Received an email this week that looks exactly like it has come from the income-tax (I-T) department? The tricolour emblem is there, so is the familiar blue e-filing header, a reference number and a polite request to ‘click here to view your important message’. 
 
Before you do anything else, take a breath. It is very likely fake — and it has been built, quite deliberately, to fool you.
 
One such email doing the rounds carries the subject line ‘Income Tax Department | Important Message’ and appears to come from [email protected]. Everything about it screams authenticity: the layout, the fonts, the official disclaimers about confidentiality under the Income-tax (I-T) Act, 1961, and the Information Technology (IT) Act, 2000. There is even a made-up reference number (ITBA/AST/F/17/2025-26/1035917840) and an assessment year tag (AY25-26) thrown in to make the whole thing feel procedurally watertight. It mentions ‘Information u/s 143(1) — Processing of Return’ and invites you to log in via a bright orange ‘View Message on e-Filing Portal’ button.
 
Here is the catch, though. Look past the display name and check the actual sender address, and you will find the email has really been sent from ‘[email protected]’ — a domain with absolutely nothing to do with the government. Click the button, and it doesn't take you anywhere near incometax.gov.in either. Instead, it drops you onto a completely unrelated web address (api.teledema.scoding.com/storage/foi/index.html) hosted on infrastructure with no connection whatsoever to the I-T department.
 
That one mismatch, between what the email claims and where it actually sends you, is the entire scam laid bare.
 
And this is not a one-off. It is part of a much larger, ongoing pattern.
 
A Pattern, Not an Isolated Incident
Tax-themed phishing has become one of the most persistent scams in India, and it tends to flare up every year around income-tax return (ITR) filing, tax refund, and assessment seasons (mainly July and August, but can extend) — precisely when people are anxiously refreshing their inboxes, waiting for something genuine from the I-T department.
 
Cybersecurity researchers at CloudSEK have flagged an active campaign this tax season impersonating the I-T department, sending fake penalty notices via WhatsApp and emails that push victims to download malware capable of harvesting one-time passcodes (OTPs) and banking credentials. 
 
Another recent wave, reported by Trak.in, targeted taxpayers, chartered accountants (CAs) and corporate finance teams, using official-looking notices designed to trick recipients into installing remote-access malware. 
 
Just last month, a similar fake email threatened prosecution over alleged ‘tax irregularities’, giving recipients a mere 72 hours to submit documents through a link. As TaxGuru reported, the message falsely claimed irregularities had been found under Section 271(1)(c) of the I-T Act, piling on pressure to act immediately — that familiar cocktail of official-sounding language and a ticking clock, engineered to make you click before you think. 
 
A related version of the same scam, flagged separately by TaxGuru, used a fabricated ‘Tax Authority Checklist’ reference number to lend it even more legitimacy.
 
The Indian government's own fact-checkers have hardly had a quiet year. Earlier in 2026, a fake email claiming taxpayers owed a demand for AY25-26 circulated widely enough that the Press Information Bureau (PIB) had to step in publicly and confirm that neither the email nor the ‘assessment order’ it referenced were genuine
 
Barely a fortnight ago, another message did the rounds claiming a modest, entirely believable ₹6,000 tax demand — and once again, the PIB fact check team had to clarify it was a phishing scam, not a real notice. Incidentally, it landed right in the middle of refund season, when a tax demand notice or ‘you owe more tax’ message feels just plausible enough to work.
 
Refunds get used as bait just as often as demands do. One widely circulated email, covered by Business Standard, promised a refund of ₹60,000 but insisted the taxpayer ‘manually verify’ it by clicking through a link — a tactic the PIB flagged as a deliberate attempt to harvest bank details and passwords. 
 
Fake e-PAN offers have made the rounds too, with cybercriminals sending emails dressed up as government communication and urging people to download an ‘instant’ e-PAN card — the real goal being to extract PAN, Aadhaar, bank account and password details.
 
What the Tax Department Says
 
That advice holds just as true a decade on. More recently, the tax department reiterated on its official social media handle that it never asks for confidential information such as OTPs, PINs or passwords via email or SMS and advised taxpayers to rely solely on the official e-filing portal, incometax.gov.in, for anything to do with filing, refunds or verification.
 
Genuine government notices don't arrive from free email services either. In one advisory, the department clarified that neither it nor other government bodies issues statutory notices through private email services — genuine communication comes through official government channels, full stop. The same logic applies to lookalike domains like the one in this case: anything that isn't a genuine ‘@incometax.gov.in’ email address should be treated as suspect by default.
 
How To Protect Yourself
None of this takes any technical expertise. It just takes a habit of pausing before you click.
 
  • Check the actual sender email address, not the display name. All emails follow the same format: the sender's name followed by the email ID. Fraud emails often set the name to something like ‘Income Tax Department’, but the real address behind it — visible the moment you tap or hover over the sender — gives the game away. In the case above, the email ID was from a completely unrelated domain with no government linkage at all. The fraudsters used ‘[email protected]’ as the sender’s name to fool the recipient into assuming it was sent by the tax department. Check the actual (fraud) email ID in <> below.

           
          
  • Never click links inside unexpected tax emails. Open a browser yourself instead and type incometax.gov.in directly, or use the official app. If there is genuinely a message waiting for you, it will be sitting there when you log in through the front door — not arriving via a link someone sent you.

  • Be suspicious of urgency. Genuine tax processes don't usually threaten action within 72 hours or demand instant ‘reconfirmation’. That ticking-clock pressure is manufactured purely to stop you thinking clearly.
     
  • Never share OTPs, PAN details, passwords or banking information over email, SMS or WhatsApp, however official the request looks. Government departments and authorities have repeatedly said that they simply don't ask for this over these channels.
     
  • Look for the mismatch. Spelling errors are rare in modern scams, but a mismatched sender domain, an odd-looking link when you hover over a button, or a reference number that means nothing when checked on the real portal — these are the giveaways worth training your eye to catch.
     
  • Report it, rather than just deleting it. Suspicious emails claiming to be from the I-T department can be forwarded to [email protected], with a copy to [email protected], as outlined on the I-T department's official phishing report page. Reporting helps the department flag the domain and warn other taxpayers before more people fall for it.
 
The Bigger Picture
What makes this particular scam effective is not clever hacking — it is patience and imitation. The cybercriminals behind it have clearly studied genuine I-T department communication closely enough to reproduce its tone, structure and visual identity almost perfectly. 
 
The illusion breaks down only in two places: the sender's email address and the destination of the link, which, not coincidentally, are the two things most people never actually check.
 
That is the real lesson here. 
 
As government services move further online and taxpayers grow accustomed to receiving digital notices, cybercriminals will keep refining their impersonations to match. Treat the tax department the way your bank taught you to treat your bank: log in yourself, don't click your way in. 
 
A minute spent checking a domain name is a small price to pay against the very real risk of a drained account or a stolen identity.
 
Stay Alert, Stay Safe!