Skip to main content
FixMyTech

How to Tell If an Email Is Really From Your Bank

By

Published

8 min read

Share

Short answer

Ignore the display name and the logo. Expand the sender to read the actual address, and check the domain immediately before the first single slash in any link. The decisive test costs nothing: close the email and sign in through your banking app instead. A genuine alert will be waiting there.

On this page

Bank phishing is the most polished category there is, because the payoff is direct. The emails are usually exact copies of the genuine template, with the correct logo, the correct typography and frequently your name. Looking for sloppiness is a losing strategy.

Two checks survive a good forgery, and a third test settles the matter without inspecting anything at all. All three take under a minute.

Check one — the actual sending address

The name you see in your inbox is a display name, and it can be set to anything. “Barclays Security Team” costs nothing to type. The address underneath is the part that carries information.

  • Gmail: tap or click the sender name to expand the header, or the small arrow beneath it
  • Outlook: hover or click the sender to see the full address
  • Apple Mail: tap the sender name on iOS; on macOS, View → Message → All Headers for the full detail

Then read the domain the way a computer does, from the right. The meaningful part is the last two labels before the first single slash.

Address Real domain Verdict
[email protected] hsbc.co.uk Plausible
[email protected] secure-verify.com Fake
[email protected] hsbc-security.com Fake, lookalike
[email protected] login.net Fake
[email protected] hsbc.co.uk Plausible subdomain

The third row is the one that catches people. A hyphenated domain containing the bank’s name is a completely separate domain that anyone can register. Banks use subdomains of their own domain, not new domains that mention them.

Banks also legitimately use dedicated mailing providers, so an address at a marketing domain is not automatically fake — which is exactly why this check alone is not sufficient and check three exists.

Same rule, applied to the link rather than the sender.

On a computer, hover the link and read the address in the bottom-left status bar. On a phone, press and hold until the preview appears, then dismiss it by tapping elsewhere. Do not tap.

Read right to left again, to the first single slash. In https://hsbc.co.uk.account-review.net/signin, the domain is account-review.net and everything before it is decoration chosen to be read left to right.

Two things that are not evidence of fraud on their own: link shorteners and tracking redirects. Legitimate marketing uses both. They do mean you cannot see the destination, which is reason enough not to use the link.

And a padlock on the page proves nothing. Certificates are free and automatic for any domain, including one registered yesterday by a scammer. The padlock means the connection is encrypted; it says nothing about who is at the other end.

Check three — the one that always works

Close the email. Open your banking app, or type the bank’s address yourself from a bookmark. Sign in normally.

If the alert was genuine, it will be in your messages or notifications there. Banks put anything important inside the account precisely because email is not trustworthy.

This works regardless of how good the forgery was, requires no inspection skill, and cannot be defeated by a better-looking email. It is the only check that scales with the quality of the attack rather than against it. The broader version of this principle is in recognising a phishing attack.

If you prefer to ring, use the number printed on the back of your card. Not the number in the email, and not one from a search result, where paid adverts for fake support numbers appear regularly.

The content signals that still mean something

Modern fakes pass most surface checks, but certain requests are diagnostic because no bank makes them.

A request for a one-time code. Nobody from your bank will ever ask you to read out a code they sent you. This is the clearest rule in the whole subject.

“Move your money to a safe account.” No such thing exists. This phrase is the centrepiece of bank impersonation calls and is worth remembering as an absolute.

A full card number, PIN or online banking password requested. Your bank already has these and does not ask.

Threatened account closure within hours. Real banks act on a slower timetable and through more than one channel.

An attachment claiming to be a statement. Statements live inside the account. A password-protected archive, in particular, exists to defeat your mail provider’s scanning.

Conversely, these are not evidence of fraud by themselves: your correct name, your last four card digits, correct branding, a thread containing real messages, and the message arriving at a plausible moment. All of these are obtainable or arrangeable, and relying on them is how good forgeries succeed.

Reading headers, if you want the technical check

Rarely necessary, occasionally satisfying. The full headers show the authentication results your provider calculated.

In Gmail: open the message → the ⋮ menu → Show original. Look for a block reporting SPF, DKIM and DMARC. In Outlook: ⋯ → View → View message source, then search for Authentication-Results.

spf=pass dkim=pass dmarc=pass means the message genuinely came from a server authorised by whatever domain is in the From address. Note the limit: that can be a pass for a lookalike domain the scammer owns and configured properly. The check confirms the sender is who the From line claims, not that the From line is the bank.

A dmarc=fail on mail claiming to be from a major bank is a strong fraud signal, because those domains publish strict policies. In practice your provider has usually already filed such messages as spam.

If you already entered something

Order matters, and the first step is not scanning.

Change the online banking password immediately, from a different device, by going to the bank directly. Then ring the number on your card and tell them what happened. If you gave a card number, the card needs blocking and reissuing, and that call is the priority over everything else.

The complete ordered checklist is in what to do after clicking a suspicious link.

Realistic expectations

Expanding the sender address and reading one link destination resolves the large majority of these in under a minute, because most bulk phishing does not bother with a convincing domain.

The ones designed to defeat inspection do exist, and inspection will eventually fail against them. That is why check three is the one to build the habit around: never act on a banking message from inside the message. Close it, open the app, and let the absence of any alert there tell you what the email was.

Frequently asked questions

Can a scammer send email that genuinely comes from my bank's domain?
It is now difficult for well-configured domains, because SPF, DKIM and DMARC let receiving providers reject forged mail. Most banks publish strict policies, so forgeries are usually sent from lookalike domains rather than the real one.
What does the padlock in my browser prove?
Only that the connection is encrypted. Anyone can obtain a certificate for a domain they control, including a scammer with a lookalike domain, so a padlock on a fake site is normal and means nothing about who owns it.
Do banks ever include links in emails?
Many do, which is why "banks never send links" is unhelpful advice. The safer habit is to treat every link as optional and reach your account through the app or a bookmark instead.
Why does the email know my name and last four card digits?
Personalisation can come from a breach at a retailer rather than your bank. Partial card numbers appear on receipts and in many companies' records, so their presence raises credibility without proving anything.
What if the message arrived in the same thread as real bank texts?
Sender IDs on text messages can be set to match a bank's name, which makes the message group with genuine ones on your phone. Thread position is not evidence, and this is specifically why text-based bank scams work so well.

All Security guides