Your phone buzzes. "ALERT: Unusual activity on your account. Verify now or your card will be locked." There's a link, or a number to call. Your stomach drops, and that's the design: the message exists to make you tap before you think. The fastest way to know whether a text really came from your bank is to read the domain, not the words.

Why this scam works on careful people

Impersonation scams, where someone pretends to be a company or agency you trust, are not a fringe problem. According to the Federal Trade Commission, people reported losing $3.5 billion to imposter scams in 2025. That made imposter scams the single most-reported fraud category — the ninth year in a row, per the FTC's own summary of the trend. Nearly one in three fraud reports in 2025 was an imposter scam, and reported losses in this category have nearly tripled since 2020.

Within that total, one impersonator did more damage than any other. The FTC found that criminals pretending to work for a bank were tied to the highest reported losses of any impersonation type. Business impersonators as a whole accounted for about $1 billion, and bank impostors led the pack inside that group. Government impersonators added roughly $920 million more. (Independent coverage from BleepingComputer and CNBC reported the same $3.5 billion figure, part of roughly $16 billion in total reported fraud losses across all categories, the highest on record.)

This works on careful people because the message is designed to switch off the careful part of your brain. It manufactures urgency, "act now or lose your money," so you react before you inspect. The people who get caught are rarely careless. They are just responding to fear on the terms the scammer set.

A real bank alert and a fake one can read identically. The words, the logo, the tone, all of it can be copied in minutes. The one thing a scammer can't copy is your bank's actual domain, the address after the @ in an email or behind a link. That's where you look.

Real alert vs. fake alert: what actually differs

Say your bank is Chase. Here is what a legitimate address looks like next to a lookalike a scammer might use.

Realchase.comthe bank's registered domain
Fakechase-secure-alerts.com"chase" is just a word inside someone else's domain

The trick in that second one is that chase appears at the front, so your eye stops there and feels reassured. But a web address is read right to left. The real owner of a domain is the part immediately before the .com, which here is chase-secure-alerts, not Chase. Anyone can register a domain with a brand's name buried in the middle.

The four ways a fake "bank" reaches you

ChannelHow the fake shows upWhat to check
Text message"Your card is locked. Tap to verify." A link on a tiny screen.Don't tap. Read the domain in the link, or ignore it entirely.
EmailDisplay name says "Chase Fraud Dept." The address after the @ is something else.The part after the @ is the only part that counts.
Phone callA number that "spoofs" your bank's caller ID and asks you to confirm details.Hang up. Call the number on the back of your card instead.
Web link in an adA sponsored search result that looks like your bank's login page.Check the domain before typing anything. Lookalikes buy ads too.
The number or link in the message is the scammer's, not your bank's. Never call the number a suspicious message gives you, and never tap its link. If you want to check your account, reach your bank the way you always do: the app you already installed, or the phone number printed on your card.

How do you check a bank text in under a minute?

  1. Don't tap or call anything yet. The message wants speed. Deny it that. Nothing bad happens if you pause for a minute.
  2. Find the real sender. In an email, look at the address after the @, not the display name. In a text with a link, press and hold the link to reveal the full address without opening it.
  3. Copy the domain, don't retype it. If you retype it, you may unconsciously "correct" a swapped character and miss the very thing you're checking for.
  4. Paste it into IP Tracker and read the result: is it a lookalike of a known bank? Has Google Safe Browsing flagged it? Is the domain brand new?
  5. When in doubt, go around the message entirely. Open your bank's app or call the number on your card. If there's a real problem, they'll tell you there.

How does IP Tracker read a bank domain?

IP Tracker is a free Chrome extension. Paste a domain or a full email address into the popup; the free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.

For a bank message, it does a few things at once. It compares the domain against the official domains of roughly 100 widely impersonated brands, including major banks and payment services, and normalizes look-alike characters first (so chase.com and a zero-for-o fake like chas0.com don't slip past). An exact match to an official domain gets a "verified" note. A match only after normalizing the tricky characters is flagged HIGH, with a banner naming the exact swap. Near-miss spellings are caught by a separate typo-tolerant check and flagged as a MEDIUM caution.

Alongside that, it shows whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the domain, how many security vendors flag it on VirusTotal, community abuse reports, and the domain's creation date. Fraud domains are often registered days before a campaign, so if the domain is very new, the banner adds a "Registered N days ago" line as a supporting clue, never a verdict on its own.

What can't it do?

Honesty matters more than comfort here, so four limits worth knowing:

"Not flagged" is not the same as "safe." Every result is a signal for your judgment, not a verdict. IP Tracker surfaces what it can see about a domain. It can't promise a site is safe, and it can't stop you from calling a number; that part is still yours.

Your bank has your account already. It doesn't need you to "verify" it through a link in a text, and it will never lose anything if you take a minute to check first. The message wants you to move fast. The domain is what tells you the truth, and it takes seconds to read.

To summarize:

Stay sharp! 😎