Guides

How to spot phishing in 60 seconds

A phishing message wants one thing: that you click before you think. Here is how to see through it in a minute, with no technical knowledge.

Phishing is a message — e-mail, SMS, WhatsApp, sometimes a letter — pretending to come from your bank, the government, a parcel service or a shop. It sends you to a copied website where you log in or pay. From that moment the scammers have what they came for.

The messages keep getting better: correct language, real logos, sometimes part of your details. So “look for spelling mistakes” no longer works. What does work: look at what the message wants from you, and where the link really goes.

How to spot it

  1. 1
    Urgency.“Within 24 hours”, “or your account will be blocked”, “final reminder”. Real organisations do not put a stopwatch on you.
  2. 2
    A link to log in or pay.Your bank, DigiD and the Belastingdienst do not send links to log in. They say: log in yourself, through the app or the site.
  3. 3
    The address is almost right.ing-veilig.nl is not ing.nl. postnl-bezorging.info is not postnl.nl. Look at what sits just before the last dot-and-extension: that is the real owner.
  4. 4
    A sender that does not fit.An “ING” e-mail from a gmail address or a strange domain. On a phone you only see the name — tap it to see the address.
  5. 5
    An attachment you did not expect.An “invoice” or “tax return” as .zip, .html or .docm. Do not open it.
  6. 6
    A request for a tiny amount.“Pay € 0.01 to verify”, “€ 1.99 customs fee”. The amount is not the goal; your bank details are.
  7. 7
    It comes out of nowhere.You expect no parcel, you owe no tax, you ordered nothing. Then the message is the problem, not you.

A real example, taken apart

SMS from “PostNL”
Your parcel could not be delivered. Schedule a new delivery and pay € 1.99 shipping: postnl-bezorging.info/track
Why this is fake
  • The domain is postnl-bezorging.info, not postnl.nl.
  • PostNL never asks for shipping fees by SMS.
  • You were not expecting a parcel — or you were, which is exactly why these messages work.

What you do

  1. Do not click; check the link.On a phone: press and hold the link to see the address. On a computer: hover over it. Or paste the address into the checker on this site.
  2. Go to the organisation yourself.Open the app or type the address you know. Same message there? It was real. Nothing there? It was phishing.
  3. In doubt? Call.The number on the back of your card, or the number on the official site. Never the number in the message.
  4. Report and delete.Forward the e-mail to valse-email@fraudehelpdesk.nl or your bank’s reporting address (for instance valse-email@ing.nl, valse-email@rabobank.nl, valse-email@nl.abnamro.com). Then delete it.

Never do this

Dossiers of this kind

367,077 dossiers in our database match this kind — counted by what they are, not estimated. A few:

See what is being checked now →

Questions people ask

I clicked but entered nothing. Is that bad?

Usually not. Close the page, delete the message and, to be safe, change your password if the page looked like a login. Did you download or open a file? Have your device checked.

I logged in on a fake site. What now?

Call your bank immediately (the number on your card), have your card blocked and your login reset. Change the password — everywhere you use the same one. File a police report. See Scammed — what now?.

How do I know an e-mail really comes from my bank?

Not by its looks. By its behaviour: a bank sends no links to log in, never asks for your PIN or SMS code, and sets no deadline. In doubt, open the app: messages that matter are there too.

Unsure about a website, number or e-mail?
Paste it into the checker. Thirty seconds, and you know what others already saw.
Check it now

Read next

Sources

Fraudehelpdesk — report a fake e-mail · Veilig bankieren

← All guides