Security
Is this email a scam? How to tell, in about a minute
People forward us suspicious emails constantly, and they’re nearly always slightly embarrassed about asking. They shouldn’t be. Modern scam emails are good — properly good — and the ones that catch people out are rarely the obvious ones.
Here are the checks that actually work, in the order we use them.
First: were you expecting it?
The single most useful question, and the one people skip.
An unexpected message about a parcel you didn’t order, a payment you didn’t make, an account you don’t have, or a refund you didn’t request — treat all of it as suspicious by default. Scams work by arriving unannounced and making you react before you think.
Second: what does it want you to do, and how quickly?
Nearly every scam email needs you to do something urgently:
- Your account will be closed within 24 hours
- Confirm your details now or lose access
- Your parcel will be returned unless you pay a small fee
- Suspicious activity detected — verify immediately
Genuine organisations rarely give you a deadline measured in hours. Urgency is the tell. It exists to stop you checking.
Third: check the sender properly
The display name means nothing — anyone can set it to “HMRC” or “Royal Mail”. You need the actual address behind it.
On a computer, hover over the sender name. On a phone, tap it. You’ll see the real address, and it’s often something like service-royalmail@delivery-update-2847.com.
Look at the bit immediately before the first single slash — that’s the real domain. royalmail.com/tracking is Royal Mail. royalmail.tracking-update.net is not.
Fourth: hover over the link, don’t click it
On a computer, rest your mouse on the button or link without clicking. The real destination appears at the bottom of the window. On a phone, press and hold to see where it goes.
If the text says one thing and the destination says another, that’s your answer.
The checks that no longer work
Worth saying plainly, because a lot of well-meaning advice is out of date.
“Look for bad spelling.” This used to be reliable. It isn’t any more. Plenty of scam emails are now written in flawless English, and plenty of genuine ones contain typos.
“Check for the padlock.” Fake sites have padlocks too. The padlock means the connection is encrypted, not that the site is honest.
“It used my real name, so it must be genuine.” Names, addresses and even old passwords have been exposed in data breaches for years. A scammer knowing your name proves nothing at all.
The one that frightens people most
The email claiming to have recorded you through your webcam, quoting one of your real passwords, demanding payment.
It is a bluff, every time. The password came from an old data breach, not from your computer. There is no video. They send it to millions of addresses hoping a handful panic.
Don’t pay, don’t reply. But do change that password anywhere you still use it — because the breach it came from was real, even though the threat isn’t.
If you’ve already clicked
It happens, and to careful people. Don’t panic, but act in this order:
- If you entered a password, change it immediately — and anywhere else you used the same one. This is the urgent bit.
- If you entered card details, ring your bank now. They deal with this daily.
- If you downloaded or installed something, disconnect from the internet and bring the machine to us.
- If you only clicked and closed it, you’re most likely fine. Run a scan to be sure.
The thing that turns a scare into a real problem is delay, usually because someone is too embarrassed to mention it. Please don’t be.
When in doubt, ask
You can always forward it to us, or bring your phone or laptop into the workshop on Station Road and we’ll look at it with you. It takes a minute and it costs nothing.
You can also report scam emails to the National Cyber Security Centre by forwarding them to report@phishing.gov.uk.
Ring 01753 884700 if you’d rather talk it through. Nobody here will make you feel silly for asking — we’d far rather answer the question than clean up afterwards.
Leave a Reply