How Australians Can Check Whether a Bank Email Is Genuine

A convincing bank email can arrive while you are travelling through Brisbane, paying a tradie in Perth, or checking your phone on the Sydney train. Scammers often copy a bank’s colours, logo and writing style, then create urgency around a payment, suspicious login or account suspension.

Domain checks provide a useful first filter when you need to verify the authenticity of an email claiming to be from your bank. They can reveal lookalike domains, weak email authentication and reputation problems, although no single technical check proves that a message is safe.

Before You Trust The Message

Do not click a button, open an attachment or reply to the email while you are assessing it. Banks such as CommBank, Westpac, NAB and ANZ generally do not ask customers to provide internet banking passwords, one-time passcodes or full card details by email. A request to “confirm” these details is a strong warning sign.

Open your bank’s app by using its existing icon, or type the official address into your browser yourself. Australian customers can also call the number printed on their card rather than using a number in the message. If the email mentions an Osko transfer, PayID payment or unusual login, verify the activity inside your banking app.

Inspect The Sending Domain

Look beyond the display name. An email may show “Your Bank Security Team” while the actual address uses a domain such as secure-bank-alerts.com, a misspelling, or an unrelated Gmail account. Pay close attention to substitutions such as commbank-support.com, extra hyphens, unusual country-code domains and characters that resemble letters.

A domain checker can identify reputation signals, DNS records and potential spoofing concerns. You can use a sender trust checker to examine the domain associated with a suspicious message, but treat the result as evidence rather than a guarantee. A reputable domain can still be abused if an account has been compromised.

Read The Authentication Signals

Email authentication relies mainly on SPF, DKIM and DMARC. SPF checks whether the sending server is authorised by the domain. DKIM adds a cryptographic signature, while DMARC tells receiving systems what to do when authentication fails and checks whether the visible From domain aligns with the authenticated sender.

A failed check does not automatically mean fraud, because legitimate organisations sometimes misconfigure third-party email platforms. However, a bank-branded message from a domain with no meaningful authentication, poor reputation or failed alignment deserves extra caution. The anti-spoofing guidance explains how DMARC conformance helps domains resist impersonation.

Compare Headers And Links

If you know how to view full headers, compare the visible From address with Return-Path, DKIM signing domain and the receiving server’s authentication results. A mismatch can occur for legitimate marketing services, but it should make you pause when the message also demands immediate action.

Hover over links without opening them and inspect the destination. A genuine bank may use a carefully controlled service domain, while a scam commonly redirects through shortened URLs, newly registered sites or pages hosted on unrelated infrastructure. Check the spelling character by character; nab.com.au and nab-login.example are entirely different domains.

Decide What To Do Next

When a message appears suspicious, report it through your bank’s official fraud channel and forward it according to the bank’s published instructions. You can also report scams to Scamwatch, an important Australian resource, and delete the email after preserving evidence such as screenshots and headers. If you entered credentials, contact the bank immediately and change affected passwords from a trusted device.

Use domain checks as part of a layered decision, alongside independent contact methods, authentication results and sensible behaviour. The following guide shows how common findings should influence your response:

Finding What It May Mean Safer Response
Domain exactly matches the bank’s official domain The address is plausible, but the mailbox or account could still be compromised Verify the request in the banking app
Lookalike or unrelated domain Likely impersonation or phishing Do not click; report and delete
SPF, DKIM and DMARC pass and align Stronger evidence that the domain authorised the message Still inspect links and content
Authentication fails Misconfiguration or spoofing attempt Contact the bank through a trusted channel
Urgent request for an OTP or password Common social-engineering tactic Never disclose the code; contact the bank
Link leads to a different domain Possible redirect or credential-harvesting page Close it and report the email