The IRS does not email you out of the blue — but criminals impersonating it do, and they want your practice far more than they want any one client’s refund. The lures aimed at tax professionals, the checks that expose them, and the weekly check the IRS itself tells you to run.
Published 21 September 2026 · ~9 min read · By the Phixo team
Most advice about IRS phishing emails is written for taxpayers: don’t click, the IRS won’t email you, watch for refund bait. All true, and all beside the point if you prepare returns for a living. Attackers worked out long ago that the person filing hundreds of returns is worth more than any of the people on them.
The IRS says so plainly in its guidance for tax professionals: criminals use stolen EFINs and CAF numbers to file fraudulent returns. Phish one taxpayer and you get one refund. Phish one preparer and you get a filing channel the IRS already trusts, plus a filing cabinet of Social Security numbers, dependants, bank details and prior-year returns — everything needed to make the next hundred returns look genuine.
So the question isn’t only “is this IRS email real?” It’s “what is this email actually trying to take from my practice?” Here are the four lures that land on tax offices, the tells for each, and the checks that settle it.
The IRS does not initiate contact by email to request personal or financial information. Real IRS contact starts with a letter in the post. There are narrow exceptions once a case is already open and you’ve agreed to correspond with a named employee — but an unexpected message asking you to verify an account, revalidate credentials, click a link or confirm details is not one of them, no matter how well it’s written or how convincing the sender looks. If you take one thing from this page: never resolve an IRS message from inside the message. Open IRS.gov yourself.
This is the one built specifically for you, and it is the most dangerous of the four. An email that looks like IRS e-Services correspondence says your account needs revalidation, your EFIN needs confirming, or your access will be suspended unless you act. The link goes to a login page that mirrors the real one. Whatever you type, the attacker now holds.
The deadline is the tell. Notice what it’s doing: it isn’t threatening you personally, it’s threatening your ability to file, in season, for clients who are waiting. That’s a far better lever than a refund, and it’s aimed squarely at the busiest, most distracted week of your year.
Two details worth holding on to. First, a domain that contains the word “irs” is not an IRS domain — read the part immediately before the final .gov or .com, because irs-eservices-portal.com and irs.gov.secure-login.net are both attacker-controlled. Second, even a perfect-looking irs.gov sender proves less than you’d hope, since display names and visible from-lines are easy to forge. The address is worth checking because it catches the lazy majority; it is not proof on its own.
An unsolicited email from a prospective client. Polite, plausible, often a little flattering about a referral. It asks whether you’re taking on new work, and attaches last year’s return or a summary of their situation — or links to it on a file-sharing page that asks you to sign in first.
This one works because saying yes is your job. A firm looking for clients is primed to open the attachment, and during filing season an unfamiliar sender is completely normal. The payload is either malware in the document or a credential-harvesting sign-in page behind the “shared file” link.
The defence isn’t to stop reading new enquiries — it’s to change the order of operations. Reply and ask a question before opening anything. A genuine prospect will happily answer, get on a call, or upload documents through your own portal once you point them at it. A phishing run rarely survives a conversation, because the attachment was the entire point.
Same mechanism as the e-Services lure, aimed at the other credential that matters: your professional tax software. An email says your subscription lapsed, your licence needs revalidating before the deadline, or a sign-in was blocked, and a link takes you to a convincing copy of the login screen.
This one is easy to underestimate because it doesn’t mention the IRS at all, and it lands amid genuine renewal traffic from the same vendors. It’s the same pattern we break down for accounting software in our guide to QuickBooks and Intuit phishing emails, and the answer is identical: never sign in through a link in a message about signing in. Open the application the way you always do — your own bookmark, the app itself — and see whether the warning is genuinely waiting for you there. It almost never is.
Not every attack aimed at your practice arrives in your inbox. Your clients get IRS-impersonation email too: a refund awaiting confirmation, a “discrepancy” needing verification, a demand for immediate payment. And when they get one, they forward it to you, because you’re their tax person.
That’s an opportunity rather than a nuisance. The firms that handle this best get ahead of it with one short note before filing season: the IRS will not email you; if you get one, forward it to us and don’t click; we will never ask you to send bank details by email. It costs one email a year, positions you as the person who protects them, and quietly inoculates your client base against the version of this scam that impersonates you — which is the one that eventually costs somebody a payment.
Worth being explicit with clients on the payment point: the IRS does not demand payment by gift card, wire transfer or cryptocurrency, and does not threaten to have someone arrested over the phone. Those specific demands are conclusive on their own.
Four checks, in the order worth doing them:
If you want to see the technical trail behind a message — where it actually originated and whether it passed authentication — our free email header analyzer reads the raw headers for you.
To settle a specific email: don’t click anything in it. Open a new tab, type IRS.gov yourself, sign in to e-Services, and see whether the notice is genuinely waiting for you. If it isn’t reflected in your account, the email is the fake — not your account.
The habit that actually catches a breach, though, is a different one, and the IRS spells it out in its guidance for tax professionals: track your weekly EFIN usage. The IRS posts the number of returns filed under your EFIN each week. Sign in to e-Services, open your e-file application, check EFIN Status, and compare it against what your practice actually filed. If the numbers are off, contact the IRS e-Help Desk. The same page suggests tracking your daily e-file acknowledgements — more acknowledgements than returns you sent is the same alarm from the other direction.
This is the highest-value five minutes in this article. Credential phishing is silent by design; a stolen EFIN produces no bounce, no alert and no obvious symptom. The return count is the one place the theft becomes visible, and it becomes visible while the fraudulent refunds can still be stopped.
Being straight about this matters more than a sales pitch. Automated email checks are genuinely good at the spoofed and lookalike cases, which is most of what lands: a sender on a freshly-registered domain that merely contains “irs”, a reply-to that doesn’t match the visible sender, a link whose real destination is nothing like its text, a message that fails its authentication checks (SPF, DKIM, DMARC). IRS.gov is among the domains Phixo watches specifically for impersonation, alongside the tax and accounting software brands.
What no tool can promise is catching a message sent from a genuinely compromised mailbox — a real colleague’s or a real client’s account that an attacker is sitting inside. By definition nothing about that message is technically wrong. That isn’t a gap in one product; it’s the reason the verify-out-of-band habit exists. Let a scanner take the spoofing and lookalike cases off your plate automatically, and keep a human rule for anything touching credentials, client data or money. Phixo also can’t see text messages, and IRS-impersonation scams arrive by SMS too — verify those the same way, by opening IRS.gov yourself.
One thing many small practices don’t realise: paid tax preparers fall under the FTC Safeguards Rule, which requires a written information security plan. The IRS publishes the background in Publication 4557, Safeguarding Taxpayer Data, and an actual template in Publication 5708.
Treat it as a floor rather than a strategy. But for a firm of three people, writing it down is what converts good intentions into a specific answer for who checks EFIN usage, on which day, and what happens when a number looks wrong. That’s the difference between knowing about this attack and being able to catch it.
Move fast; sequence matters more than perfection.
If credentials were entered on a fake login page, our step-by-step on what to do after giving a password to a phishing site covers the recovery order in more detail.
Not to start a conversation. The IRS states it does not initiate contact with taxpayers by email, text message or social media to request personal or financial information — real contact begins with a letter in the post. Narrow exceptions exist once a case is open and you’ve agreed to correspond with a named employee, but an unexpected email asking you to verify an account or click a link is not one of them.
Because your practice is a master key. The IRS warns that criminals use stolen EFINs and CAF numbers to file fraudulent returns, and your systems hold complete client records. Phishing one taxpayer yields one refund; phishing one preparer yields a trusted filing channel and the data to make hundreds of returns look legitimate.
The IRS posts your EFIN’s weekly return count. Sign in to e-Services, open your e-file application, check EFIN Status, and compare it with what you actually filed; if the numbers are off, contact the e-Help Desk. Track your daily e-file acknowledgements too — more acknowledgements than returns you sent is the same warning.
Forward it to phishing@irs.gov and delete it. If client data may have been exposed, contact your IRS Stakeholder Liaison as well — they notify IRS Criminal Investigation so filings made with your stolen credentials can be flagged. Speed matters, because fraudulent returns are much easier to stop before refunds go out.
Yes. Paid preparers fall under the FTC Safeguards Rule, which requires a written information security plan. IRS Publication 4557 covers safeguarding taxpayer data and Publication 5708 provides a template for writing the plan itself.
Phixo is a browser extension that checks the email open in your Gmail or Outlook across sender and domain reputation, reply-to and link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language — and explains, in plain English, why it flagged anything. IRS.gov is one of the domains it watches for impersonation. Each person installs it themselves; there’s no IT setup and no admin console. It won’t catch a genuinely compromised mailbox (nothing can), so keep verifying credentials and payments out of band — but it takes the spoofed and lookalike attacks off your plate. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.