Phishing Emails UK: Spot a Fake, Check It, Report It

Fake bank, HMRC, PayPal, Netflix and Microsoft emails all run the same play. How to check a suspicious email safely and report phishing in the UK.

Email is where scammers do their most patient work. An email can carry a pixel-perfect copy of a company's branding, a hidden link, an attachment and a reply address that looks right at a glance. Your inbox is also the master key to everything else you own — password resets for your bank, your shopping accounts and your social media all land there — so an email scam that succeeds rarely stops at one payment.

Many phishing emails are one of two things: a manufactured problem ('your payment failed', 'your account is suspended') or a manufactured windfall ('you're owed a refund', 'exclusive presale tickets'). Both exist to make you act inside the message instead of checking the account itself. Not sure about one? Paste it into our free AI scam checker for an automated second opinion — it is a fallible assessment, not a verdict, so check the claim independently as well by opening the official app or typing the company's address yourself.

The most common UK phishing emails

Bank emails are the classic: an 'unusual activity' or 'account locked' warning with a button leading to a convincing sign-in page — see fake HSBC 'verify your details' emails, Santander 'restore access' emails and NatWest 'unusual activity' emails.

Billing and subscription emails run the same play using services you really do pay for — a failed Netflix payment, a limited PayPal account, an Amazon order or refund problem, or a Microsoft account facing suspension.

Official-looking emails borrow a public body's authority: a tax rebate you can supposedly claim through a link, a DVLA vehicle tax or fine notice, a TV Licence payment failure, or a Companies House filing demand aimed at company directors.

Three more break the mould entirely: CEO fraud, where the sender appears to be your own boss; sextortion emails demanding cryptocurrency; and seasonal lures such as fake festival presale emails timed to a lineup announcement.

Which email have you actually got?

The right response depends on what the message wants you to do. Find your situation below.

  • A payment or account problem at a company you really use. Your instinct is to fix it immediately, and that instinct is the product being sold. Don't use the email — open the app or type the address yourself and see whether the same message is waiting in your account, as our Netflix billing and PayPal 'account limited' guides show.
  • A problem at a company you have no account with. Do not act through the message; report and delete it, while remaining alert to follow-up targeting.
  • A request to move money, change an invoice's bank details or buy gift cards, apparently from a colleague or supplier. That is business email compromise — read the CEO fraud guide before you touch the payment.
  • A threat to publish webcam footage unless you pay in cryptocurrency. These go out in bulk to addresses harvested from old breaches, and such a demand is usually part of a bulk bluff; the sextortion email guide explains how to respond without paying or replying. If real intimate images of you do exist, treat it as a different problem and use the response set out further down this page.
  • An offer you never asked for. Treat it as a likely phishing attempt; it may seek details, payment or malware installation — see the HMRC rebate email and festival presale patterns.
  • You downloaded a file, opened an attachment, installed an app, granted a permission, or your device has since behaved oddly. That is a possible device compromise rather than a simple phishing email, and it needs its own steps — see the device branch below.
  • Your own account sending mail you didn't write, or a login that no longer works. That is a compromise rather than phishing: work through how to recover a hijacked email account straight away.

How to check a suspicious email safely

  • Never use the link, button or phone number in the email. Open the official app, or type the company's address into a new tab yourself, and look for the same problem inside the account.
  • Treat the sender address as a clue, not an answer. Display names are trivially faked and reply addresses can be spoofed. A lookalike domain — micros0ft.com for microsoft.com — is a strong warning sign, but a convincing address is not evidence a message is genuine.
  • Judge the request, not the channel. Banks, HMRC, TV Licensing and retailers all run genuine email campaigns, and some include links. No genuine bank employee will ask you to disclose or read out a full PIN, full password or one-time banking or security code. Enter a code only in the official app or site, for an action you initiated, understand and can match to the code message; never do it at an unexpected caller's direction — a criminal can talk you through a genuine app while dictating the action you are approving. For another support service, verify the request independently and follow the warning in the code message. Do not enter credentials into a page reached from an unexpected message.
  • Don't open unexpected attachments, and distrust any deadline measured in hours — it exists to stop you checking.

The expensive minority: invoice and CEO fraud

Email is a rare starting point for authorised push payment fraud but a disproportionately costly one. UK Finance's Annual Fraud Report 2026 attributes around 1% of APP fraud cases to email and about 7% of the money lost — figures, periods and sources are in our UK scam statistics dataset. The emails that get through tend to be the ones aimed at businesses and at people in the middle of a large payment.

That is the shape of CEO fraud and its invoice-fraud cousin: no malware and no fake login page, just a confidential, urgent request to pay a real-looking invoice into a new account. A genuine-looking internal address is not evidence the request is real — verify with the named person through a channel you already had, never the contact details in the email. A Companies House email demanding payment or your company authentication code deserves the same treatment: Companies House says it will not ask for a company authentication code by telephone or email, so start fresh at GOV.UK.

If you clicked, paid or replied

  • Entered card or bank details? Contact your bank using the number on your card or statement or its official app. If your bank and phone provider participate, you can also dial 159; if it does not connect, use the number on your card. Your provider sets the price of the call. Ask for the card to be blocked.
  • Disclosed a password, or typed one into a page you reached from the message? Change it through the service's official app or an address you type yourself, then change it anywhere else you reused it, and turn on two-step verification or a passkey. Then check for forwarding rules, filters and recovery addresses you did not set — attackers add them to keep reading your mail after the password changes, which is why the account takeover checklist puts that step first.
  • Downloaded a file, opened an attachment, installed an app or granted a permission? Opening a link is not always the end of it. If you downloaded or ran anything, allowed a browser or device permission, saw a security warning, or your device has since behaved unusually — unfamiliar apps or profiles, settings you did not change, sudden battery or data use — install the pending operating-system and app updates, run the security checks your device or security software provides, remove anything you did not deliberately install, revoke permissions you did not intend to grant, and change your passwords from a device you trust. If the odd behaviour continues, get help from a trusted support route such as the device manufacturer's own support channel.
  • Sent money by bank transfer? Tell your bank immediately. Eligible domestic consumer payments by Faster Payments or CHAPS made on or after 7 October 2024 may fall within the mandatory APP reimbursement rules, subject to exclusions, an £85,000 cap, a 13-month outer reporting limit and a possible excess of up to £100 that cannot be applied to a consumer the firm assesses as vulnerable. Reimbursement is not guaranteed, and reporting quickly matters.
  • Shared personal details? Watch for identity fraud, check your credit reports, and consider a Cifas Protective Registration at cifas.org.uk.
  • Being threatened with real intimate images? Do not pay and do not reply. Keep the evidence — the message, the account name and any payment demand — and report an immediate threat to the police. Adults in the UK can get support from the Revenge Porn Helpline. StopNCII may help if you are currently 18 or over, were 18 or over when the image or video was created, are the person depicted, and still have the file; it creates a hash on your own device for use by participating platforms and does not upload the image. The sextortion email guide sets out the steps in order.
  • Keep the email as evidence, then work through the remaining payment, account and identity steps in our scam recovery checklist.

How to report a scam email in the UK

Forward suspicious emails to the National Cyber Security Centre at report@phishing.gov.uk. HMRC-branded phishing goes to phishing@hmrc.gov.uk and Companies House-branded phishing to phishing@companieshouse.gov.uk. Most large brands also run their own abuse mailbox or an in-product 'report phishing' option; take the current address from the security or help pages of their official website rather than from the email in front of you. If you have lost money or shared details, report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or to Police Scotland on 101 in Scotland. A suspicious website or link can be reported to the NCSC through its own suspicious-website reporting form, and a suspicious SMS text can be forwarded free to 7726.

All email scams guides

Email Scams

TV Licence Scam Email UK: How to Spot a Fake

TV Licensing uses several genuine sender addresses, and scammers can spoof them — so check your licence at tvlicensing.co.uk rather than trusting the sender.

Updated

Email Scams

PayPal Account Limited Email Scam UK

An email says your PayPal account is limited and you must verify now? Log in directly instead. Genuine emails use your account name.

Updated

Email Scams

HMRC Tax Rebate Email Scam: Spot a Fake (UK)

An HMRC email saying you're owed a tax rebate, with a link to claim? Real rebates aren't claimed through an email link — how to spot the scam and check safely.

Updated

Common questions

How can I tell a phishing email from a real one?

Judge what the message asks you to do, not how it looks. Branding is easy to copy and genuine organisations do send emails containing links. No genuine bank employee will ask you to disclose or read out a full PIN, full password or one-time banking or security code. Enter a code only in the official app or site, for an action you initiated, understand and can match to the code message; never do it at an unexpected caller's direction — a criminal can talk you through a genuine app while dictating the action you are approving. For another support service, verify the request independently and follow the warning in the code message. Do not enter credentials into a page reached from an unexpected message.

Does the sender's email address show whether a message is genuine?

No. Display names are easy to fake and reply addresses can be spoofed, so a convincing sender is not evidence the email is real. A lookalike domain — extra words, hyphens or a swapped character such as micros0ft.com — is a strong warning sign, but its absence tells you nothing either way. Check the claim inside your own account instead.

I clicked a link in a phishing email — what should I do?

If you only opened the page and entered nothing, that does not automatically mean the device is compromised: close it, report the suspicious website to the NCSC, run the security check your device or security software provides, and check for any unexpected download, app, profile, permission or security warning. If any occurred, or the device behaves unusually, follow the device-compromise steps below. If you entered card or bank details, contact your bank using the number on your card or statement or its official app. If your bank and phone provider participate, you can also dial 159; if it does not connect, use the number on your card. Your provider sets the price of the call. If you disclosed a password or typed one into that page, change it through the service's official app or an address you type yourself, then anywhere else you reused it, turn on two-step verification, and check your email for forwarding rules or filters you did not create. If you downloaded a file, opened an attachment, installed an app, granted a permission, saw a security warning or your device has since behaved oddly, treat it as a possible device compromise: update the device, run its security checks, remove anything you did not install, and seek trusted support if it continues.

Should I reply to a sextortion email or pay?

No. These are sent in bulk and the demand is usually part of a bulk bluff, often quoting a password taken from an old data breach to make it feel specific. Paying invites more demands and replying confirms your address is live. Change that password if you still use it and report the email. If real intimate images of you do exist, keep the evidence, still do not pay, report an immediate threat to the police, and get support from the Revenge Porn Helpline. StopNCII may help if you are currently 18 or over, were 18 or over when the image or video was created, are the person depicted, and still have the file.

Where do I report a scam email in the UK?

Forward it to the National Cyber Security Centre at report@phishing.gov.uk. Use phishing@hmrc.gov.uk for HMRC-branded messages and phishing@companieshouse.gov.uk for Companies House-branded ones. If money or personal details were lost, report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or to Police Scotland on 101 in Scotland.

Check a message Start recovery