.
The ones designed to defeat inspection do exist, and inspection will eventually fail against them. That is why check three is the one to build the habit around: never act on a banking message from inside the message. Close it, open the app, and let the absence of any alert there tell you what the email was.