Learn
Scams, in plain English
Five minutes here can save you a lot of money and grief. No tech talk. When we have to use a tech word, we explain it.
What bait is
Scammers send emails and texts that pretend to come from someone you trust: your bank, Amazon, the post office, your boss. The message is the bait. The hook is what happens when you bite: you type your password into a fake page, pay a fake bill, call a fake support line, or open a file that takes over your computer.
They don't need to fool everyone. They send millions of messages, and a few people bite. Everyone can be fooled on a busy day, so don't feel bad if you've been close.
Spot a scam in 10 seconds
Almost every scam uses at least one of these tricks. If you see one, slow down.
- It rushes you. "Within 24 hours." "Final notice." "Your account will be closed today." Real companies rarely give you one day.
- It scares you or excites you. A locked account, a missed package, a charge you didn't make, a prize, a refund, free money.
- It wants you to act. Sign in, pay, call a number, scan a code, buy gift cards, open a file.
- The sender's address is off. The name says "PayPal", but the address after the @ is something like @pay-secure-mail.com or a random Gmail.
- The link goes somewhere else. The button says "PayPal", but the web address behind it doesn't end in paypal.com.
- It doesn't know you. "Dear customer" or just your email address, when the real company knows your name.
The golden rule: never use the link, phone number or file in a message you weren't expecting. Open the app yourself, or type the company's address yourself, and check there. If it's real, you'll see it there too.
Read a link before you tap it
On a computer, rest your mouse on the link or button without clicking. The real address shows up in a corner of the screen. On a phone, press and hold the link until a box pops up with the address. Then back out without opening it.
Now find who owns the site:
- Skip the https:// at the start.
- Find the first single / after that. Ignore everything after it.
- Look at the last two parts right before it, like paypal.com. That's the owner. Everything to the left of that can be made up.
https://www.paypal.com/signinReal. The owner is paypal.com.
https://paypal.com.account-check.net/loginFake. The owner is account-check.net. The "paypal.com" in front is just decoration.
https://paypa1.comFake. That's the number 1, not the letter L.
https://pay-paypal.com/helpFake. A dash makes it a whole different website, owned by whoever bought it.
https://paypal-login.pages.devFake. pages.dev is a free page host that anyone can use.
Some countries use a two-part ending, like .co.uk. There, the owner is the last three parts: bbc.co.uk.
A padlock in the address bar doesn't mean a site is safe. It only means the connection is private. Scam sites have padlocks too.
The “From” line can lie
The name you see next to an email is just text. Anyone can type "Chase Bank" there, the same way anyone can write any return address on an envelope. Tap or click the name to see the real address behind it.
Scammers can sometimes fake the address itself, too. A company protects its address with three settings, called DNS records, that mail services like Gmail and Outlook read before they deliver:
- SPF is a guest list. It names the servers allowed to send email for the company.
- DKIM is a seal. Each real email gets a signature that a fake can't copy.
- DMARC is the instructions for everything else: deliver it anyway, put it in spam, or block it.
When a company sets DMARC to block, fake email "from" them doesn't arrive. Many companies never finish this step, so fakes still get through.
Look-alike websites
Scammers buy web addresses that look like real ones: a swapped letter, an extra word like -login or -support, a different ending like .co instead of .com, or letters from other alphabets that look the same. Most are only days or weeks old when the scam goes out, then they vanish.
If you run a business, our Copycat check tries hundreds of these names for your domain and shows which ones someone already bought.
Scam texts and phone calls
- Unpaid toll or parking texts asking you to pay on a website.
- Missed package texts asking for a small "redelivery fee".
- Bank alerts asking you to reply YES or NO, then someone calls "from the fraud team".
- "Wrong number" chats that turn friendly, then turn into an investment tip.
Never call a phone number from a message you didn't expect. Call the number on the back of your card or on the company's real website. Your bank will never ask for your password, the code they text you, or for you to move money to a "safe account".
Anyone who asks you to pay with gift cards, crypto, or a wire transfer is a scammer. Every time.
Files and QR codes
- Fake invoices. A PDF says you were charged $499 for antivirus or a subscription, and to call a number to cancel. The person on the phone wants remote access to your computer or your bank login.
- Files that open web pages. An attachment ending in .html or .htm opens a fake sign-in page right on your computer.
- Zip files and "enable editing". Don't open zipped files you didn't expect, and never click "Enable content" or "Enable macros" in a document.
- QR codes in emails. A code "to set up your security" or "to view the document" is a link in disguise, and your phone opens it without showing much. Treat it like any other link.
Already clicked? Do this now
Don't panic. Most damage can be undone if you move quickly. Do the steps that match what happened:
- You typed a password. Change it right away on the real site. Type the address yourself. If you use the same password anywhere else, change it there too.
- Turn on two-step sign-in for that account, so a password alone isn't enough to get in.
- You gave card or bank details. Call your bank using the number on the back of your card. Ask them to block the card and watch for charges.
- You let someone into your computer or installed something they asked for. Disconnect from the internet, then get help from someone you trust before you sign in to anything.
- You paid with gift cards. Call the gift card company right away and tell them it was a scam. Keep the cards and receipts.
- Someone may use your identity. Go to IdentityTheft.gov for a step-by-step plan.
Report it
- Not sure? Forward the email to bite@bait.sh. We open every link and file in a sealed sandbox and tell you what's really going on. We're in private beta, so join the list to get in.
- Forward scam emails to reportphishing@apwg.org, a group that shares them with companies that block scams.
- Forward scam texts to 7726 (it spells SPAM). Your phone company uses them to block the sender.
- If you lost money, tell the FTC at ReportFraud.ftc.gov.
Words you'll hear
- Phishing
- A scam email that fishes for your password, money or personal details.
- Smishing
- The same thing by text message.
- Vishing
- The same thing by phone call or voicemail.
- Spoofing
- Faking who a message or call comes from.
- Malware
- Software made to harm you: steal passwords, lock your files, or spy on you.
- Domain
- The name part of a web or email address, like paypal.com.
- Two-step sign-in
- A second check when you sign in, like a code on your phone. Also called 2FA.
Want a second pair of eyes?
Forward any sketchy email and get a plain-English answer in minutes. Join the list to get in.