Privacy
Phishing, impersonation and unsafe links

How to Spot a Phishing Email, SMS or WhatsApp Message

UrbanX Digital Safety & Privacy
26 Aug 2026
11 min read
Quick Answer

Phishing messages try to make a recipient click, disclose information, approve a login or send money before verifying the request. Look at the action being demanded, not only the logo or grammar. Do not use the link, reply address or phone number in the message; open the known app or website and verify through an independently obtained channel.

Read the full Digital Safety guide

Last reviewed: 26 August 2026 · 11 min read

Phishing describes the method

The delivery channel changes the label:

  • Phishing: commonly email or a broad category for deceptive credential theft.
  • Smishing: phishing by SMS or messaging app.
  • Vishing: deceptive voice call or voice note.
  • Social-media phishing: direct messages, adverts, fake support accounts or compromised friends.
  • QR phishing: a QR code conceals the link until a device opens it.

The goal may be a password, OTP, card detail, identity document, remote access, malware installation or direct payment.

Do not rely on bad spelling

Scam messages can be polished, personalised and correctly branded. AI tools, leaked customer data and copied templates make appearance a weak test.

Use stronger signals:

The contact is unexpected

An unrequested password reset, parcel fee, tax refund, prize, invoice or security alert deserves independent verification.

Urgency blocks reflection

The message claims an account, line, card, game inventory or benefit will disappear within minutes.

It requests a secret

Passwords, OTPs, PINs, backup codes and recovery links are authentication tools—not information to read to a caller.

The requested payment method is unusual

Be cautious of sudden bank-detail changes, instant transfers, cryptocurrency, vouchers or payment to a personal account.

The link and story disagree

The visible text mentions a trusted company while the real destination belongs to another domain.

It tries to isolate the recipient

Instructions such as “do not call the company,” “stay on the line” or “do not tell anyone” prevent verification.

Inspect without interacting

Email

  • Expand the sender’s full address.
  • Treat the display name as unverified.
  • Preview links without opening them where safe.
  • Check whether reply-to and sender domains differ unexpectedly.
  • Be cautious with attachments, especially unexpected archives, documents or installers.

SMS and WhatsApp

  • A logo, profile photo or business name can be copied.
  • A message in the same thread is not absolute proof if an account or number was compromised.
  • Short links conceal the destination.
  • “Forwarded” and recently changed security details deserve caution.
  • Voice notes can be cloned or taken out of context.

QR codes

Use the camera preview to read the destination before opening. A printed code can be covered by a malicious sticker. Navigate independently for payments or logins.

Verify through a separate path

  1. Stop engaging with the message.
  2. Open the organisation’s official app or type its known address.
  3. Check the account for the claimed alert, invoice or order.
  4. Call a number from the official website, bank card or prior statement.
  5. Ask a known person through a different channel if they supposedly requested money.
  6. Confirm changed banking details verbally using an established contact.

Caller ID and a familiar WhatsApp name can be spoofed or compromised. Independent verification means the suspicious message does not choose the channel.

Common South African lures

Messages may imitate:

  • banks and instant-payment services;
  • SARS refunds or penalties;
  • couriers and parcel fees;
  • mobile-network SIM or RICA issues;
  • electricity, municipal or utility accounts;
  • ISP billing or line suspension;
  • job offers, bursaries and competitions;
  • family emergencies and cash-send requests; and
  • marketplace buyers or sellers.

The story changes, but urgency, secrecy and credential or payment requests remain useful warning signs.

What to do without clicking

  • Report the message using the platform’s phishing or spam function.
  • Notify the impersonated organisation through its official fraud channel.
  • Preserve evidence if money, threats or identity abuse are involved.
  • Block the sender after evidence is captured.
  • Delete routine spam once no further evidence is needed.
  • Warn affected colleagues or family without forwarding an active malicious link.

Do not publicly post a live phishing URL where other people may open it.

What to do after clicking

If the page opened but no information was entered:

  • close it;
  • do not accept downloads, profiles or notifications;
  • check the browser’s download list;
  • update and scan the device if anything executed; and
  • monitor the relevant account.

If credentials or an OTP were entered:

  1. Use a trusted device and the real service address.
  2. Change the affected password.
  3. Change it everywhere it was reused.
  4. End unknown sessions and revoke linked access.
  5. Turn on or repair MFA.
  6. Secure the recovery email.
  7. Contact the bank immediately if payment or card data was involved.
  8. Inform contacts if the compromised account sent messages.

Use What to Do After an Online Account Is Hacked for the full recovery sequence.

Reporting crime or harm

Online fraud remains crime. SAPS advises victims of computer crime, identity theft or commercial scams to report at a police station. ISPA’s South African guidance recommends preserving facts, requesting investigation and obtaining a CAS number where a charge is laid.

The correct route depends on what happened. Contact the bank immediately for an unauthorised or fraud-induced payment, the platform for an abusive account, and emergency services where physical safety is at risk. Check current official contact information before publishing or acting.

Sources

Related guides

Frequently Asked Questions

Still experiencing issues? Run a diagnostic check or reach out to our support team with a structured ticket.