Every mailbox gets junk. Most of it is only annoying — but some of it is written to take your password, your money, or both. This guide shows you the ones actually landing in South African inboxes, pictured, so you can recognise them at a glance.
Every scam in this guide works the same way: it invents a deadline so you act before you think. Take the pressure away and almost all of them fall apart.
Bulk advertising you never asked for. Newsletters, "special offers", conferences, SEO services, printer toner. It clutters your inbox but it isn't trying to rob you.
An email pretending to be someone you trust — your email provider, your bank, a courier — to get you onto a fake login page and steal what you type.
Emails aimed straight at your money: fake invoices, changed banking details, prizes, "investments", blackmail, or a phone number that connects you to a fake helpdesk.
This is the one we see most often, because it targets the thing every business has: an email account. It arrives looking like a system message from your own mail server and it wants one thing — for you to type your email password into a page that isn't ours.
Where the button goes is the whole point. It opens a login page built to look like webmail — and the moment you type your password, the criminal has your email account. From there they read your invoices, watch how you write, and start sending convincing requests for payment to your own customers.
A parcel is supposedly stuck, and a tiny customs or redelivery fee will release it. The amount is deliberately small so it feels safer than checking — but the page that takes the R45 is really there to capture your card number. The real charge appears weeks later, and it is not R45.
You're told your antivirus, cloud storage or "premium support plan" has auto-renewed for a few thousand rand. There's no link to click — just a phone number to cancel. That number is the scam. It puts you on the phone with a friendly "support agent" who asks to connect to your PC to process the refund, and once they're in, they take over your online banking.
An alert claims money is leaving your account, and offers a button to stop it. Panic is the product. The link leads to a copy of your bank's login page, and some of these pages ask for your OTP in real time so the criminal can use it while you're still typing.
What to do instead: close the email, open your banking app, and look at your own transaction list. If something really is wrong you'll see it there — and the number to phone is on the back of your card.
The oldest scam in email, still sent because it still works. You've won a competition you never entered, a stranger wants to share a fortune, or a trading platform is showing 40% a month. They all end the same way: a small "release fee", "tax" or "minimum deposit" that grows every time you pay it.
A blackmail email claims to have hacked your webcam, and demands payment in Bitcoin within 48 hours. It sometimes quotes a real password of yours, which is what makes it land — and that password came from a website breach years ago, not from your computer. There is no video. There is no access.
The costliest scam of all is a supplier's invoice with a new account number on it. That one has its own guide — how to check who really sent it, and how to avoid paying a criminal.
Read: Is this email real? →The words in a link are just words — a button that says "Visit our website" can point anywhere at all. The real destination is always visible before you commit, on every device.
On a computer: rest your mouse pointer on the link without clicking. The true address appears at the bottom of the window, or in a small bubble beside the pointer.
On a phone: press and hold your finger on the link for a second or two. A panel slides up showing the full address — read it, then tap Cancel or press outside the panel to dismiss it without opening anything.
Read the address from right to left. The part that matters is the last name before the first single slash — here that's zx-mailsecure.ru. Everything to the left of it is decoration the criminal chose, including any real company name they've put there to reassure you.
If the destination isn't a domain you recognise, don't open it. And even if it looks right, it costs you nothing to go to the site yourself instead.
Swipe left on the message → More → Move to Junk. Or open it, tap the flag icon, then Move to Junk.
Press and hold the message to select it, tap the ⋮ menu, then Report spam or Block sender.
Right-click the message → Junk → Block Sender. The message moves to the Junk Email folder.
Select the message and use the Spam or Junk button in the toolbar. Ask us if you can't find it.
Clicking a link on its own is rarely a disaster. What matters is whether you typed something into the page that opened, or ran something it offered you.
If you entered your email password:
If you entered card or banking details:
If you installed something or let someone connect:
Forward it to us and ask, or phone before you do anything else. There's no charge for a second opinion, and no such thing as a silly question when your password or your money is involved.
Monday to Friday, 08:00–17:00
Call 078 247 2221