# How to Spot a Phishing Email, SMS or WhatsApp Message

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/spot-phishing-email-sms-whatsapp

**Answer:** Phishing messages try to make a recipient click, disclose information, approve a login or send money before verifying the request. Look at the action being demanded, not only the logo or grammar. Do not use the link, reply address or phone number in the message; open the known app or website and verify through an independently obtained channel.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 11 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 11 min read**

### Phishing describes the method

The delivery channel changes the label:

- **Phishing:** commonly email or a broad category for deceptive credential theft.
- **Smishing:** phishing by SMS or messaging app.
- **Vishing:** deceptive voice call or voice note.
- **Social-media phishing:** direct messages, adverts, fake support accounts or compromised friends.
- **QR phishing:** a QR code conceals the link until a device opens it.

The goal may be a password, OTP, card detail, identity document, remote access, malware installation or direct payment.

### Do not rely on bad spelling

Scam messages can be polished, personalised and correctly branded. AI tools, leaked customer data and copied templates make appearance a weak test.

Use stronger signals:

#### The contact is unexpected

An unrequested password reset, parcel fee, tax refund, prize, invoice or security alert deserves independent verification.

#### Urgency blocks reflection

The message claims an account, line, card, game inventory or benefit will disappear within minutes.

#### It requests a secret

Passwords, OTPs, PINs, backup codes and recovery links are authentication tools—not information to read to a caller.

#### The requested payment method is unusual

Be cautious of sudden bank-detail changes, instant transfers, cryptocurrency, vouchers or payment to a personal account.

#### The link and story disagree

The visible text mentions a trusted company while the real destination belongs to another domain.

#### It tries to isolate the recipient

Instructions such as “do not call the company,” “stay on the line” or “do not tell anyone” prevent verification.

### Inspect without interacting

#### Email

- Expand the sender’s full address.
- Treat the display name as unverified.
- Preview links without opening them where safe.
- Check whether reply-to and sender domains differ unexpectedly.
- Be cautious with attachments, especially unexpected archives, documents or installers.

#### SMS and WhatsApp

- A logo, profile photo or business name can be copied.
- A message in the same thread is not absolute proof if an account or number was compromised.
- Short links conceal the destination.
- “Forwarded” and recently changed security details deserve caution.
- Voice notes can be cloned or taken out of context.

#### QR codes

Use the camera preview to read the destination before opening. A printed code can be covered by a malicious sticker. Navigate independently for payments or logins.

### Verify through a separate path

1. Stop engaging with the message.
2. Open the organisation’s official app or type its known address.
3. Check the account for the claimed alert, invoice or order.
4. Call a number from the official website, bank card or prior statement.
5. Ask a known person through a different channel if they supposedly requested money.
6. Confirm changed banking details verbally using an established contact.

Caller ID and a familiar WhatsApp name can be spoofed or compromised. Independent verification means the suspicious message does not choose the channel.

### Common South African lures

Messages may imitate:

- banks and instant-payment services;
- SARS refunds or penalties;
- couriers and parcel fees;
- mobile-network SIM or RICA issues;
- electricity, municipal or utility accounts;
- ISP billing or line suspension;
- job offers, bursaries and competitions;
- family emergencies and cash-send requests; and
- marketplace buyers or sellers.

The story changes, but urgency, secrecy and credential or payment requests remain useful warning signs.

### What to do without clicking

- Report the message using the platform’s phishing or spam function.
- Notify the impersonated organisation through its official fraud channel.
- Preserve evidence if money, threats or identity abuse are involved.
- Block the sender after evidence is captured.
- Delete routine spam once no further evidence is needed.
- Warn affected colleagues or family without forwarding an active malicious link.

Do not publicly post a live phishing URL where other people may open it.

### What to do after clicking

If the page opened but no information was entered:

- close it;
- do not accept downloads, profiles or notifications;
- check the browser’s download list;
- update and scan the device if anything executed; and
- monitor the relevant account.

If credentials or an OTP were entered:

1. Use a trusted device and the real service address.
2. Change the affected password.
3. Change it everywhere it was reused.
4. End unknown sessions and revoke linked access.
5. Turn on or repair MFA.
6. Secure the recovery email.
7. Contact the bank immediately if payment or card data was involved.
8. Inform contacts if the compromised account sent messages.

Use [What to Do After an Online Account Is Hacked](/knowledge-hub/digital-safety-privacy-account-protection/what-to-do-account-hacked) for the full recovery sequence.

### Reporting crime or harm

Online fraud remains crime. SAPS advises victims of computer crime, identity theft or commercial scams to report at a police station. ISPA’s South African guidance recommends preserving facts, requesting investigation and obtaining a CAS number where a charge is laid.

The correct route depends on what happened. Contact the bank immediately for an unauthorised or fraud-induced payment, the platform for an abusive account, and emergency services where physical safety is at risk. Check current official contact information before publishing or acting.

### Sources

- [South African Department of Justice Cyber Safety Resources](https://www.justice.gov.za/cybersafety/cybersafety.html)
- [SABRIC: How to Stay Safe](https://www.sabric.co.za/how-to-stay-safe/)
- [FTC: How to Recognise and Avoid Phishing Scams](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)
- [ISPA: How to Report Online Crime in South Africa](https://ispa.org.za/consumer-support/how-to-report-online-crime/)
- [SAPS Cybercrime Prevention Tips](https://www.saps.gov.za/alert/cybercrime_prev_tips.php)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [Fake ISP Support Calls and Messages](/knowledge-hub/digital-safety-privacy-account-protection/fake-isp-support-scam-red-flags)
- [How to Check Whether a Website or Payment Link Is Legitimate](/knowledge-hub/digital-safety-privacy-account-protection/check-website-payment-link-legitimate)
- [What to Do After an Online Account Is Hacked](/knowledge-hub/digital-safety-privacy-account-protection/what-to-do-account-hacked)

## Frequently Asked Questions

**Can a phishing message come from a real contact?**

Yes. Their email, social or WhatsApp account may be compromised. Verify through another channel.

**Is a message safe if it uses my name and account details?**

No. Personalisation can come from public sources, prior transactions or a data breach.

**Should I reply and ask if the sender is real?**

No. The scammer controls that channel. Contact the supposed sender independently.

**Can merely opening an email hack an account?**

Risk varies by platform and content, but the more common danger is clicking, opening an attachment, installing something or disclosing information. Keep software updated.

**What if I sent money?**

Contact the bank or payment provider immediately through its official fraud channel, preserve evidence and follow current SAPS reporting guidance.
