Phishing Emails and Smishing Texts: How to Spot Fake Messages

Most people encounter a phishing email or scam text nearly every week without necessarily recognising it. The UK’s National Cyber Security Centre (NCSC) is the government body that tracks and helps take down these campaigns at scale, and its guidance gives a specific, checkable set of signs rather than a vague “trust your instincts.”

What phishing and smishing actually are

Phishing is when criminals use scam emails, text messages (smishing) or phone calls (vishing) to trick you into visiting a fake website, downloading malicious software, or handing over personal or financial details directly. The goal is almost always one of: stealing login credentials, stealing payment details, or getting malicious software installed on your device.

Specific signs the NCSC recommends checking for

  • Urgency or pressure. An “amazing,” time-limited offer, or strong pressure to “click here now” — urgency is a deliberate tactic to stop you thinking it through.
  • Generic greetings. An email or text that doesn’t use your actual name, when a real organisation holding your details normally would.
  • Spelling and grammar mistakes. Genuine organisations’ official communications are usually well-proofed; scam messages often aren’t.
  • Branding that’s almost right, but not quite. Logos, colours or formatting that look familiar but slightly “off” compared to the real organisation’s usual communications.
  • A mismatched sender address. An email address or sending number that looks similar to a real company’s but doesn’t actually match — check the full address, not just the display name, since display names can be faked entirely.

What to do with a suspicious message

The core NCSC advice is simple and specific: don’t click any links, don’t open any attachments, and don’t enter any information into a linked page, even if it looks legitimate. If a message claims to be from your bank, HMRC, a delivery company or similar, and you want to check it’s genuine, go directly to the organisation’s known website or app yourself, or call them using a number from a genuine source (like the back of your card or a previous statement) — never a number or link provided in the suspicious message itself.

How to report it — and why it’s worth doing even with no loss

The NCSC operates dedicated, free reporting routes specifically so it can investigate and take down scam infrastructure, not just log individual complaints:

  • Suspicious emails: forward them to [email protected].
  • Suspicious text messages: forward them, free of charge, to 7726 — most UK mobile providers support this.
  • Suspicious websites: can be reported directly to the NCSC via its website reporting tool.

Reporting takes under a minute and genuinely matters at scale: the NCSC has the ability to investigate and take down scam email addresses and websites once enough evidence is gathered, which protects other people even if you personally weren’t fooled by a particular message.

If you’ve already clicked a link or entered details

  • If you’ve entered your bank details or made a payment, contact your bank immediately using the number on your card or their official app, not any number from the suspicious message.
  • If you’ve entered a password, change it immediately on the genuine site, and change it anywhere else you’ve reused the same password.
  • If you’ve downloaded a file or app you now suspect was malicious, run a security scan and consider seeking IT support, particularly if the device holds sensitive information.
  • Report the incident to Action Fraud (actionfraud.police.uk) if money or significant personal data has been lost, alongside reporting the original message to the NCSC.

A habit worth building

The most reliable long-term protection isn’t spotting every clever fake — some are genuinely well made. It’s building the habit of never acting (clicking, calling back, entering details) directly from an unsolicited message, and instead going to the organisation independently, every time, regardless of how convincing the message looks. That single habit defeats the large majority of phishing and smishing attempts, however sophisticated the fake.

Sources