Trust your instincts when communications feel wrong—your vigilance creates protective barriers that strengthen cybersecurity defences for everyone. You must scrutinize sender addresses for suspicious domains, avoid clicking embedded links, and verify unexpected requests through independent channels to identify phishing threats. Forward suspicious emails to SERS, report malicious texts to 7726, and document fraudulent calls to Action Fraud at 0300 123 2040. Check website URLs for misspellings and verify security certificates before entering personal data.
Key Considerations
- Examine sender addresses carefully for suspicious domains, misspellings, and inconsistencies that indicate fraudulent communications.
- Hover over embedded links without clicking to reveal actual destinations and verify legitimacy before taking action.
- Forward suspicious emails immediately to SERS at suspicious.email@ncsc.gov.uk to enable automatic blocking and threat intelligence.
- Report malicious text messages to 7726 and document fraudulent phone calls to help authorities identify scammer networks.
- Screenshot and report deceptive websites to NCSC while verifying authenticity through official company channels and security certificates.
Identifying Fraudulent Messages and Communications

While cybercriminals continuously refine their deception tactics, you can identify fraudulent communications by scrutinizing key warning signs that reveal malicious intent.
Examine sender addresses for suspicious domains and misspellings that impersonate legitimate organizations. Don’t click embedded links—hover to reveal actual destinations that often redirect to malicious sites.
Analyse message urgency and pressure tactics demanding immediate action or personal information. Verify unexpected requests through independent channels before responding.
Trust your instincts when something feels wrong—that intuition often detects subtle inconsistencies your conscious mind hasn’t processed.
Report suspected phishing attempts immediately to protect yourself and prevent others from becoming victims.
Forwarding Suspicious Emails to Security Authorities
After identifying suspicious messages, you must immediately forward them to the proper security authorities to neutralize threats and protect other potential targets.
Send these emails directly to the Suspicious Email Reporting Service (SERS) at report@phishing.gov.uk. The National Cyber Security Centre analyses each submission to identify attack patterns and malicious infrastructure.
They’ll block compromised email addresses and websites, preventing further exploitation. Your reporting creates a protective barrier for countless other users who might encounter identical threats.
This collective intelligence system depends on swift action from users like you.
- Forward complete emails with headers intact to preserve forensic evidence for threat analysis
- Enable automatic blocking of malicious domains and email addresses across national networks
- Generate threat intelligence that strengthens organizational and individual cybersecurity defences
Reporting Malicious Text Messages and Phone Calls
When malicious actors escalate beyond email attacks, they’ll target your mobile device through deceptive text messages and fraudulent phone calls that impersonate trusted institutions.
Forward suspicious texts to 7726 immediately—most providers investigate these reports for free and can block malicious senders.
For fraudulent phone calls, especially those impersonating banks or government agencies, document the incident details.
Report financial losses or security breaches to Action Fraud at 0300 123 2040 in England, Wales, or Northern Ireland. In Scotland, contact Police Scotland at 101.
Your reports help authorities identify scammer networks and protect other potential victims.
Taking Action Against Deceptive Websites and Advertisements
As cybercriminals expand their operations beyond messaging platforms, they’ll deploy sophisticated fake websites and fraudulent advertisements designed to harvest your personal data and financial information.
These deceptive sites mirror legitimate businesses, banking portals, and e-commerce platforms to steal your credentials. Scam advertisements feature false celebrity endorsements and unrealistic investment opportunities to lure victims.
You must report suspicious websites to NCSC immediately. They’ll investigate and remove malicious sites protecting countless potential victims.
- Verify website authenticity by checking URLs for misspellings and security certificates
- Screenshot suspicious advertisements before reporting to preserve evidence for investigation
- Cross-reference offers with official company websites to identify fraudulent promotions
Final Thoughts
You’ve gained the tactical knowledge to identify and neutralize phishing threats targeting your digital assets. Don’t hesitate—implement these countermeasures immediately. Forward suspicious emails to security teams, report malicious communications to authorities, and document deceptive websites. Your proactive response disrupts cybercriminal operations and protects vulnerable targets. Stay vigilant, act decisively, and maintain these defensive protocols. Every threat you report strengthens our collective cybersecurity posture against evolving attack vectors.