Checking an invoice is genuine
An invoice has arrived from a supplier you do not recognise, or one you do recognise asking for something different. This is the order worth working through, and — just as usefully — where the verifiable part ends.
Most fraudulent invoices are caught by one of the first two steps. Almost none are caught by staring harder at the PDF.
1. Did anyone actually order this?
Before checking whether the company exists, check whether the purchase exists. Match the invoice to a purchase order, a delivery, or a person in your organisation who can say “yes, I asked for that.”
This single step catches the largest category of fake invoices, which are not sophisticated at all: plausible-looking bills for office supplies, directory listings, domain renewals or “compliance registrations”, sent in volume to businesses in the hope that one gets paid without anyone asking. They rely entirely on nobody checking whether there was ever an order.
Directory and registration invoices deserve special mention. They are often technically worded as an offer rather than a bill — the small print says so — and are designed to be mistaken for a renewal of something you already have.
2. Is this a change from what you did before?
If you have paid this supplier previously, compare against the last invoice:
- Same bank account?
- Same legal entity and VAT number?
- Same sending address and domain?
- Amount and terms in the normal range?
A change in bank details is the one that matters most, and it has its own guide: a supplier emailed asking to change their bank details.
3. Check the identity claims
These are the parts a computer can verify, and you can run all of them at once on the homepage. Each answers a narrow question:
- VAT number. Is it currently registered, and to whom? A valid number proves the registration exists; it does not prove the sender owns it, since VAT numbers are public. See valid VAT number, different name.
- IBAN. Is it correctly formed, and issued in the country you would expect? The checksum catches typos essentially always. It says nothing about who owns the account — no public source can. See IBAN country differs from VAT country.
- Sanctions screening. Does the name resemble an entry on the EU consolidated list? A similarity, not a determination. See what a possible match means.
- Sending domain. Does it authenticate its own email, and how old is it? A domain registered three weeks ago that publishes no DMARC policy is a different proposition from one that has existed for a decade. See no DMARC policy.
4. Read the document itself
Worth a look, but weak evidence in both directions — a competent forgery gets all of this right, and legitimate small businesses get plenty of it wrong.
- Required particulars. An EU or UK VAT invoice must carry an invoice number, date, the supplier’s name, address and VAT number, a description, the net amount, VAT rate and VAT amount. Missing several of these on a large invoice is a reason to query it.
- Arithmetic. Does the VAT actually equal the stated rate applied to the net?
- Consistency. Does the VAT number’s country prefix match the address? Does the currency match the country? Is the invoice number plausible against previous ones?
- The bank details block. Look for signs it was edited separately from the rest — different font, alignment or spacing.
5. Pick up the phone
For anything material, and for every change of bank details, call the supplier on a number you already had — from an earlier invoice, your accounting system, or their website navigated to yourself. Never the number on the invoice or in the email.
This is the step that catches the fraud that passes every other test: a real supplier, a real VAT number, a real domain, a real invoice, and someone else’s bank account.
What none of this can tell you
It is worth being clear about the boundary, because tools that blur it are how people end up over-trusting a green tick:
- Who owns a bank account. Not public in the EU or UK. There is no lookup.
- Whether the goods or services were delivered. Only your own records answer that.
- Whether the company is solvent, or intends to deliver. A registered company with clean records can still be a bad counterparty.
- Whether the person emailing you is who they claim to be. Email authentication proves a message came from a domain. It cannot prove who was sitting at the keyboard, which is precisely why a compromised mailbox defeats it.
This is also why the tool on this site returns four independent results and never a single “safe to pay” verdict. Each check answers its own narrow question honestly. Combining them into one number would imply an assurance that none of them, together or apart, can give.
Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.