Be Scam Aware

Email & Messages · beginner · 10 min

Phishing: Emails That Look Legit

How to dissect a suspicious email in under a minute — sender, links, and asks — and what to do when one lands in your inbox.

Dissecting a phishing email

A phishing email pretends to be someone you trust — your bank, the ATO, AusPost, a streaming service — and asks you to click, log in, or confirm details. The goal is your password, your card, or a foothold for malware.

The one-minute dissection

  1. Sender address, not display name. "Commonwealth Bank bob1999@randommail.net" is not from the bank. Click the sender name to reveal the real address.
  2. Hover every link. The visible text says "cba.com.au" but the link target should match. Hover, don't click.
  3. The ask. Banks and the ATO never ask you to confirm passwords, PINs, or codes by email. Never.
  4. The tone. Urgency + threat ("account suspended", "overdue tax") is the classic cocktail. Legitimate notices don't demand instant action.

If you clicked

Don't panic, but act fast: change the password on that account (and anywhere you reused it), enable two-factor authentication, call your bank if you entered card details, and report the email to ReportCyber at cyber.gov.au/report. Forward suspicious emails to the real organisation's reporting address if they have one.

The golden rule

When in doubt, don't click — go to the website yourself, by typing the address, and log in from there. If something is genuinely wrong, you'll see it inside your real account.