Email & Messages · beginner · 10 min
Phishing: Emails That Look Legit
How to dissect a suspicious email in under a minute — sender, links, and asks — and what to do when one lands in your inbox.
- Check sender address and link targets in under a minute
- Know the asks legitimate organisations never make
- Respond correctly if you've already clicked
Dissecting a phishing email
A phishing email pretends to be someone you trust — your bank, the ATO, AusPost, a streaming service — and asks you to click, log in, or confirm details. The goal is your password, your card, or a foothold for malware.
The one-minute dissection
- Sender address, not display name. "Commonwealth Bank bob1999@randommail.net" is not from the bank. Click the sender name to reveal the real address.
- Hover every link. The visible text says "cba.com.au" but the link target should match. Hover, don't click.
- The ask. Banks and the ATO never ask you to confirm passwords, PINs, or codes by email. Never.
- The tone. Urgency + threat ("account suspended", "overdue tax") is the classic cocktail. Legitimate notices don't demand instant action.
If you clicked
Don't panic, but act fast: change the password on that account (and anywhere you reused it), enable two-factor authentication, call your bank if you entered card details, and report the email to ReportCyber at cyber.gov.au/report. Forward suspicious emails to the real organisation's reporting address if they have one.
The golden rule
When in doubt, don't click — go to the website yourself, by typing the address, and log in from there. If something is genuinely wrong, you'll see it inside your real account.