Disposable email Guides
Updated 23 September 2026
Phishing imitates a trusted organisation to make you click, pay or hand over your login details. The messages are more and more polished, so here are the checks that expose them.
| Pretext | What you're asked to do |
|---|---|
| Parcel waiting, unpaid delivery fee | Pay a small amount by card |
| Bank account suspended, suspicious transaction | Log in on a fake bank website |
| Fine, tax, refund | Enter your card details |
| Mailbox full, password expired | Type your email password |
| Invoice or quote attached | Open a booby-trapped file |
| Message from a "colleague" or the boss | Make an urgent transfer or buy gift cards |
They all share the same mechanics: urgency, an immediate action and a link or attachment.
The display name ("Bank Customer Service") can be anything. Only the full address counts. Be wary of:
On mobile, tap the sender's name to reveal the real address.
On a computer, hover over the link without clicking: the destination appears at the bottom of the window. On mobile, a long press shows it. Read the domain just before the first slash: in https://mybank.com.customer-security.net/login, the real site is customer-security.net, not mybank.com.
The padlock in the address bar proves nothing: it means the connection is encrypted, not that the site is honest. Nearly all phishing sites have a valid certificate.
The files most used as traps are archives (.zip, .rar, .iso), attached web pages (.html, .htm), Office documents that ask you to "enable macros", and disguised executables (invoice.pdf.exe). An unexpected invoice from a supplier you don't know stays unopened.
A legitimate organisation never asks by email for your password, card PIN or a code received by text message.
Fraudulent messages used to be full of mistakes. With translation and text-generation tools they are now often flawless and copy logos faithfully. So don't judge by the writing quality; rely on the checks above.
When in doubt, don't click the link in the message. Open the bank's, courier's or agency's app yourself, or type their address into the browser. If the alert is real, you'll find it in your account. For a colleague asking for a transfer, call them back on a number you already know.
The same trap exists by text message (smishing) and QR code (quishing): a code stuck on a parking meter or sent in an email leads to a fake payment site. Before confirming anything, read the address your phone displays.
The more your main address circulates, the more phishing it receives. Using a disposable address for one-off sign-ups reduces the number of lists it appears on, and therefore the attempts aimed at you.
Reading the message in an up-to-date email app is generally safe. The danger comes from clicking a link, opening an attachment or entering information. Also avoid loading remote images, which can confirm to the sender that your address is active.
No. Replying or clicking an unsubscribe link in a fraudulent message confirms your address is read. Report it as phishing, then delete it.
Don't trust the message itself. Log in to your bank through its app or by typing its official address: if the alert exists, it will show there. If in doubt, call the number on the back of your card.