Phishing

Why Your Email Is Worthless Without This One Check

Stop falling for phishing emails. A seasoned Indian cyber-crime observer shares the one habit that actually works—and why banks won't tell you.

CyberSathi DeskAI-assisted · editorially reviewed
Why Your Email Is Worthless Without This One Check

Why Your Email Is Worthless Without This One Check

Last month, a woman in Gurugram lost ₹2.3 lakhs to a single email.

Not a malware link. Not a fake app. Just an email that looked like it came from her ICICI Bank. She clicked. She typed her username. She typed her password. She typed her OTP. By the time she realised what had happened, the money was gone—transferred out in seven separate UPI transactions to accounts she did not recognise.

When I asked her what made her click, she said: "It had the ICICI logo. It said my account was locked. It had a phone number at the bottom that matched what I found online."

She did everything "right" except one thing.

She did not check where the email actually came from.

The Thing No One Teaches You

You probably know you should not click suspicious links. You probably know not to share your OTP. You probably know that banks never ask for passwords via email. These lessons are everywhere now—on WhatsApp forwards, on news channels, in awareness posters at your local grocery store.

But I have watched this play out in Mumbai, Bengaluru, and small towns across Rajasthan for fifteen years. The single most reliable way to catch a phishing email before you lose money is not on that list.

It is this: Check the sender's email address, not the sender's name.

I know. It sounds stupidly simple. That is because it is. And yet.

Your email client shows you what the scammer wants you to see. The name line at the top—"ICICI Bank", "Amazon Customer Support", "SBI Alert"—that is window dressing. The scammer can put anything there. What they cannot easily fake (though they try) is the part after the @.

If the email says it is from your bank, the real address should end with @icicibank.com or @sbi.co.in. Anything else is not your bank. Not close to it. Not in a different server. Not a regional branch. A phishing email.

The Gurugram woman's email came from "support@icicibanks-secure.com".

She never checked.

Why This Actually Works

When you receive an email in Gmail, Outlook, or the Mail app on your phone, there is a sender field. Most people look at the display name only—the part before the email address. That display name is trivial to fake. Scammers can register "ICICI Bank" as the name that shows up in your inbox. Your email client will display it right alongside a real email from your actual bank.

The domain—the part after the @ sign—is harder to counterfeit in a way that passes inspection. A scammer could register icicibanks-secure.com or icici-bank.in or a hundred variations that look right when you glance at them quickly. But these are not the official domains. They are registrations they made themselves, using money and effort.

To check: open the email. Look for the sender's address. On Gmail, click the three dots next to the sender's name and select "Show original." On Outlook, right-click the sender and select "View message details." On most phones, look for a down arrow or info icon next to the sender.

Read the full email address. Not the name. The address.

If it does not match the official domain of the organisation, do not click anything. Do not reply. Do not call the number in the email. Delete it and move on.

That is it. That is the whole technique.

The Complication: Scammers Know This Too

Yes, the technique works. But scammers are not standing still. They have gotten smarter about the domains they register. They buy addresses that are one letter off from the real thing: "iccibank.com" instead of "icicibank.com". They use lookalike characters—the number 0 instead of the letter O, or Cyrillic letters that render identically in some fonts. They will register a domain, send a few hundred emails in one day, and abandon it the next.

So checking the domain stops most phishing emails. Not all.

This is the hard part that no awareness campaign wants to say out loud: there is no single check that guarantees safety. The domain check stops the sloppy attacks. The ones sent to millions of people at random. But a scammer who has done their homework—who has registered a near-perfect fake domain, who has spoofed the sender's address at the mail server level—can still get through.

Which is why the second habit matters as much as the first.

If you receive an email claiming to be from your bank, asking you to verify your account, update your details, or confirm a transaction—and it has a link—ignore the link entirely.

Instead, open your web browser yourself. Type the bank's website directly into the address bar (do not click a link, do not search for it, do not use a bookmark from last month). Log in using your credentials. Navigate to the section that matches what the email claimed. If there is a real alert, you will see it there.

If there is nothing, the email was fake.

Nine times out of ten, this is what catches the attack. Not the domain check. The refusal to click.

I watched a software engineer in Bengaluru fall for a phishing email last year. He checked the domain. It looked right. He clicked anyway, thinking "I will just check my bank's site directly after." But the link took him to a fake login page that looked identical to his bank's real site. He typed his credentials. The page showed an error. He typed them again, more slowly. The page showed another error. He gave up and opened his actual bank app on his phone.

Everything was normal. His account had not been locked.

But the credentials had been captured. It took his bank thirty-six hours to spot the fraudulent login attempts from a VPN in Vietnam. By then, the scammers had already set up two fake UPI IDs linked to his account and were testing small transactions.

He had checked the domain. The domain was real—almost. It was iccibank.in, registered in his own name using a forged ID, and active for less than forty-eight hours. His real bank is icicibank.com.

He lost ₹41,000 before the bank's fraud team reversed the transactions. He felt stupid. He was not stupid. He was just human, in a hurry, and trusting a link he thought he had vetted.

What This Actually Looks Like in Practice

You receive an email from SBI saying your account is locked due to suspicious activity. Your heart jumps. There is a link that says "Verify Now."

Here is what you do:

  1. Do not click the link.
  2. Do not call the number in the email (until you have verified it is real).
  3. Open your web browser.
  4. Type www.sbi.co.in directly into the address bar.
  5. Log in with your username and password.
  6. Check whether your account actually shows as locked.
  7. If it does, use the contact information on the official website to reach the bank.
  8. If it does not, the email was phishing. Delete it.

The entire process takes three minutes. It has stopped every single phishing email I have personally tested this way.

The catch is that it requires you to not click. To pause. To suspect the email even though it looks official, even though it feels urgent, even though the threat is explicit and frightening. This is not a technical habit. It is a psychological one. And it is harder than most people admit.

Why Banks Won't Make This Easier

You might think: "Why does not my bank just put a message at the top of their website reminding me of the official domain?"

They do, sort of. But not as prominently as they should. Why? Because admitting that phishing is rampant is bad for business. It makes customers feel unsafe. It invites scrutiny from RBI. It opens the door to liability questions.

The result is that the awareness you see is generic, buried, and often passive. The really clear warnings—the ones that would stick—are reserved for helpline recordings and fine print.

So you are on your own here. Your bank will not save you. Your email provider will not catch every fake. The law (such as it is under the IPC and IT Act) will pursue the scammer after your money is gone, if ever.

Your safety depends on habits you build yourself.

Five Things You Can Do Right Now

  1. Check your email settings. In Gmail, go to Settings > Forwarding and POP/IMAP > Show Original on any email and learn what the "From" field actually says. Do this with one real email from your bank right now, so you know what the official domain looks like. Screenshot it if you need to.

  2. Create a contact card. Save your bank's official website and phone number (from their official website, not from Google Search) in your phone contacts. When you receive an email claiming to be from them, call that number or visit that website directly. Never use contact details from the email.

  3. Turn on two-factor authentication everywhere. If a scammer gets your email and password, they still need your OTP to log in or transfer money. OTP is not perfect (SIM swaps exist), but it stops the basic attacks. Do this for email, banking, and social media, in that order.

  4. Tell your family. The people most likely to fall for phishing are your parents and grandparents. Tell them the domain check. Tell them to call you before clicking any bank links. This one conversation could save ₹2 lakhs.

  5. Report the email. If you receive a phishing email, forward it to your bank's official email address (find this on their website, not in the phishing email). Report it to CERT-In (cert@cert-in.org.in). Most phishing emails go unreported. Your report might help shut down the attacker's infrastructure before they target someone less cautious than you.


The woman in Gurugram has started checking the sender's email address on every message. It took her three months and ₹2.3 lakhs to learn this habit. You do not have to wait that long.

Read next