Suspicious email Belgium

How to check a suspicious email, an external portal or a risky attachment.

Information checked : 2026-09-10

Understand / Check / Act

  1. Understand - What this scam is trying to obtain

    Check a suspicious email in Belgium and assess its sender, external portal, attachment and requested action before responding.

  2. Check - The safe channel to open yourself

    6 useful official sources listed below.

  3. Act - The useful next step

    I already took action

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
6
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

How this scam appears

  • How to check a suspicious email, an external portal or a risky attachment.
  • A message or call does not become genuine just because it uses a familiar name. Check the sender, the channel and especially the action requested separately.

Warning signs

  • Concerning sender
  • External link
  • Sensitive login or attachment

How to check without taking risks

  • Do not reply to the message and do not use the link, QR code or number it contains.
  • Open the official app or website yourself, then check whether the same request appears in your personal account.
  • If in doubt, contact the organisation using a number found on its official website, a reliable invoice or your bank card.

What to do immediately

  • Do not open the link without checking.
  • Go through the official website that you type in yourself.

If you have already clicked or replied

  • Close the page and do not enter any more information. If you shared a password, change it from the official website and everywhere it is reused.
  • If bank details, a code or a validation have been sent, call your bank immediately using its official number. Use Card Stop if a card is involved.
  • Keep the message and the observed address for reporting, without forwarding them to others as a clickable link.

Email-specific points

  • The display name and the real address are two different things. A similar-looking address, a different reply domain or an unexpected attachment must be checked separately.
  • The content may reuse a real signature or an intercepted conversation. A matching style does not replace confirmation of the payment, IBAN or document through another channel.

Attachments and links

  • Do not open an attachment to find out whether it is safe. First confirm the sender and the need for the document.
  • For a link, note the destination address without logging in. The final redirection may be different from the visible text in the email.

Hijacked conversations and invoices

  • A reply in an existing thread may come from a compromised mailbox. Check any new IBAN, new attachment or request for confidentiality separately.
  • For a business transaction, keep the headers and apply double validation instead of asking for a simple confirmation by return email.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the email received, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the email received depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

What to do now without panic

  • If the email received worries you, choose the next step from the requested action: clicking, paying, sharing a code, installing an app, sending a document or approving account access. Do not rely only on the logo or sender name.
  • When the email received involves an urgent, financial or hard-to-undo action, StopArnaques treats the situation as something that must be checked first. Polished wording, a familiar brand or a realistic amount does not make the request reliable by itself.
  • If you already acted in a case involving the email received, the order matters more than the label: contact the bank, platform or official service first, preserve evidence next, then compare the situation with similar campaigns.

What can be legitimate

  • For the email received, some notifications can be real: a delivery, invoice, administrative document, payment request, security alert or platform message. This is why this page does not claim that every similar message is automatically a scam.
  • The difference in a the email received case is verification. A real request should be visible through the app, portal, customer area or phone number that you open yourself, not only through a link, QR code or number included in the suspicious message.
  • If the official environment does not show the same request about the email received, amount, reference or beneficiary, it is safer to stop and report or verify the case before continuing.

Limits and responsibility

  • For the email received, StopArnaques helps explain signals and choose safer actions, but it does not replace your bank, the police, Safeonweb, the FPS Economy, a platform or the organisation concerned.
  • A result about the email received may remain uncertain when the text is too short, when context is missing or when the fraud uses a new variant. In that situation, slow down, verify independently and avoid any irreversible action.
  • If the email received involves a payment, code, card, identity document, itsme approval, banking app or remote access, the protective action comes first. Do not wait for a perfect label if harm may already be possible.

Keep evidence and report

  • For the email received, keep the message, date, channel, visible sender, neutralised link and useful screenshots. Do not publish personal data or clickable suspicious links on social media.
  • Report the email received to the relevant channel when appropriate, for example Safeonweb for suspicious messages, the platform for account abuse and your bank when money or payment details are involved.
  • This evidence about the email received can also help link a campaign to a case later without storing raw personal data. That matters if the system is to improve without exposing users unnecessarily.

Frequently asked questions

How can I check this contact without using its link or calling back?

Do not open the link without checking. Then compare the request with your official account and test the text or link in the StopArnaques detector.

Which signs should make me stop?

Stop the interaction if you notice in particular: concerning sender, external link, sensitive login or attachment. A familiar visual identity never makes up for an unusual request.

Does the detector replace official verification?

No. The detector helps you understand the risk and the signs observed. For a banking, administrative or account-related operation, always confirm with the official service through an independent channel.

Useful official sources

Test another suspicious message

I already took action

I already took action

I already took action

I already took action

Prepare my next steps