Simple clear advice in plain English

How to spot email scams

We take a look at a recent phishing email, claiming to be from the HMRC, to show how you can catch the scams

Loading the player ...
Looking at the code of this scam email reveals its true nature

We received a scam email last week pretending to be from the tax man offering a refund if we just filled out an online form with our bank details. Many of you alerted us to the scam as well so we thought we would share some of the methods we used to spot that this wasn't a legitimate email.

1. The common-sense test

Granted, the tax man does occasionally give money back, but not like this. You'll either know about it from submitting a tax return, or you'll just receive a cheque in the post as my wife did a couple of years ago. HMRC says it will never send notifications of a tax rebate by email.


2. Does the tax man know your email address

Think about if you've ever given the tax man this email address. You may have done in the past so apply the common-sense test as well.


3. Check the links

Don't click on the links, but hover the mouse over them to see a preview of what they are. Be sure to check the whole link, especially the last two words as these are the actual server of the web server. Some of the links may well be genuine to help fool you. You may find this easier in the view source mode – we'll cover the basics of HTML in a moment.

4. Check the From and Reply to addresses

The scammers might be hoping that you'll respond so check both the From and To address. The from address isn't fail safe because its very easy to spoof, but the reply address might give the game away. After all, they don't want you to get in touch with real tax man.

5. Check the email's journey

Now we get a little more technical. An email travels through several servers on its way to your inbox and each one leaves its address in the email. You can't normally see this but if you use the View Source option in Thunderbird you can see the trail. It's the first server you want to check, the servers in the middle are most likely innocent.

6. Examining the attachment

This particular scam wants you to enter some information in a web form attached to the email. This is where this particular scam really happens so it gets more interesting here. The golden rule is don't open the form in a browser just in case it contains some malicious code. Instead we're going to use a text editor called Notepad++. Notepad++ will colour-code the web page code to make it easier to read. Save the HTML file to your computer, start Notepad++ and load it from there.

7. The code

Looking at the code shows how this is a clever scam – all of the images and styling information, references to CSS files, are taken from the hmrc.gov.uk website. There's no particular trick here as you can just take the links from legitimate emails or web pages. The main part of this document is the form for you to fill in and it starts here.

What we're looking at is how the information is going to be transferred when you click on the submit button and, more importantly, where the information is going. For the first time we don't have an hmrc.gov.uk link but instead an IP address. If nothing else has got alarm bells ringing this should, and it confirms that this is a scam.


8. Where is the scam server based?

Every IP address on the Internet is accountable to someone. Whether they care about the scam is another matter, but you can usually find out more about the address using a whois service. We're going to copy and paste the IP address from the scam email in to the Whois service from APNIC. This IP address is registered in New Zealand, so unless there are some very serious Lord of the Rings fans in HMRC, this isn't legitimate.

We don't recommend trying to contact the person listed in the details here,though you might want to report it to the registrant if they sound legitimate. To be honest, you're best off leaving any action to the HMRC by forwarding the email to their fraud-reporting service.

Article tags

Reader Comments

   

Add your comment

Please keep comments constructive and free from abuse of any kind and swearing. If you wish to link to a product or service online, please do so in such a way that makes it clear that it is not spam. If you are connected to any such product you should make that clear.

We may use your comments in the magazine. We may edit your comments for clarity or to remove unacceptable material. We will attribute your comments but not share your email address.

We request your email address and record your Internet Address (IP address) in order to block spam from our site. We will never share this information without your permission.

All comments are reviewed by the Computeractive Team before being published. Please bear with the slight delay this causes, you don't need to post more than once.

Click here to read our Privacy Policy

Click here to read our site Terms & Conditions

Related articles

getrichquick1

Scams disguise malicious software as apps says Bitdefender

Cybercriminals are setting up get-rich-quick websites that download malicious software disguised as apps

Image of an Xbox 360 games console

Xbox Live users fall victim to email phishing scam

Microsoft has responded to claims that its Xbox Live network has been hacked by stating that users have been victim of a phishing scam

actionfraud

Trading Standards campaign urges victims of fraud to report scams

Consumer watchdogs launch scamnesty month to encourage victims to come forward

Content Recommendation

Question & Answer

Q.Why is Windows Backup skipping files?

> Read the answer

Q.Why do my scanned documents display gibberish?

> Read the answer

Q.How can I convert MTS files to edit in Windows Movie...

> Read the answer

Best deals on the web

img

Samsung NP350E7C-A04UK

£349.99- Buy it now

img

Toshiba Satellite C850D-11Q (PSCC2E-00R00JEN)

£279.97- Buy it now

img

ASUS Eee PC X101CH-BLK043S

£239.99- Buy it now

Updating your subscription status Loading

Most popular articles

No matching document

Poll

Do you have Windows 8?

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive

Information currently unavailable