# IRS phishing email: how to verify and report it

> Learn how to check an IRS phishing email, verify a tax claim without using the message, report it safely, and respond if you shared information.

Treat an unexpected IRS email as unverified until you confirm its tax claim through a federal government site or contact method you found independently. Do not use the message's link, attachment, reply address, payment instructions, or phone number. A government seal, case number, refund amount, or threat of a deadline cannot prove that the sender is the IRS.

## Quick takeaways

- Stop if the email asks you to pay, sign in, open a tax document, or provide personal data.
- Do not use a phone number or reporting link contained in the message.
- Verify the notice through a government destination you open independently.
- Separate a refund claim from a demand for money or identity information.
- Report the email through your mailbox and current official government guidance.
- Protect tax, financial, and account information promptly if you already shared it.

## What does an IRS phishing email look like?

An IRS impersonation email usually gives a tax-related reason for immediate action. The claim may involve a refund waiting for confirmation, unpaid tax, an audit, a corrected return, a transcript, identity verification, a penalty, or a notice that supposedly expires soon. The email then asks the reader to follow a link, open a document, call a number, pay, or submit personal information.

Those are pattern shapes, not a description of one campaign. The details can change while the decision problem stays the same: the sender is using tax authority and time pressure to keep you inside the message.

The Federal Trade Commission's [phishing guidance](https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams) describes messages that impersonate familiar organizations and try to obtain money or personal information. An IRS-themed message fits that general model when it uses the agency's identity to direct the recipient into a sender-controlled action.

Do not approve a message because it includes your name, partial tax data, a plausible filing year, or an official-looking signature. Personal details can make a pretext more convincing, but they do not establish who sent it.

For examples across other organizations, use the [phishing email examples page](/learning/phishing-email-examples). This guide stays with the tax-specific verification and recovery choices.

## Which IRS email clues matter most?

Start with the request. A demand to send money, buy a payment instrument, provide a Social Security number, upload tax records, disclose bank details, or enter account credentials creates immediate risk. Do not comply through the email, even if the tax issue sounds plausible.

Read the complete sender address rather than stopping at "IRS" in the display name. Look for misspellings, extra words, unrelated domains, and a Reply-To address that differs from the visible sender. Do not treat any address as a permanent allowlist. A familiar-looking address does not validate the notice or the destination behind a button.

Preview links without opening them. Do not infer that a site is official merely because `irs`, `refund`, or another government word appears somewhere in a long hostname or URL path. Compare the complete destination with a federal government site that you reached independently through your own bookmark, records, or typed navigation.

Attachments deserve the same caution. A file named like a notice, transcript, or refund form can still be a lure. You do not need to open it to verify whether your tax account or records contain the claimed issue.

## How can I verify an IRS claim safely?

Leave the email unused and open a new browser session. Navigate to the federal government destination you normally use for tax matters by typing it yourself or using a trusted bookmark. If you rely on a tax professional, contact that person through the number or address already in your records.

Match the message's claim with evidence you control:

- For a claimed refund, check the status through an independently opened government service and compare it with your filed return.
- For tax owed, review your own return, prior notices, account records, and known payment history.
- For an audit or identity question, locate current official instructions without following the email.
- For a transcript or document, confirm that you requested it and find the corresponding activity through a trusted route.
- For a payment change, stop and verify the obligation and payment method separately.

If a real issue exists, continue only through the independent session or verified professional. A phishing email can refer to a subject that genuinely matters. Confirming the issue does not make the email's link or contact details safe.

Do not use a search advertisement as automatic proof of an official destination. Check the hostname carefully and begin from a federal government site you recognize from your own records. If uncertainty remains, use contact information on a prior genuine notice rather than the email in question.

## How do I report an IRS phishing email?

The IRS publishes a reporting address for suspicious email: send it to `phishing@irs.gov` ([IRS: report phishing](https://www.irs.gov/privacy-disclosure/report-phishing)). The IRS states it will never initiate contact with you by email ([IRS: privacy guidance about email contact](https://www.irs.gov/privacy-disclosure/irs-privacy-guidance-about-email-contact)), so treat any emailed request for personal or financial information as fraudulent, so treat any such request as fraudulent regardless of how the message looks.

First, locate the reporting process documented by the provider or organization responsible for the receiving mailbox. Do not assume that every mailbox has the same button or forwarding address. A work mailbox may also require an internal security report, especially if the email involved employee, payroll, or managed-device access.

To report the impersonation to the IRS, forward the message to `phishing@irs.gov` with `IRS` in the subject line, or `Treasury` if the message claims to be from Treasury. Send it **as an attachment** rather than a plain forward: the IRS notes that forwarding normally strips the header data it needs to identify the sender. Never use a reporting form linked from the suspected message itself.

Follow the documented process for retention, deletion, or submission of the original message. Avoid broadly forwarding it. If another person needs to assess it, use the organization's approved security process.

The [report-email-phishing-scams guide](/learning/report-email-phishing-scams) explains what evidence to keep and why mailbox reporting is different from notifying the impersonated organization.

## What if I already clicked or sent tax information?

Move from message analysis to recovery. Record what you exposed, when it happened, and which account or device was involved. Do not continue answering the sender in hopes of correcting the mistake.

- If you entered a password, change it through the real account and replace it anywhere else you reused it.
- If you supplied a Social Security number, tax document, or identity record, follow independently located government identity-theft guidance.
- If you shared bank or card information, contact the financial institution through the number on the card or a known statement.
- If you sent money, contact the payment provider and preserve receipts and transfer details.
- If you opened an attachment or installed software, contact your security team and follow the endpoint incident process.
- If the message involved a work tax, payroll, or benefits account, notify the responsible internal team without sending the suspicious file around.

Treat password recovery, payment response, identity recovery, and device response as separate tasks. Complete each path that matches the information or access you disclosed. The [clicked-phishing-link recovery guide](/resources-post/what-to-do-if-you-clicked-on-a-phishing-link) provides a fuller decision tree.

## Why did an IRS phishing email reach me?

An email reaching the inbox is not proof that the sender is genuine. The visible From address can also differ from the identities that SPF or DKIM evaluated, so a recipient still has to verify the tax claim outside the message.

[DMARC helps a domain owner connect authentication with the domain shown to the reader and publish a requested policy for failures](https://www.rfc-editor.org/rfc/rfc9989.html). That makes it relevant to direct domain spoofing. It does not examine tax records, confirm a refund, validate a payment request, or identify the person controlling a reply address.

The explanation of [why phishing can pass SPF and DKIM](/learning/why-do-phishing-emails-pass-spf-and-dkim) covers authenticated lookalike domains, compromised accounts, and the limits of transport evidence. For an IRS-themed message, the safe answer still comes from independently verified tax records and government channels.

## A safe IRS email decision rule

Write down the claimed tax event and the action the sender wants. Then remove every link, number, address, attachment, and payment method supplied by the email from your verification path.

Open a trusted tax account, locate an official government site separately, consult your filed records, or contact a known tax professional. If no independent evidence matches, report the email as suspected impersonation. If evidence does match, handle the real issue through the trusted route and keep the email unused.

This process avoids two common errors: trusting a fake because the topic is plausible, and ignoring a real tax issue because the message carrying it was fraudulent. The email and the underlying tax question are separate objects.

## When does this guidance change?

An expected message tied to a tax action you just took still deserves normal link and sender checks. Expectation improves context, but it does not turn the message into an identity guarantee. Open your known account or records to complete sensitive steps.

An authorized workplace simulation may also use IRS-style language. Employees should still use the standard reporting control. The training team can confirm the exercise through its established channel after the report arrives.

This guide does not decide whether the IRS sent a particular message and does not supply an official sender allowlist. Message templates and sending systems can change. Independent verification avoids relying on a static list that may be incomplete or stale.

## Sources and further reading

- [Federal Trade Commission: How to recognize and avoid phishing scams](https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams)
- [RFC 9989: Domain-based Message Authentication, Reporting, and Conformance](https://www.rfc-editor.org/rfc/rfc9989.html)
- [Palisade guide to reporting phishing](/learning/report-email-phishing-scams)
- [Palisade phishing examples](/learning/phishing-email-examples)

## Frequently asked questions

### Does a tax refund amount prove an IRS email is real?

No. A plausible amount is message content, not sender proof. Compare the refund claim with your filed return and an independently opened government service.

### Should I call the phone number in an IRS email?

No. Use a contact method from a prior genuine notice, your trusted tax records, or an official government site you opened separately.

### Can I open an attached tax notice just to inspect it?

No. Verify the claimed notice through a trusted account or contact first. An unexpected attachment should remain unopened unless an authorized security process handles it.

### What if the tax problem mentioned in the email is real?

Handle it through the independently opened government account, verified professional, or trusted notice. Do not return to the email's link, attachment, or payment instructions.

### Is reporting the email enough after I shared my Social Security number?

No. Reporting addresses the message. Identity, account, payment, and device recovery are separate tasks and should begin through independently located official channels.
