Learn

Scams, in plain English

Five minutes here can save you a lot of money and grief. No tech talk. When we have to use a tech word, we explain it.

What bait is

Scammers send emails and texts that pretend to come from someone you trust: your bank, Amazon, the post office, your boss. The message is the bait. The hook is what happens when you bite: you type your password into a fake page, pay a fake bill, call a fake support line, or open a file that takes over your computer.

They don't need to fool everyone. They send millions of messages, and a few people bite. Everyone can be fooled on a busy day, so don't feel bad if you've been close.

Spot a scam in 10 seconds

Almost every scam uses at least one of these tricks. If you see one, slow down.

The golden rule: never use the link, phone number or file in a message you weren't expecting. Open the app yourself, or type the company's address yourself, and check there. If it's real, you'll see it there too.

On a computer, rest your mouse on the link or button without clicking. The real address shows up in a corner of the screen. On a phone, press and hold the link until a box pops up with the address. Then back out without opening it.

Now find who owns the site:

  1. Skip the https:// at the start.
  2. Find the first single / after that. Ignore everything after it.
  3. Look at the last two parts right before it, like paypal.com. That's the owner. Everything to the left of that can be made up.

https://www.paypal.com/signinReal. The owner is paypal.com.

https://paypal.com.account-check.net/loginFake. The owner is account-check.net. The "paypal.com" in front is just decoration.

https://paypa1.comFake. That's the number 1, not the letter L.

https://pay-paypal.com/helpFake. A dash makes it a whole different website, owned by whoever bought it.

https://paypal-login.pages.devFake. pages.dev is a free page host that anyone can use.

Some countries use a two-part ending, like .co.uk. There, the owner is the last three parts: bbc.co.uk.

A padlock in the address bar doesn't mean a site is safe. It only means the connection is private. Scam sites have padlocks too.

The “From” line can lie

The name you see next to an email is just text. Anyone can type "Chase Bank" there, the same way anyone can write any return address on an envelope. Tap or click the name to see the real address behind it.

Scammers can sometimes fake the address itself, too. A company protects its address with three settings, called DNS records, that mail services like Gmail and Outlook read before they deliver:

When a company sets DMARC to block, fake email "from" them doesn't arrive. Many companies never finish this step, so fakes still get through.

Check any company's domain

Look-alike websites

Scammers buy web addresses that look like real ones: a swapped letter, an extra word like -login or -support, a different ending like .co instead of .com, or letters from other alphabets that look the same. Most are only days or weeks old when the scam goes out, then they vanish.

If you run a business, our Copycat check tries hundreds of these names for your domain and shows which ones someone already bought.

Scam texts and phone calls

Never call a phone number from a message you didn't expect. Call the number on the back of your card or on the company's real website. Your bank will never ask for your password, the code they text you, or for you to move money to a "safe account".

Anyone who asks you to pay with gift cards, crypto, or a wire transfer is a scammer. Every time.

Files and QR codes

Already clicked? Do this now

Don't panic. Most damage can be undone if you move quickly. Do the steps that match what happened:

  1. You typed a password. Change it right away on the real site. Type the address yourself. If you use the same password anywhere else, change it there too.
  2. Turn on two-step sign-in for that account, so a password alone isn't enough to get in.
  3. You gave card or bank details. Call your bank using the number on the back of your card. Ask them to block the card and watch for charges.
  4. You let someone into your computer or installed something they asked for. Disconnect from the internet, then get help from someone you trust before you sign in to anything.
  5. You paid with gift cards. Call the gift card company right away and tell them it was a scam. Keep the cards and receipts.
  6. Someone may use your identity. Go to IdentityTheft.gov for a step-by-step plan.

Report it

Words you'll hear

Phishing
A scam email that fishes for your password, money or personal details.
Smishing
The same thing by text message.
Vishing
The same thing by phone call or voicemail.
Spoofing
Faking who a message or call comes from.
Malware
Software made to harm you: steal passwords, lock your files, or spy on you.
Domain
The name part of a web or email address, like paypal.com.
Two-step sign-in
A second check when you sign in, like a code on your phone. Also called 2FA.

Want a second pair of eyes?

Forward any sketchy email and get a plain-English answer in minutes. Join the list to get in.