Is this SARS email real? How to check, in tax season
Five scam alerts logged on SARS's own register in six weeks, and a separate alert about a phishing link hidden inside a PDF. One check settles all of them.
Start here: SARS has told you what it never does
You have an email in front of you. It says SARS, it mentions an assessment or a refund or — worse — a summons, and the deadline in your head makes it feel plausible. Before you read another word of it, run this test.
SARS states plainly that it *"will never request passwords, one-time pins (OTPs), banking PINs, or eFiling login credentials through email, SMS, social media, or telephone."* It also does not send hyperlinks to external websites in its communications, does not ask for your credit card details, and does not send .htm or .html file attachments.
If the email in front of you does any one of those things, you're done. It's not real. Skip to the third section below for what to do with it, and don't open anything else in it first.
Why your inbox is full of these right now
The reason a SARS email lands in September and feels expected is that it is expected — Filing Season 2026 runs from 13 July to 23 October for non-provisional individuals, and from 13 July 2026 all the way to 22 January 2027 for provisional taxpayers, which is most business owners. Whichever one is yours, a message about your return right now sits inside a window you were already watching for.
That's exactly what's being rented. SARS's own scam register has logged five fresh alerts in six weeks: a fake High Court summons (2 September 2026), a fake ITA34 notice of assessment (27 August), another fake assessment (5 August), a "Tax Return Notification – Action required" (28 July), and "Sars Tax Return Approve R68 652.86" (22 July) — a fabricated refund. Notice the range: a refund to tempt you, a summons to frighten you, an assessment to make either one look procedural. SARS says it directly: *"In the run up to Filing Season there will be many attempts from scammers to mimic what we do and try and get your personal details, or to pay money into an account."*
Don't click anything — open eFiling yourself
Here's the one move that settles every version of this, permanently: close the email. Log into eFiling the way you normally do — not through any link in the message — and look for yourself.
If there's a real assessment, a real refund, or a real demand, it's sitting in your eFiling profile. If it isn't there, the email wasn't real, whatever it looked like. You don't need to spot a convincing fake. You just need to stop trying to judge the email at all, and check the one place that actually holds the truth.
The PDF is the part people get wrong
Most people's rule by now is "don't click links in emails." That rule is exactly what the current wave is built around. In a scam alert SARS published on 22 July 2026, it describes an email impersonating a SARS employee — with a PDF attached, not a link in the body. SARS's warning is direct: *"Please don't open the PDF attached to the email or click on the link in the PDF as it is a fraudulent phishing link designed to extract personal details from you to be used in a scam."*
An attachment feels safer than a link. That feeling is the trick. Opening the PDF "just to see what it says" is the click — the dangerous part was moved one step later, past the rule you'd already trained yourself to follow. SARS's scam register also logged an entry the same day, 22 July 2026 — "Sars Tax Return Approve R68 652.86" — but that's a separately published item, and this post makes no claim about whether the two are the same campaign. Pair the PDF alert with SARS's other stated rule: it does not send .htm or .html attachments, so anything that opens as a web page instead of a document has already failed the test.
What to tell your staff before the next one lands
You're not the only target. Anyone who touches payroll, PAYE, or supplier payments will get one of these eventually, and it's worth saying three things out loud once, before it happens:
- Nobody actions a tax or payment email by clicking anything in it. They open eFiling, or whatever system it claims to be from, directly.
- A summons or penalty email never gets handled alone. It comes to you first — urgency and fear are the whole mechanism, and slowing down is the fix.
- Forward anything that looks suspicious to the reporting address published on SARS's Scams & Phishing page rather than deleting it. That page is also worth a minute's check on its own — it's a public, dated list, and cross-referencing an email against it takes less time than second-guessing it.
If payroll and PAYE mail is the exposure in your business, that's also where payroll software built for South African filing helps — one system your staff check, instead of one more inbox to guess at. And this sits alongside the wider staff-security habits in our small-business cybersecurity checklist, which covers phishing generally rather than SARS specifically.
The one thing this test cannot catch
Everything above is for a message claiming to be from someone else — SARS, in this case. It does nothing about mail sent as *your own* domain to your customers, which is a different problem with a different fix: one that lives in your DNS, not in your inbox. That's how a customer can receive a convincing invoice with new banking details on it that you never sent. If that's a gap you haven't closed, our post on email authentication covers it.
Want the rule set once for your whole team — the checks in place, staff told once, and someone to forward the questionable email to instead of guessing at 16:45 on a deadline day? Get in touch.
General information, not legal or tax advice.
Get the rule set for your team
We set up the checks, tell your staff once, and take the questionable email off your hands.
Get in touch →