Scam email template websites usually mean one of two things: a look-alike page linked from a fraudulent message, or a site offering phishing templates and kits. Neither is a safe place to test a password or sign in. Don't enter credentials, payment details, verification codes, or personal information; don't download unknown files; and don't approve a sign-in until you've checked the request through a separate, trusted route.
This guidance is for U.S. consumers. What you should do next depends on what happened. Opening a page, entering a password, approving a login, giving away card details, and sending money create different risks and require different responses.
How the email and website work together
The pressure usually comes first. The message may say that an account will close, a delivery is waiting, an invoice is overdue, or a refund needs confirmation. It then sends you to a page that borrows a familiar logo, color scheme, login form, or support layout.
Once there, the page may ask for a password, one-time code, card number, bank details, identity document, or file download. Some fake pages send the visitor to the genuine service afterward, which can make the whole exchange appear normal.
A convincing design proves nothing. Attackers can copy public branding and writing styles, and polished grammar is no longer a reliable safety signal.
Common scam email template examples
These are patterns, not links to live scam sites.
Account and password alerts
The message claims that your email, cloud-storage, payroll, or shopping account will be suspended unless you sign in immediately. A subject such as "Password expires today" is designed to leave no time for checking the destination.
The link may open a fake sign-in page that records your username and password. It might then ask for a one-time code or tell you to approve a login notification.
Delivery, refund, and payment messages
A fake carrier notice may ask for a small redelivery fee or an address confirmation. A refund message may request card details before releasing money. A low-dollar charge can make the request seem less risky than it is.
Don't use the link or telephone number in an unexpected message. Open the retailer's, carrier's, or bank's official app, or type a web address you already know.
Invoice and business impersonation
A message that appears to come from a vendor, manager, landlord, or service provider may request an urgent payment, a bank-detail change, or a copy of a tax or identity document.
An existing email thread isn't proof that the new request is genuine. The account may have been compromised, or the sender may have copied the thread's display name and formatting. Confirm new payment instructions through a known phone number or an established contact.
Fake technical support
These messages claim that your computer, subscription, or account has a serious problem. They may include a support number or a link for remote access.
Don't install remote-access software, call an unverified number, or give a caller your password or verification code just because an email says your device is in danger.
Prize, job, and advance-fee messages
A template may promise a prize, job, grant, inheritance, publishing opportunity, or investment return. The recipient is then asked to pay a processing fee, buy gift cards, send documents, or provide banking information.
Paying before receiving an unexpected benefit is a strong warning sign. Secrecy, unusual payment methods, and pressure to move the conversation away from email increase the risk.
How to check whether an email is fake
Look at the sender, the destination, and the requested action. Branding should be the least persuasive part of the message.
Examine the actual sender
A display name can say "Your Bank" while the underlying address uses an unrelated domain or a slight spelling variation. In Outlook, Microsoft says suspicious sender details can include a question-mark indicator or a "via" tag when the visible From address differs from the authenticated sending address. See Microsoft's guidance on phishing and suspicious behavior in Outlook.
An authenticated sending domain still doesn't establish that the request is honest. A real account can be compromised, and an otherwise legitimate message can contain a fraudulent link or instruction.
Inspect the link without opening it
On a computer, hover over the link and read the destination shown by the browser. On a phone, use the mail app's link preview or copy-link option if available instead of tapping through.
Watch for:
- Misspellings, extra words, or unusual domain endings
- A brand name used only as a subdomain
- A shortened link that hides the destination
- Several redirects before the final page
- A domain that doesn't match the company you expected
For example, microsoft.com.example.com is controlled by example.com, not Microsoft. A padlock or https means the connection is encrypted; it doesn't show who operates the site.
Consider what the message wants
Be cautious when an unexpected message asks you to:
- Sign in through a supplied link
- Share a password, one-time code, or backup code
- Approve an unfamiliar login notification
- Pay by gift card, cryptocurrency, wire transfer, or another unusual method
- Change a vendor's bank details
- Open an unexpected macro-enabled document, archive, HTML file, or other attachment
- Keep the request secret or skip a normal approval process
Typos can expose a scam, but clear writing doesn't clear one. Ask yourself: Would I have made this request through the same channel if the email had never arrived?
Verify the request using a separate route
Pause before clicking, replying, paying, or downloading. Then:
- Open the company's official app or type a known web address into the browser.
- Check the account's alerts, order history, invoice area, or support page.
- Call the number on your card, statement, contract, or a trusted official website.
- If the request concerns work, ask a manager or colleague through a known phone number or established work channel.
- Report the message through your email provider. For Gmail, Google's phishing and suspicious-email guidance explains how to report suspicious messages and why you shouldn't answer them.
- For a personal mailbox, delete the message after reporting it. If it involves a work account, preserve it for your IT or security team first.
Don't use contact details supplied in the suspicious message itself.
What to do after clicking a phishing link
Clicking a link does not by itself show that an account was taken over. The risk changes if you entered information, downloaded something, or approved an authentication request.
If you only opened the page
Close it without entering information, accepting browser notifications, downloading a file, or approving a sign-in. Report the message.
If a file downloaded, you opened an attachment, or the device behaves unusually, disconnect it from the internet if needed and run a scan with reputable, up-to-date security software. Install pending operating-system and browser updates.
If you entered a password
Treat that password as exposed, even if the page looked professional.
- Go to the real service using a typed address or trusted bookmark.
- Change the password immediately.
- Change it anywhere else you reused it.
- Sign out of other sessions if the service offers that option.
- Review recovery email addresses, phone numbers, forwarding rules, filters, and connected apps.
- Turn on multifactor authentication.
- Consider a passkey or security key where the service supports one.
Google Workspace's Password Alert FAQ notes that a FIDO security key can help prevent password phishing. MFA adds protection, but never approve an unexpected prompt or share a verification code.
If you entered payment or identity information
Call the card issuer or bank using the number on the card or statement. Explain exactly what you supplied and ask which protective steps are appropriate, such as replacing a card or monitoring the account.
If you provided identity documents or other account information, contact the relevant company through an independently verified fraud or support channel as well. Avoid any follow-up caller or email that offers to recover your money or secure the account for an upfront fee.
If a credit or debit card was charged, the FTC's sample dispute-letter guidance says you must notify the card company within 60 calendar days of when the first statement showing the disputed charge was sent to you. That's a card-dispute deadline, not a single process for every kind of payment. Don't wait for the deadline: follow the issuer's required dispute process, keep copies of your communications, and check that any promised credit or refund appears on the account.
Wire transfers, bank transfers, gift-card payments, and peer-to-peer payments may require a different recovery process. Contact the bank or payment service immediately and ask whether a recall, freeze, or fraud review is possible. Recovery isn't guaranteed, but delay can reduce the available options.
If you approved a sign-in or shared a one-time code
Treat the account as potentially compromised even if you never revealed the password. From a trusted device, change the password, revoke unfamiliar sessions, review security settings, and contact the provider through its official support channel.
Never use a new number or link sent by someone who claims to be fixing the incident.
If a work account was involved
Tell your employer's IT or security team immediately. Don't delete the original message before the team has had a chance to preserve useful evidence, including message headers, sender details, links, and timestamps.
Administrators may need to disable the account temporarily, reset credentials, revoke active sessions, inspect mailbox rules, review sign-in logs, and check whether the account sent additional fraudulent messages. Microsoft's response guidance for a compromised Microsoft 365 account describes investigation and recovery steps for Microsoft 365 environments.
If the account handled payroll, invoices, customer data, or cloud files, ask the organization whether payment instructions or shared documents need to be checked.
What does not prove that a website is legitimate?
None of these details is a sufficient safety check on its own:
- A familiar logo or copied company footer
- Professional wording
- A browser padlock
- A request for only one small piece of information
- A message that appears inside an existing conversation
- A sender name that matches someone in your contacts
- A redirect to the real website after information was submitted
The useful check is independent verification of both the domain and the request. If you can't verify them, stop.
Can you safely download phishing email templates?
Don't download live phishing kits, cloned login pages, or unknown template files onto a personal device. They may contain malware or collect information entered into them.
For awareness training, use an authorized simulation managed by your employer or a reputable training provider. A responsible simulation uses dummy data, never real passwords, and has clear approval from the organization being tested.
A short response plan
Keep the sequence simple:
- Stop: don't click again, reply, pay, download, or approve a prompt.
- Verify: start from the official app, website, statement, or a known phone number.
- Report: notify your email provider, bank, employer, or the impersonated company.
- Secure: change exposed passwords, revoke unfamiliar sessions, and strengthen sign-in protection.
- Document: save the message, screenshots, URLs, timestamps, and transaction details.
If money or sensitive information was involved, make the bank or card-issuer call first. If only a suspicious email arrived, report it, preserve it if someone needs to investigate, and then remove it from your mailbox.