Treat any unexpected IRS message as suspicious and verify it outside the message itself. The IRS does not contact people through email, text, or social media for personal or financial information. Delete the message, do not reply, and if verification is needed, go directly to the official IRS website or use a known official phone number.
How to verify an IRS message before you act
The safest test is to separate the message from the decision. Do not click, reply, or use contact details inside the message. Instead, verify independently through the official IRS website or a known legitimate phone number. That matters because phishing messages often imitate routine tax notices, refund updates, or identity checks to pressure quick action.
What a legitimate IRS contact should and should not look like
A real IRS message will not ask for personal or financial information through email, text, or social media. It also will not rely on urgency alone to force a response. If the message says there is a problem, treat the claim as unconfirmed until you check it through a trusted IRS channel you already know is authentic. The key issue is not whether the message looks official, but whether the channel is verifiable.
Verification should focus on the sender, the channel, and the requested action. A message that contains links, attachments, or login prompts is higher risk than a plain informational notice, especially if it asks you to “confirm” identity, open a refund portal, or call a number provided in the message. For a practical verification path, use the IRS website directly and compare the wording against IRS phishing guidance.
What to do when the message demands immediate action
Do not let the request dictate the verification method. If a message says your refund is on hold, your account is locked, or a payment is overdue, step away from the embedded links and look up the IRS contact information yourself. If the message is fraudulent, the safe response is to delete it and avoid engagement. If you want a broader model for the same habit, the principle is the same as FIRST incident response standards: verify the event through an independent, trusted path before acting on it.
Use the content of the message only as a clue, not as proof. The subject line, sender name, and formatting can all be spoofed. A caller or text sender can also impersonate a government agency and still be fake. If the message includes a link or phone number, do not treat that as validation. Use a known official source instead, even if that means taking a few extra minutes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Identity and Credential Management | Verifying IRS contact prevents unsafe response to spoofed identity claims. |
| Recommendation — Use verified channels before responding to any tax-season IRS request. | ||
| CIS Controls v8 | CIS-5 — Account Management | Phishing checks protect account access from fraudulent requests. |
| Recommendation — Require independent verification before acting on account-related tax messages. | ||
| MITRE ATT&CK | T1566 — Phishing | IRS impersonation messages are a classic phishing delivery path. |
| Recommendation — Treat unexpected IRS messages as phishing until independently verified. | ||
Practitioner Guidance
What to verify: Confirm the claim through a separate IRS channel, not through the message itself. If the message points you to a website, compare it with the official IRS domain you navigate to manually. If it asks for credentials, payment, or identity details, treat that as a verification failure until proven otherwise.
Common mistake: People often verify only the sender display name or the first line of the message. That is not enough. The practical standard is whether you can independently reach the IRS through a path you chose yourself, not one embedded by the sender.
Decision rule: If the message is unexpected and asks for action, do nothing until you have confirmed it outside the message. If you cannot independently confirm it, assume it is unsafe and delete it.
Practitioner takeaway: The safest tax-season habit is to make every IRS claim prove itself through an independent channel, because the channel is what you trust, not the message.
Related resources from NHI Mgmt Group
- What happens when employees respond to business email compromise during tax season?
- How should people verify whether a COVID-related message is legitimate before they act on it?
- What should smaller accounting firms do first to protect a public website during tax season?
- How should employees respond when a tax refund message arrives by phone, email, or text and asks for immediate action?