The message arrived with that unnaturally cheerful ping that tightens your stomach before your mind has even checked what it says.
It claimed my delivery was waiting at the depot until I paid £1.45 - all I had to do was press the blue button. As my kettle switched itself off, the only sounds were the radiator’s faint ticking and my thumb lingering above the trackpad like it had something to hide. Most of us know that instant when we can practically sense cash draining from our account because a message sounds convincing and looks more convincing still. That morning, I did one almost effortless thing that kept me from funding a criminal’s payday. It was so straightforward that I felt slightly foolish for not doing it years earlier - perhaps that is precisely why it is so effective. I still remember that ping and how one modest habit gave the story a different ending. Curious?
The email that had me reaching for my wallet
The branding was flawless, the copy polished and completely free of typos. This was not the clumsy, cartoon-style phishing attempt we have become used to mocking. It addressed me by name rather than using the familiar “Dear Customer” that normally exposes the trick. The link preview displayed a plausible-looking URL, while the deadline created pressure without being overblown: just urgent enough to seem sensible and grown-up.
The detail that lodged in my throat was this: I really was expecting a parcel. Naturally I was. That is where these scams find us - in the vulnerable gaps of busy lives and to-do lists crowded with small payments. The email sailed past my defences, like a clever striker placing the ball in the corner while you are still waiting for the whistle. Then curiosity gave me the nudge I needed, the same uneasy feeling you get when your own name appears slightly wrong on a birthday card.
I checked the “To:” field. It was tiny, seemingly unimportant and sitting beside my name. What I found made the hair on my arms rise.
The simple trick that changed everything
A few months earlier, I had begun assigning a different version of my email address to every company by using a plus sign. If my address was [email protected], I would register with Amazon as [email protected], Royal Mail as [email protected], and my bank as [email protected]. It takes only moments, and most email providers treat everything after the plus sign as part of the same inbox. It is like quietly giving yourself a secret handshake and keeping it safely to hand. Give every company its own email.
Its strength lies in an unobtrusive detail: if an email claims to come from Royal Mail but is sent to [email protected] rather than name+royalmail@, I know it was not sent through the genuine account I hold with them. It could still be legitimate promotional mail, but it is not connected to my login. Where money is involved, that difference is a warning flare. Criminals can copy a logo and forge a sender name, but they seldom know the precise alias you gave to the legitimate company.
I had not beaten the hacker with brilliance; I had simply made them miss.
How it works in real inboxes
Gmail, Outlook.com and iCloud all recognise the plus sign. An email sent to [email protected] will still arrive in [email protected]. The same applies to Outlook.com and iCloud. This lets you create small, disposable labels whenever you need them, without opening another account. You can also immediately see which company has leaked your details, which is oddly satisfying.
Use name+netflix@ when joining Netflix and name+gym@ when registering with your gym. If you tend to forget things, keep a brief list in your notes app. Then, if an email saying “Your payment failed, click here” arrives at the unmodified version of your address, you have a clear reason to stop and think. That moment of hesitation is valuable.
Set a filter to make it automatic
The next stage turns the trick into a seatbelt. Create a filter so that an email claiming to be from a particular brand reaches your main inbox only when it has been sent to the corresponding alias. Gmail allows filters based on “To”, which can send non-matching messages to a folder called “Check First”. Outlook and Apple Mail offer comparable options. In effect, you are installing a tripwire for yourself, and your future self will appreciate it on a Tuesday when your brain feels like mush.
The rule of thumb on the Post-it beside my screen is: If the alias doesn’t match, it’s a fake - bin it. There will, of course, be exceptions: a newsletter sent through another platform or a voucher you genuinely wanted. Those can be retrieved. But only entering your bank details when the secret handshake is correct? That is how the money remains in your pocket.
Why criminals hate this trick
Phishing campaigns depend on volume. Criminals purchase or scrape lists of ordinary email addresses, then send messages widely in the hope that a proportion of recipients will click. They can falsify the “From” name to resemble your bank and may even reproduce the footer. What is much harder for them is guessing the little alias you created for a specific service three months earlier while half-watching Match of the Day.
Some highly sophisticated attacks do reply within an existing email thread or compromise a supplier and use your real alias. Those cases are less common and are generally directed at businesses handling large invoices with busy finance departments. This method is not magic. It is a quick, human check that removes most of the rubbish, leaving your attention for the uncommon cases that warrant a telephone call.
The bleak reality is that phishing and business email compromise continue to take billions from people every year, quietly and shamefully, without making headlines. One small plus sign will not block every attempt. It does make half the field off-limits to criminals.
Two near-misses that still make me cringe
My friend Lorna owns a small café near the station, the sort of place where the coffee is hot and the conversation even warmer. She received an email from “HMRC” offering a VAT refund: a neat sum at exactly the right time. Her accountant was away, and it had been a difficult quarter. The email used the correct logos and imposed a 48-hour deadline. She told me she nearly clicked while her hands still smelled of lemon washing-up liquid.
But she did not. The “To” field showed name@ rather than name+hmrc@. That alone gave her enough room to breathe, forward the message to me and wait. Ten minutes later came the relief. Two months after that, the genuine HMRC letter arrived in the post, as it always does.
There was another close call involving a student I know who was moving into halls and received an email requesting the first rent instalment. He was stressed about keys and boxes. Seeing the university crest, he reached for his card. Then he noticed that the email had gone to his standard address, rather than the name+uni@ address he had used for all campus matters since freshers’ week. He phoned the accommodation office using the number on the website instead of the one in the email. No payment was owed. The scammer received silence, while he got a decent night’s sleep.
The 20-second sanity check
The alias method is your first barrier, and adding a second is useful. Before any money leaves my account, even when life is hectic, I follow this small routine. Honestly, nobody follows it every single day. That is alright. Use it whenever something feels risky.
- Check the “To” line. Is it the secret alias assigned to that brand?
- Examine the true domain beneath the “From” name. Tap or click once, without hurrying.
- Enter the brand name in your browser yourself and sign in from there. Type the company name into your browser, not the email link.
- For invoices or changes to bank details, phone a number you already know and trust, rather than one provided in the email.
- Leave it for five minutes. Make a tea, then return with fresh eyes.
That final step may sound ridiculous until you do it. You notice the warmth of the mug, the room becomes slower, and the spell disappears. Urgency is the scammer’s preferred software; pausing is the uninstall button.
Set it up in five minutes
You can put the alias method into practice quickly without overhauling your whole life. It is easy enough to do on your phone while travelling between stations.
- Choose five services where losing money would hurt most: your bank, mobile network, energy provider, Royal Mail and one shopping website.
- Change those accounts to name+bank@, name+network@, name+energy@, name+royalmail@ and name+shop@. Most sites allow the plus sign; if one does not, move on to the following section.
- Make a phone note titled “Aliases” and record them there. After checking it a few times, they will become familiar.
- Create one email filter for each alias. In Gmail, search for “to:[email protected]”, select “Create filter”, then choose “Star it” and “Apply label: Bank”. Add another filter for emails containing “Barclays” that are sent to your plain address, and send them to “Check First”. Outlook.com and iCloud Mail have similar rules in Settings.
- Explain what you have done to one person you care about. The strongest security advice is advice that gets shared.
What if a site blocks the plus sign?
Some services still object to “+”. It is strange, but it happens. You have alternatives. iCloud’s Hide My Email generates unique addresses that forward mail to your inbox. SimpleLogin and Firefox Relay provide the same kind of service. If you own a domain such as yourname.co.uk, you can create aliases like [email protected] that all arrive in one place.
For sites that refuse to cooperate, use one short, separate alias solely for low-risk registrations such as newsletters. Reserve the more carefully tailored aliases for accounts that can transfer money or reveal personal information. The point is visibility. If something claims to be your energy supplier but appears at your catch-all newsletter address, that mismatch is still useful.
A tiny habit that reshapes your day
The finest part of this approach is how it changes your online posture. You begin checking the “To” line as naturally as a pilot checks an altimeter. It ceases to feel like a chore and becomes automatic. In a world constantly trying to pull at your sleeve, you feel a little calmer. On a busy afternoon, you may find yourself scanning it without conscious thought as your coffee cools beside the keyboard.
There is a modest pleasure in it too: discovering who sold your details when a particular alias starts receiving junk, or seeing a fake bank email gently filed under “Nice Try”. This is not paranoia; it is routine maintenance, like locking the back door as you leave home. You still go out and live normally - you simply do not leave the lights burning all day.
For workplaces and big invoices
If your role involves money, make the plus-sign method part of your standard vocabulary. Use finance+supplier@ for each supplier and projects+clientname@ for chargeable work. Your team will be able to spot immediately when an email about banking details does not match the relevant thread. In Microsoft 365 and Google Workspace, administrators can set organisation-wide rules that flag messages supposedly “From” a supplier but sent “To” the wrong alias.
Combine this with a no-exceptions callback policy. Every request to change bank account details must be verified by calling a number already held on file. Do not use the number in the email, and do not make an exception “just this once”. Business email compromise is still emptying company accounts from Manchester to Milton Keynes. The criminals are patient, while their emails are calm and persuasive. You counter that calm with habits that are calmer still.
Police and fraud organisations continue to warn that losses amount to billions every year. That is not an attention-grabbing headline; it is the collective sigh of people who believed they were acting sensibly. The quiet, unexciting habit of checking an alias can make you the oddly fortunate person in the group chat. You click less, make one call, and the money stays exactly where you put it.
The small satisfaction of being unscammable
I would like to say I have always been clever, or that I learnt this lesson painlessly. I have had close calls before. The difference now is that I have made a small fence from my own email address, one I cross every day without stumbling. It does not delay me; it merely points me the right way.
That delivery scam did not get my £1.45. I entered the courier’s name into my browser, found that nothing was due and returned to my tea. The ping can still make me flinch, but the habit is now in place. Check the alias. Breathe. A simple trick, a calmer brain, and a lot of money left untouched.
Comments
No comments yet. Be the first to comment!
Leave a Comment