How to spot phishing in 60 seconds
A phishing message wants one thing: that you click before you think. Here is how to see through it in a minute, with no technical knowledge.
Phishing is a message — e-mail, SMS, WhatsApp, sometimes a letter — pretending to come from your bank, the government, a parcel service or a shop. It sends you to a copied website where you log in or pay. From that moment the scammers have what they came for.
The messages keep getting better: correct language, real logos, sometimes part of your details. So “look for spelling mistakes” no longer works. What does work: look at what the message wants from you, and where the link really goes.
How to spot it
- 1Urgency.“Within 24 hours”, “or your account will be blocked”, “final reminder”. Real organisations do not put a stopwatch on you.
- 2A link to log in or pay.Your bank, DigiD and the Belastingdienst do not send links to log in. They say: log in yourself, through the app or the site.
- 3The address is almost right.ing-veilig.nl is not ing.nl. postnl-bezorging.info is not postnl.nl. Look at what sits just before the last dot-and-extension: that is the real owner.
- 4A sender that does not fit.An “ING” e-mail from a gmail address or a strange domain. On a phone you only see the name — tap it to see the address.
- 5An attachment you did not expect.An “invoice” or “tax return” as .zip, .html or .docm. Do not open it.
- 6A request for a tiny amount.“Pay € 0.01 to verify”, “€ 1.99 customs fee”. The amount is not the goal; your bank details are.
- 7It comes out of nowhere.You expect no parcel, you owe no tax, you ordered nothing. Then the message is the problem, not you.
A real example, taken apart
- The domain is postnl-bezorging.info, not postnl.nl.
- PostNL never asks for shipping fees by SMS.
- You were not expecting a parcel — or you were, which is exactly why these messages work.
What you do
- Do not click; check the link.On a phone: press and hold the link to see the address. On a computer: hover over it. Or paste the address into the checker on this site.
- Go to the organisation yourself.Open the app or type the address you know. Same message there? It was real. Nothing there? It was phishing.
- In doubt? Call.The number on the back of your card, or the number on the official site. Never the number in the message.
- Report and delete.Forward the e-mail to valse-email@fraudehelpdesk.nl or your bank’s reporting address (for instance valse-email@ing.nl, valse-email@rabobank.nl, valse-email@nl.abnamro.com). Then delete it.
Never do this
- Log in through a link from a message — not even “just to see if it is real”.
- Pass on a code you receive by SMS. That code is your signature.
- Reply to the message. Then the sender knows your address works.
Dossiers of this kind
367,077 dossiers in our database match this kind — counted by what they are, not estimated. A few:
See what is being checked now →
Questions people ask
I clicked but entered nothing. Is that bad?
Usually not. Close the page, delete the message and, to be safe, change your password if the page looked like a login. Did you download or open a file? Have your device checked.
I logged in on a fake site. What now?
Call your bank immediately (the number on your card), have your card blocked and your login reset. Change the password — everywhere you use the same one. File a police report. See Scammed — what now?.
How do I know an e-mail really comes from my bank?
Not by its looks. By its behaviour: a bank sends no links to log in, never asks for your PIN or SMS code, and sets no deadline. In doubt, open the app: messages that matter are there too.
Paste it into the checker. Thirty seconds, and you know what others already saw.