Checking an invoice is genuine
By Jose PollmanPublished Updated
An invoice has arrived from a supplier you do not recognise, or one you do recognise asking for something different. This is the order worth working through, and — just as usefully — where the verifiable part ends.
Most fraudulent invoices are caught by one of the first two steps. Almost none are caught by staring harder at the PDF.
The ten-point check
If you want the short version, this is it. Points 1 to 3 catch almost everything; the rest are worth a minute each on an invoice that is large, unfamiliar, or different from last time.
- Is there an order? Match the invoice to a purchase order, a delivery, or a person who says they asked for it. No order, no payment, whatever the paperwork looks like.
- Have the bank details changed since last time? Compare against the previous invoice, not against the email you are holding.
- Did you phone them on a number you already had? Required for any change of account. Not the number on the invoice, not the one in the signature.
- Is the VAT number registered, and to whom? A registered number proves a registration exists — not that the sender owns it.
- Does the registry name match the invoice name? Trading names and group companies explain most mismatches; ask about the ones they do not.
- Does the IBAN pass its checksum, and is it issued where you would expect? The checksum catches typos essentially always and tells you nothing about the owner.
- Does the sending domain authenticate its own mail, and how old is it? A domain registered three weeks ago is a different proposition from a twenty-year-old one.
- Does the name resemble a sanctions listing? A similarity is a prompt to look properly, never a determination.
- Are the required particulars there, and does the arithmetic work? Invoice number, date, supplier name, address, VAT number, description, net, rate, VAT amount.
- Is the supplier still a going concern? A company in liquidation keeps a working VAT number and a working bank account, often for months.
Points 4 to 8 are the ones a computer does better than a person, and the invoice checker runs all five at once: drop the PDF in and the VAT number, bank account and email domain are read off it in your browser — the file itself is never uploaded — then checked in one pass.
1. Did anyone actually order this?
Before checking whether the company exists, check whether the purchase exists. Match the invoice to a purchase order, a delivery, or a person in your organisation who can say “yes, I asked for that.”
This single step catches the largest category of fake invoices, which are not sophisticated at all: plausible-looking bills for office supplies, directory listings, domain renewals or “compliance registrations”, sent in volume to businesses in the hope that one gets paid without anyone asking. They rely entirely on nobody checking whether there was ever an order.
Directory and registration invoices deserve special mention. They are often technically worded as an offer rather than a bill — the small print says so — and are designed to be mistaken for a renewal of something you already have.
2. Is this a change from what you did before?
If you have paid this supplier previously, compare against the last invoice:
- Same bank account?
- Same legal entity and VAT number?
- Same sending address and domain?
- Amount and terms in the normal range?
A change in bank details is the one that matters most, and it has its own guide: a supplier emailed asking to change their bank details.
3. Check the identity claims
These are the parts a computer can verify, and you can run all of them at once on the homepage. If the invoice is in front of you as a PDF, the invoice checker reads the VAT number, bank account and sending domain off it in your browser and runs the same checks, so there is nothing to retype. Each answers a narrow question:
- VAT number. Is it currently registered, and to whom? A valid number proves the registration exists; it does not prove the sender owns it, since VAT numbers are public. See valid VAT number, different name.
- IBAN. Is it correctly formed, and issued in the country you would expect? The checksum catches typos essentially always. It says nothing about who owns the account — no public source can. See IBAN country differs from VAT country.
- Sanctions screening. Does the name resemble an entry on the EU consolidated list? A similarity, not a determination. See what a possible match means.
- Sending domain. Does it authenticate its own email, and how old is it? A domain registered three weeks ago that publishes no DMARC policy is a different proposition from one that has existed for a decade. See no DMARC policy.
4. Read the document itself
Worth a look, but weak evidence in both directions — a competent forgery gets all of this right, and legitimate small businesses get plenty of it wrong.
- Required particulars. An EU or UK VAT invoice must carry an invoice number, date, the supplier’s name, address and VAT number, a description, the net amount, VAT rate and VAT amount. Missing several of these on a large invoice is a reason to query it.
- Arithmetic. Does the VAT actually equal the stated rate applied to the net?
- Consistency. Does the VAT number’s country prefix match the address? Does the currency match the country? Is the invoice number plausible against previous ones?
- The bank details block. Look for signs it was edited separately from the rest — different font, alignment or spacing.
5. Pick up the phone
For anything material, and for every change of bank details, call the supplier on a number you already had — from an earlier invoice, your accounting system, or their website navigated to yourself. Never the number on the invoice or in the email.
This is the step that catches the fraud that passes every other test: a real supplier, a real VAT number, a real domain, a real invoice, and someone else’s bank account.
Three invoices, and what gave them away
All three are composites of the patterns that actually turn up, with invented details. What matters is the shape of each one, and which step above catches it.
1. The renewal that was never a subscription
“Domain listing renewal — EUR 987, payable within 7 days.” Addressed to the company by its correct registered name and address. Carries a real-looking reference number. In smaller type near the foot: this is an offer, not an invoice.
What was true: the sender existed and was VAT-registered. The name and address were correct because both are public. Nothing was forged.
What caught it: point 1. There was no order. Every identity check on it passes, because there is nothing wrong with the sender’s identity — only with the assumption that a document arriving in the payables tray represents something somebody bought.
2. The genuine supplier with someone else’s account
A real invoice from a supplier of two years’ standing, on the same email thread as the last four, same PO number, same layout, same signature. One field differs from the previous invoice: the IBAN. The covering note apologises for the change and mentions an audit.
What was true: almost all of it. The mailbox had been compromised weeks earlier. The domain was genuine, so SPF and DKIM passed. The VAT number was genuine. The IBAN was well-formed and belonged to a real, recently opened account.
What caught it: points 2 and 3, and nothing else could have. This is the case the whole site is built around — see a supplier emailed asking to change their bank details.
3. The company that had stopped trading
An ordinary invoice for consultancy, from a company whose VAT number resolves cleanly in VIES, whose name matches the registry exactly, and whose IBAN is in the same country.
What was true: every check passed, because every check was asking about the registration. The company had entered liquidation four months earlier. The VAT number was still live — deregistration and insolvency are separate processes on separate timetables — and the account was still open, now controlled by an insolvency estate.
What caught it: point 10, which is the national company register rather than VIES. VIES answers whether a number is registered and nothing else; the register answers what state the company is in. See what a company in liquidation means for your payment.
What none of this can tell you
It is worth being clear about the boundary, because tools that blur it are how people end up over-trusting a green tick:
- Who owns a bank account. Not public in the EU or UK. There is no lookup.
- Whether the goods or services were delivered. Only your own records answer that.
- Whether the company is solvent, or intends to deliver. A registered company with clean records can still be a bad counterparty.
- Whether the person emailing you is who they claim to be. Email authentication proves a message came from a domain. It cannot prove who was sitting at the keyboard, which is precisely why a compromised mailbox defeats it.
This is also why the tool on this site returns independent results per check and never a single “safe to pay” verdict. Each check answers its own narrow question honestly. Combining them into one number would imply an assurance that none of them, together or apart, can give.
Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.
Invoice Checker →Drop in a supplier’s invoice, or paste its text, and the VAT numbers, bank accounts and email domains on it are read out in your browser — the file itself is never uploaded. Correct anything misread, then run every check at once.