How to Spot a Scammer by a Website Address
Easily Identify Scams from Website Addresses in Texts or Emails
We’ve all received those suspicious texts claiming to be from a courier, urging you to click a link to track a parcel, or emails posing as your bank asking you to log in. It’s alarmingly easy to fall victim to these scams, but a simple method can help you spot the fraud—just by examining the website address, particularly the subdomain.
But first, how to find the domain name from the email
Here's an example in Gmail from MailChimp, this is the email address, and anything after the @ is the domain name:

Understanding Subdomains
A subdomain is an extension of a main domain and can be anything you choose. For example, our domain is polyspiral.com. A subdomain we create could look like subdomain.polyspiral.com. The key point is that subdomains are part of the main domain, and they can be customised without requiring separate registration.
Anyone can register an available domain name, but you can’t register a domain that’s already owned by someone else. For example, royalmail.com is owned by Royal Mail. However, a scammer could register a domain like mypackagedeliveryservice.com (available at the time of writing) and create a subdomain such as royalmail.mypackagedeliveryservice.com.
This trick exploits the fact that most people focus on the first part of a URL—in this case, "royalmail". However, the true domain is mypackagedeliveryservice.com, not royalmail.com. A scammer can easily build a legitimate-looking website on this domain to collect your personal details for malicious purposes.
How to Spot the Real Domain
The critical part of the URL is the section directly before the domain suffix (e.g., .com, .co.uk, etc.). This identifies the true owner of the website. Here’s how to check:
- Locate the Domain Suffix: Look for the last part of the domain, such as .com or .co.uk.
- Check the Word Before It: This is the main domain, not the subdomain. For example:
- royalmail.mypackagedeliveryservice.com: The real domain is mypackagedeliveryservice.com.
- subdomain.polyspiral.com: The real domain is polyspiral.com.
If the email or text claims to be from Royal Mail, UPS, or another trusted organisation, but the main domain doesn’t match, it’s a scam.
What to Do if You Spot a Scam
- Report It: Visit Action Fraud to report phishing attempts.
- Delete and Block: Remove the message and block the sender. Mark suspicious emails as spam to help your email provider filter them in the future.
- Stay Cautious: Avoid clicking links or providing personal information unless you’re certain of the sender’s legitimacy.
By understanding subdomains and knowing where to look in a URL, you can stay one step ahead of scammers. Always take a moment to verify website addresses before clicking links, and share this knowledge to help others avoid becoming victims.
