Bank email: scam or real? — check safely
Fast route: real bank emails exist — but links and attachments are still unsafe. Verify only inside the app or on the official site you open manually.
What to do now (safe route)
Do you see the same alert/notice inside your bank app?
Route A — email matches a real in-app alert (email still not trusted)
- Do not click links in the email
- Follow steps only inside the app / official site opened manually
- If the email asks for codes, passwords, or document upload → treat as suspicious anyway
Route B — nothing like this in-app
- Treat as scam if the email pushes urgency, threats, or asks you to click
- Contact the bank using the number on your card or the official website
- If you shared anything, secure your email first, then contact the bank
Common bank email types (and how to treat them)
- Informational (statements, receipts, “your monthly report is ready”) → verify in-app, usually no action
- Security alert (new device, unusual login, attempted payment) → verify in-app, call bank if unsure
- Verification request (documents, selfie, “confirm identity”) → higher risk; complete only in-app or official site opened manually
- Marketing disguised as urgent (“limited time”, “unlock reward”, “confirm to avoid closure”) → treat as suspicious; verify via official channels
Red flags (high scam likelihood)
- Asks for OTP/SMS codes, PIN, password, full card number → scam
- Reply-To address differs from the sender domain → phishing pattern
- Pressure + threats (“account will close”, “police”, “last warning”) → scam pattern
- Link domain doesn’t exactly match the bank’s official domain → high risk
- Attachment (“invoice”, “security update”) → high risk
- QR code to “verify” or “unlock” → common scam pattern
- Asked to install AnyDesk/TeamViewer / screen share → account takeover pattern
How to verify safely (without clicking)
- Open the bank app from the icon → check alerts/messages inside the app
- Type the bank website manually (or use a saved bookmark) → never use the email link
- Check the exact sender domain (not the display name)
- Check “Reply-To” (if it differs from the bank domain, treat as high risk)
- Never reply to the email thread to ask if it’s real — start a new contact via official channels
- Call the bank using an official number (card back / official website)
- If anything is unclear: assume scam and verify via official channels
Risk
If you shared codes/details or installed anything: act immediately
Common questions
Why do scams look like real bank emails?
Attackers copy branding and wording, and may spoof sender names. That’s why the safe method is process-based: verify in-app or via official channels, not by “how it looks”.
Can a real bank email still be unsafe?
Yes. Even real-looking emails can be spoofed or forwarded. Treat links and attachments as unsafe by default. Verify inside the app or on the official site you opened manually.
Is checking the sender name enough?
No. Display names can be faked. Check the exact sender domain and the Reply-To address. Then verify via the app or official contact channels.
Can banks ask for OTP/SMS codes?
Banks do not ask you to share OTP/SMS codes with anyone. If someone asks for a code, assume scam.
What if the email says “urgent” and gives a deadline?
Deadlines can exist, but pressure and threats are common scam tactics. Do not click. Verify in-app or call the bank using the number on your card.
Should I reply to the email to ask “is this real”?
No. Don’t continue the conversation in the same thread. Start a new contact via official channels (bank app chat, number on the card, official website).
What if I already clicked the link?
Do not enter credentials. Close the page. Open the bank app from the icon and check alerts. If you entered anything, change your banking password via the official app/site and secure your email.
What if I entered my password or shared an OTP?
Treat it as urgent. Secure your email account first, then contact the bank via official number. Ask the bank to freeze card/account access as needed and review recent activity.
Is it safe to open the attachment if it’s a PDF statement?
Treat attachments as unsafe. Get statements inside the bank app or from the official site you opened manually.
Do scams always have bad spelling or weird design?
No. Many scams look professional. The strongest signals are requests for codes/credentials, pressure tactics, and directing you outside the app via links/attachments.
What if the email matches an in-app alert — is the email safe then?
Not automatically. It may be related, but you still should not click the email link. Use the app to complete any steps.
What should I do if I’m still unsure?
Assume scam and verify via official channels. Calling the bank using the number on your card is the safest default.
Related banking messages
Related security concepts
Authoritative resources on phishing and account takeover.
ClearExplained — simple pages that remove panic and reduce mistakes.