Your phone buzzes. "ALERT: Unusual activity on your account. Verify now or your card will be locked." There's a link, or a number to call. Your stomach drops, and that's the design: the message exists to make you tap before you think. The fastest way to know whether a text really came from your bank is to read the domain, not the words.
Why this scam works on careful people
Impersonation scams, where someone pretends to be a company or agency you trust, are not a fringe problem. According to the Federal Trade Commission, people reported losing $3.5 billion to imposter scams in 2025. That made imposter scams the single most-reported fraud category — the ninth year in a row, per the FTC's own summary of the trend. Nearly one in three fraud reports in 2025 was an imposter scam, and reported losses in this category have nearly tripled since 2020.
Within that total, one impersonator did more damage than any other. The FTC found that criminals pretending to work for a bank were tied to the highest reported losses of any impersonation type. Business impersonators as a whole accounted for about $1 billion, and bank impostors led the pack inside that group. Government impersonators added roughly $920 million more. (Independent coverage from BleepingComputer and CNBC reported the same $3.5 billion figure, part of roughly $16 billion in total reported fraud losses across all categories, the highest on record.)
This works on careful people because the message is designed to switch off the careful part of your brain. It manufactures urgency, "act now or lose your money," so you react before you inspect. The people who get caught are rarely careless. They are just responding to fear on the terms the scammer set.
Real alert vs. fake alert: what actually differs
Say your bank is Chase. Here is what a legitimate address looks like next to a lookalike a scammer might use.
chase.comthe bank's registered domainchase-secure-alerts.com"chase" is just a word inside someone else's domainThe trick in that second one is that chase appears at the front, so your eye stops there and feels reassured. But a web address is read right to left. The real owner of a domain is the part immediately before the .com, which here is chase-secure-alerts, not Chase. Anyone can register a domain with a brand's name buried in the middle.
The four ways a fake "bank" reaches you
| Channel | How the fake shows up | What to check |
|---|---|---|
| Text message | "Your card is locked. Tap to verify." A link on a tiny screen. | Don't tap. Read the domain in the link, or ignore it entirely. |
| Display name says "Chase Fraud Dept." The address after the @ is something else. | The part after the @ is the only part that counts. | |
| Phone call | A number that "spoofs" your bank's caller ID and asks you to confirm details. | Hang up. Call the number on the back of your card instead. |
| Web link in an ad | A sponsored search result that looks like your bank's login page. | Check the domain before typing anything. Lookalikes buy ads too. |
How do you check a bank text in under a minute?
- Don't tap or call anything yet. The message wants speed. Deny it that. Nothing bad happens if you pause for a minute.
- Find the real sender. In an email, look at the address after the
@, not the display name. In a text with a link, press and hold the link to reveal the full address without opening it. - Copy the domain, don't retype it. If you retype it, you may unconsciously "correct" a swapped character and miss the very thing you're checking for.
- Paste it into IP Tracker and read the result: is it a lookalike of a known bank? Has Google Safe Browsing flagged it? Is the domain brand new?
- When in doubt, go around the message entirely. Open your bank's app or call the number on your card. If there's a real problem, they'll tell you there.
How does IP Tracker read a bank domain?
IP Tracker is a free Chrome extension. Paste a domain or a full email address into the popup; the free tier gives you 25 checks a day, with no account and no tracking. Only the value you paste is looked up.
For a bank message, it does a few things at once. It compares the domain against the official domains of roughly 100 widely impersonated brands, including major banks and payment services, and normalizes look-alike characters first (so chase.com and a zero-for-o fake like chas0.com don't slip past). An exact match to an official domain gets a "verified" note. A match only after normalizing the tricky characters is flagged HIGH, with a banner naming the exact swap. Near-miss spellings are caught by a separate typo-tolerant check and flagged as a MEDIUM caution.
Alongside that, it shows whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the domain, how many security vendors flag it on VirusTotal, community abuse reports, and the domain's creation date. Fraud domains are often registered days before a campaign, so if the domain is very new, the banner adds a "Registered N days ago" line as a supporting clue, never a verdict on its own.
What can't it do?
Honesty matters more than comfort here, so four limits worth knowing:
- It reads domains, not messages. IP Tracker checks the address you paste. It can't read the text of your SMS or judge whether the story in it is plausible. That part is still your call.
- The brand list is about 100 brands. The most impersonated ones, not every institution. A lookalike of a smaller regional bank or credit union may not be on it.
- Blocklists lag. Google Safe Browsing is strong on known-bad sites, but a phishing domain registered this morning may not be listed yet. New domains are exactly the risky ones.
- It can't undo a call you've already made. If you've handed over a code or a password, the tool checking the domain afterward won't reverse it. Contact your bank directly and fast.
Your bank has your account already. It doesn't need you to "verify" it through a link in a text, and it will never lose anything if you take a minute to check first. The message wants you to move fast. The domain is what tells you the truth, and it takes seconds to read.
To summarize:
- ✓ Slow down. Urgency is the scam's main tool.
- ✓ Read the domain, not the display name or the words.
- ✓ Never call the number or tap the link in a suspicious message.
- ✓ Paste the sender's domain into IP Tracker, then reach your bank the way you always do.
Stay sharp! 😎