An email claims your account will be blocked, a parcel is waiting or a payment has failed, and asks you to click a link. Behind it is usually a copied login page that collects passwords, card details or transaction codes. This article shows how to check such an email without touching anything, where you can forward it and what to do if you have already clicked.
Check first, touch later
Phishing emails follow a pattern that can be read from the email itself. The figure shows a recreated sample email with five red flags. The sender domain and the file are invented; in everyday life they usually look more convincing.
- Look at the sender.
Look at the full address as well as the displayed name. The police advise looking at whether it ends in the genuine domain. A name such as “Customer service” in front of an unrelated address is a warning sign.
- Check the link target without clicking.
Look at the target without opening it. The BSI writes that the link often hides behind a perfectly designed button. Rather open the provider’s site yourself by typing the address into your browser.
- Do not open the attachment.
The consumer advice centre advises being suspicious of attachments as a rule. The checklist from the BSI and the police names file endings such as .exe or .scr and double extensions such as .pdf.exe as warning signs.
- Read the greeting, pressure and demand.
A generic greeting, deadlines, threats and a request to enter data fit phishing, according to the consumer advice centre. Banks never ask for a PIN or transaction code by email.
- Look at the recipient field and header.
If your address is not in the To field, the email may have been sent as a mass mailing with hidden recipients. The mail header contains the sender’s IP address. According to the consumer advice centre, only that is forgery-proof.
There are limits all the same. The consumer advice centre points out that some phishing emails are very well made: the sender address looks credible, so does the link, and the German is flawless. Sender details can be forged as well. If you are unsure, call the provider on a phone number you look up yourself, not the one in the email.
Having the email checked on onlinebetrug.ai
If you do not want to judge the email yourself, you can have it examined under Check an email. We read the sender, links and attachments and show you what we noticed. You have three routes:
- Forward to the disposable address. The page creates an address for you. Forward the email there and follow the report live. Forwarded as an attachment, we see the headers of the original email and can check the sender. A normal forward also works, but then this sender check is missing.
- Upload as an .eml file. Save the email as a file and upload it on the page, 10 MB at most. In Gmail this is called “Download message”, in Outlook on the web “Download”.
- Text or screenshot for messages. For texts and messenger messages there is Check a message. There you paste the text or upload a screenshot.
A report does not replace your own judgement or a query to the provider. If nothing stands out, that is no guarantee, because new scams are not known straight away. We collect current cases under Warnings. How the same scam looks by text message is described in the guide Text scams with a forged sender.
Where to forward the email
Forward the email before you delete it. This helps others, because the organisations derive warnings from reported emails.
- Phishing radar of the Consumer Advice Centre NRW. Send the email to phishing@verbraucherzentrale.nrw. If that does not work, you can upload it as an .eml file on the phishing radar page, where a limit of 2 MB applies. By its own statement the consumer advice centre cannot reply because of the volume. For this address it recommends forwarding directly, not as an attachment.
- The genuine provider or your bank. The consumer advice centre advises also sending the email to the provider in whose name it was written, so that it can act against the fraud. The police note that banks often have dedicated phishing reporting points. The address is usually in the contact area of the website.
- Police. If a loss has occurred or you suspect that data was captured, the checklist from the BSI and the police advises filing a report in every case, even on vague suspicion. You will find your state’s online police station under Where to report it.
- Federal Network Agency. It is not responsible for pure phishing emails. According to its page, it can only act on email spam if the message contains a phone number.
Only delete the email once you have forwarded it. If you have already clicked or opened an attachment, do not delete it at all: in that case the consumer advice centre calls it important evidence for the police. How to secure evidence is under Already paid?. The text-message variant is described in the guide SMS fraud with a faked sender.
Already clicked or entered details
A click alone does not cause harm in every case. What to do depends on what happened afterwards. The figure follows the checklist from the BSI and the police.
What happened?
Only clicked or opened an attachment
- Enter nothing, close the page
- Check the device for malware
- Change passwords
- Do not delete the email
Entered login details
- Set a new password
- Contact the provider
- For an email account: reset other accounts
Entered payment details
- Block account or card
- Check transactions
- Inform the bank
- File a police report
Filing a police report is possible in every case, even on vague suspicion.
Sources: BSI and police crime prevention: Phishing, emergency checklist; BSI: Forged email addresses, what to do
The BSI advises checking your computer for malware immediately after a click and, if anything is found, changing all important passwords, above all for email and finance. If someone demands payment after the click, pay nothing. Turn to the police, the consumer advice centre or legal advice.
If you entered the login details of your email account, a new password for that account is often not enough. Through the mailbox, passwords of other services can be reset, so these should be reissued as well. Where possible, set up two-factor login. According to the checklist, with the second step criminals cannot reach your data even if they have captured the password.
If money was debited
Report every debit you did not initiate to your bank as early as possible. For an unauthorised payment, the bank must refund the amount without delay under Section 675u of the German Civil Code, at the latest by the end of the business day after your report. Cases are excluded where the bank has given an authority written notice of a justified suspicion of fraud. Whether the bank pays in an individual case also depends on how the approval came about.
Under Section 676b, your claims lapse if you do not inform the bank within 13 months of the debit at the latest. Further steps are under Already paid?. The scam with a changed account number on an invoice is described in the guide New bank details on an invoice.
