SecurCheckCyber Centre

ANTAI · TAX · AMELI

How to spot a fake public-service email or text message

Secur Cloud ·

A fake fine, tax refund or health-card message may copy public-service logos and wording. Its goal is to send you to a fake form asking for card details, passwords, sign-in codes or documents. Staff and finance teams can be targeted through personal and work accounts alike.

A displayed logo or name does not prove origin. Examine the message and address, then verify any request through the official portal you open yourself. The tool helps surface signals without authenticating the agency or accessing your case.

1. Recognise refund bait and penalty pressure

A notice may promise a tax refund, then demand card details to ‘receive the funds’. This is a strong warning sign: the tax authority does not request a card number for a refund. Do not submit details; check your account at impots.gouv.fr.

Another message may threaten a higher fine or suspended health benefits. ANTAI warns that texts demanding payment of a fine in its name are fake. Ameli also says issuing and shipping a new health card is free: ‘delivery fees’ are a trap.

2. Examine domains and email headers carefully

Read the actual domain rather than the logo or words placed before an address. ‘antai-gouv-amende.fr’ is not ‘antai.gouv.fr’. Genuine French services also use domains without ‘.gouv.fr’, such as ameli.fr and urssaf.fr: compare with the agency's published address rather than relying on the suffix alone.

For email, the displayed sender can be spoofed. Checking the original message with full headers can examine From, Reply-To, SPF, DKIM and DMARC; a text or forwarded excerpt lacks that evidence. Authentication is only one clue: a fraudster may authenticate their own domain, while forwarding can affect a legitimate message's headers.

Help your staff spot phishing that impersonates public services

Fake messages from tax authorities, Urssaf, ANTAI or health insurance may announce a fine, refund or blocked account. Copied logos and urgency pressure people into sharing card data or sensitive credentials.

SecurCheck Business helps administrative and finance teams review suspicious texts or emails: payment requests, recognised links and domains are checked; original email headers allow additional technical checks. Staff are guided to confirm requests through an independently opened official portal.

A result does not certify the sender or a case. SPF, DKIM and DMARC require usable email headers; no response time is guaranteed.

Read the guide: fake public-service messages

Explore the Business offer

3. Verify the request without following its link

  1. Open the portal yourself

    Type the official address or use a verified bookmark, then check your account and case reference. For fines, ANTAI lists antai.gouv.fr and amendes.gouv.fr. If unsure, contact the agency through details published on its official site.

  2. Protect access and documents

    Do not share card details, FranceConnect codes, passwords or ID through a received link. If you already entered a secret, change the password through the official service, secure affected accounts and contact your bank promptly for exposed payment data. Alert your IT team if a work device is involved.

  3. Keep evidence and report

    Keep the message and URL. Report fraudulent texts to 33700; ANTAI also directs people to internet-signalement.gouv.fr for impersonating sites. For suspicious email, use Signal Spam or the agency's published reporting channel. Reporting does not guarantee immediate blocking.

Official sources: ANTAI · DGFiP · Ameli · Signal Spam.

Conclusion: verify at the source

Text and link checks, plus technical headers for original emails, can help spot impersonation. Checking your case through the official portal remains essential before payment or disclosure.

Explore SecurCheck Business for your team