You appear to be offline. Lookups will resume automatically when your connection returns.
Free · No sign-up · Works offline-safe

Verify a bank branch before you send money

Enter any eleven-character IFSC code to confirm the bank, branch, address, MICR code and which payment rails that branch supports. A five-second check that can prevent a loss you may never recover.

IFSC verification

Verified this session: 0
  1. 1 Format checked
  2. 2 Branch found
  3. 3 Confirmed with payee

Stop and verify: do not let greed or fear rush a critical transaction.

0/11
Try one:

Understand the code

What an IFSC code actually tells you

Eleven characters, three meaningful parts. Once you can read them, a wrong code becomes obvious before you ever press send.

Characters 1–4 · the bankAlways letters. SBIN is State Bank of India, HDFC is HDFC Bank, UTIB is Axis Bank. If these four letters do not match the bank your payee named, stop immediately.

Character 5 · always zeroThe Reserve Bank keeps this position reserved for future use. It is the digit zero, never the letter O. This single position is where most hand-typed codes fail.

Characters 6–11 · the branchLetters or digits identifying one specific branch out of roughly one hundred and sixty thousand across India. This is the part that decides where your money lands.

IFSC, MICR and SWIFT are not interchangeable

Comparison of IFSC, MICR and SWIFT codes
CodeFormat Used forWhere to find it
IFSC11 characters, letters and digitsDomestic NEFT, RTGS and IMPS transfersCheque leaf, passbook, net banking
MICR9 digits, numeric onlyCheque clearing between banksPrinted in magnetic ink at the foot of a cheque
SWIFT / BIC8 or 11 charactersInternational inbound and outbound remittanceYour bank's international banking page or branch

Why this matters: a relative abroad who asks for "your bank code" needs the SWIFT code, not the IFSC. Sending an IFSC for an inbound international wire is one of the most common reasons a remittance is returned days later, usually after a deduction.

Quick reference

Bank prefixes at a glance

The first four characters of every IFSC identify the bank. Check them against this list before you trust a code someone sent you over chat.

Indian banks and their IFSC prefix codes
BankIFSC prefix SectorAction

Merged banks: customers of Dena Bank and Vijaya Bank (now Bank of Baroda), Oriental Bank of Commerce and United Bank of India (now Punjab National Bank), Syndicate Bank (now Canara Bank), Andhra Bank and Corporation Bank (now Union Bank of India) and Allahabad Bank (now Indian Bank) were all issued new IFSC codes. An old cheque book may print a code that no longer routes.

Financial awareness

Safe banking, explained properly

Almost no banking fraud in India breaks into an account. It persuades the account holder to open the door. Understanding the mechanics of that persuasion is what makes you difficult to defraud.

How an OTP fraud is actually built

An OTP fraud is not a technical attack. It is a three-stage social one, and each stage has a job. The first stage is the pretext: a reason for the call or message that sounds administrative and boring rather than alarming. Your card is due for renewal. Your account will be credited with a refund. Your reward points expire tonight. Boring is deliberate, because a dramatic story invites scrutiny and a dull one does not.

The second stage is manufactured credibility. The caller opens with something they already know — your full name, the last four digits of your card, the branch you bank with, sometimes a recent merchant you paid. None of this is secret. It leaks from breached merchant databases, delivery labels, loan enquiry forms and social media. But hearing a stranger recite it produces a powerful and false conclusion: only my bank could know this. In reality, knowing your name and card suffix proves nothing at all, because those are precisely the details that leak most often.

The third stage is time pressure, and it is the one that actually does the damage. You are told the window is closing — the card will be blocked in ten minutes, the refund lapses at midnight, the offer ends with this call. Compressed time suppresses deliberation. You stop asking whether the story makes sense and start trying to finish the task. That is the exact moment the six digits are requested, and the only thing the fraudster ever needed. They do not have your password. They do not need it. Your OTP completes a transaction they have already set up and are waiting on.

The rule that survives every variation: an OTP is not a verification of your identity to a bank. It is your authorisation of a transaction. If you did not start a transaction in the last sixty seconds, there is nothing legitimate for an OTP to authorise. Read the SMS itself — it names the amount and the merchant. If you did not intend that amount, the call is a fraud, no matter who the caller claims to be.

Phishing vectors: the four doors they knock on

The first door is SMS. A message arrives warning that your KYC has expired, your account is suspended, or your electricity connection will be cut tonight, with a shortened link. The link opens a page that looks like your bank, sometimes pixel-accurate, and asks you to log in. The tell is always the address bar, never the design. Look at the domain immediately before the first single slash: a real bank domain is short and ends in a way you recognise, while a phishing domain buries the bank's name in a subdomain or a hyphenated string. Banks do not conduct KYC through links sent by SMS.

The second door is voice, and it is the most effective, because a human voice adapts to your hesitation in real time. Caller ID means nothing — spoofing a number is trivial and free. The dangerous escalation is when the caller asks you to install an application so they can 'help' you. Any screen-sharing or remote-support app hands over your live screen, and on many phones your incoming SMS, which means every OTP you receive from that moment. No bank employee will ever ask you to install anything during a call.

The third door is search. Fraudsters buy advertisements and seed business listings so that a fake customer-care number ranks above the real one. You call it yourself, which removes all your natural suspicion, because you initiated contact. The fourth door is the app store: applications that clone a bank's name and icon closely enough to pass a quick glance. Take helpline numbers from the back of your debit card, your passbook, or the bank's own app — never from a search result — and install banking apps only by following a link from the bank's official website.

One habit closes all four doors: never continue on the channel that contacted you. If a message, call or search result raises a concern, stop, and re-establish contact yourself through a number or app you already had. A genuine issue will still be there when you call back. A fraud will not survive the switch.

The UPI collect-request trap

UPI has one rule that is worth understanding completely, because nearly every UPI fraud depends on people not knowing it. Your UPI PIN authorises money leaving your account. It is never required for money entering it. Receiving is passive: if someone sends you money, it simply arrives, with no action from you at all. So any instruction that involves entering your PIN 'to receive' something is, without exception, an instruction to pay.

The mechanism abused was the collect request — a feature that let someone ask you to pay. It appears as a notification with an amount and a note, and the note is attacker-controlled text, so it can read 'Refund for cancelled order' or 'Prize credit' while actually being a debit request. Approving it and entering your PIN sends the money out. NPCI switched off person-to-person collect requests on 1 October 2025, which removed the commonest version of this trap, but merchant payment requests, payment links and fake merchant handles still exist, and fraudsters have moved to them. The typical settings are unchanged: marketplace sales, where a 'buyer' asks you to approve something to receive payment for the item you listed, and refund scams after a fake order cancellation.

Scanning a QR code works the same way. A QR code encodes a destination for payment. It cannot pull money toward you. If anyone asks you to scan a code, or to enter a PIN after scanning, in order to receive a payment, the transaction is running in the opposite direction to the one you have been told. Read the confirmation screen before authorising: it always states plainly whether you are paying or being paid, and it is the last honest thing you will see.

Memorise this and you are immune to the entire category: no PIN is ever needed to receive money. Not on UPI, not on any Indian payment app, not once.

Building a verification loop you actually follow

Under pressure, intentions fail and habits hold. A verification loop is a short fixed sequence you run every time you pay someone new, so that you are not relying on being alert on the day it matters. Four checks are enough. Confirm the IFSC resolves to the branch your payee named. Confirm the account number character by character from a source your payee sent you directly, not from a forwarded message. Confirm the beneficiary name your banking app displays after you add the payee. And confirm the amount by reading it aloud before you authorise.

The third check carries most of the weight and is skipped most often. When you add a beneficiary, your bank fetches and displays the name registered on that account. If it does not match the person you believe you are paying, stop, whatever the explanation offered. 'That is my brother's account', 'the company account is in the accountant's name', 'the name will update later' — these are the sentences that appear in almost every account-takeover and impersonation complaint. A mismatch is not a formality. It is the system telling you that the money is going somewhere other than where you think.

For a first payment of significant size, send a small test amount, then confirm receipt by voice with the payee on a number you already had — not one supplied in the same conversation that requested the payment. Keep a screenshot of the confirmation with its reference number. If something later goes wrong, that reference is what turns a vague complaint into a traceable one, and speed of tracing is what determines whether funds can still be frozen.

The loop only works if it is unconditional. The moment you allow yourself to skip it because the request is urgent, you have handed the decision to whoever created the urgency — and urgency is manufactured far more often than it is real.

If it has already happened: the first twenty-four hours

Speed is the single largest factor in whether money is recovered, because a fraudster's objective after receiving funds is to move them through several accounts quickly. Reporting early can allow the receiving account to be frozen before that happens. Under the Reserve Bank's customer-protection framework on limited liability, a customer who reports an unauthorised electronic transaction to their bank within three working days generally bears no loss. Delay shifts the liability toward the customer. Do not wait to understand what happened. Report first, understand afterwards.

Do three things in parallel. Call the National Cyber Crime Helpline on 1930 and register the incident. File the complaint at cybercrime.gov.in, which routes it to the relevant bank and police jurisdiction. Inform your own bank in writing, by email or through the app's complaint channel, and insist on a written acknowledgement with a complaint reference number. A verbal report to a call centre is not a record you can rely on later.

Gather your evidence while it is fresh: the transaction reference or UTR number, the exact date and time, the amount, the beneficiary account and IFSC if you have them, screenshots of any messages or calls, and the number that contacted you. Block the affected card or freeze the account. If your bank does not reply within thirty days, or you are dissatisfied with its reply, you can escalate to the RBI Ombudsman under the Integrated Ombudsman Scheme, 2026 — at cms.rbi.org.in or on 14448 — within ninety days. Your written acknowledgement is what makes that escalation possible.

Report on the same day, even if you are unsure. Withdrawing a complaint later is trivial. Recovering money that has already been layered through three accounts is often impossible.

There is an old idea in Indian philosophy called viveka — the practised ability to tell what is real from what merely appears real. Fraud is engineered precisely against that faculty: it manufactures an appearance of authority, of urgency, of good fortune, and it works only in the small gap where you act before you look. The pause in which you verify is not friction, and it is not distrust of the person in front of you. It is the whole of your protection. Greed narrows that pause, and fear closes it entirely, which is why every fraud script is built to trigger one or the other.

On viveka — discernment between the real and the apparent

Questions

Frequently asked questions

What is an IFSC code and what is it used for?

IFSC stands for Indian Financial System Code. It is an eleven-character code issued by the Reserve Bank of India that uniquely identifies one individual bank branch within the national payments network.

NEFT, RTGS and IMPS all use it to route a payment instruction to the correct destination. Without a valid IFSC, the payment system has no way of knowing which of roughly one hundred and sixty thousand branches across India your transfer is meant for.

How is an IFSC code structured?

An IFSC has three parts. The first four characters are always letters and identify the bank — SBIN for State Bank of India, UTIB for Axis Bank. The fifth character is always the digit zero, reserved by the Reserve Bank for future use. The final six characters are letters or digits identifying the specific branch.

Any code that does not follow this four-letter, zero, six-character pattern is not a valid IFSC, which is why this tool checks the shape before it checks the database.

What is the difference between IFSC, MICR and SWIFT codes?

IFSC is an eleven-character code used to route domestic electronic transfers within India. MICR is a nine-digit numeric code printed in magnetic ink at the bottom of a cheque, used by the cheque clearing system. SWIFT, also called a BIC, is an eight or eleven character international code used to route payments between banks in different countries.

One branch can hold all three. They are not interchangeable, and using the wrong one is a common cause of failed or returned transfers.

What happens if I transfer money using the wrong IFSC code?

If the IFSC does not exist, the payment is rejected and the amount is normally credited back to your account within one to two working days. If the IFSC is valid but belongs to a different branch of the same bank, the transfer will usually still succeed, because the account number is what identifies the account.

The genuinely dangerous case is a valid IFSC combined with a valid account number that belongs to someone else — the money reaches a real stranger. Inform your bank in writing immediately if that happens, because recovery then depends on the receiver's consent.

Did IFSC codes change after the Indian bank mergers?

Yes, for a large number of customers. Dena Bank and Vijaya Bank merged into Bank of Baroda; Oriental Bank of Commerce and United Bank of India into Punjab National Bank; Syndicate Bank into Canara Bank; Andhra Bank and Corporation Bank into Union Bank of India; and Allahabad Bank into Indian Bank.

Each surviving bank issued fresh IFSC codes and retired the old ones. An old cheque book from a merged bank may print a code that no longer routes, so verify before relying on printed stationery.

Is it safe to enter my IFSC code on this website?

Yes. An IFSC code is public information — it identifies a branch, not a person. It is printed on every cheque leaf and published by the Reserve Bank, and it reveals nothing about you or your balance.

What you should never enter on any website is your account number together with your card number, CVV, PIN, OTP or net banking password. This site asks for none of those and has no server that could store them even if you typed them.

How do I recover money sent to the wrong account?

Inform your bank in writing on the same day, quoting the transaction reference number, date, amount and destination. Your bank will approach the beneficiary bank on your behalf.

If the money reached a real but unintended account holder, it can only be reversed with that person's written consent, because a bank cannot debit a customer's account unilaterally. If consent is refused, the remaining route is civil recovery — which is precisely why verifying the branch beforehand matters far more than any remedy afterwards.

Should I use NEFT, RTGS or IMPS?

NEFT settles in batches, runs around the clock, has no minimum amount and suits ordinary transfers. RTGS settles individually in real time, has a minimum of two lakh rupees and suits high-value transfers where immediate finality matters. IMPS is instant and available at all hours including holidays, and is generally used for smaller amounts.

All three require a correct IFSC. The choice affects speed and cost, never the need to verify the destination.

Awareness library

In-depth guides to protecting your money

Long-form, independently researched explainers on how fraud works, how India's payment routing works, and how to keep a clear head when money is on the line. Every guide is available in full in English, Bengali and Hindi.

The Anatomy of Modern Cyber Scams: Protecting Your Digital Wealth

Modern fraud rarely hacks a bank. It hacks a person — with a script, a deadline and a borrowed uniform. How digital arrest hoaxes, phishing links and reverse-charge payment traps actually work, step by step, and the exact moment each one can be stopped.

By the IFSCTool.in editorial desk

Why modern fraud targets people, not systems

India's payment systems are heavily defended. UPI apps are bound to your SIM and device, banks demand two-factor authentication, and every transfer passes through fraud-monitoring engines run by the banks and by the National Payments Corporation of India. Breaking those defences is slow and expensive. Persuading a human being to move their own money is fast and cheap.

That is why almost every large loss today is an authorised payment: the victim entered the PIN or read out the OTP themselves, believing they had a good reason to. Every scam in this guide follows the same three-act structure — a hook that creates a problem or an opportunity, pressure that removes your time to think, and an extraction step in which you move money or hand over a credential. Once you can see that structure, the costume the fraudster wears stops mattering.

Scam one: the "digital arrest" hoax

Digital arrest is the most frightening fraud in circulation because it impersonates the state itself. It typically unfolds in four stages:

  1. The hook. A call — often opened by a recorded voice menu — claims that a parcel in your name has been seized containing drugs, fake passports or contraband, or that your Aadhaar or mobile number has been linked to money laundering. The caller says they are from a courier company, customs, the telecom regulator, the police, the CBI or the Enforcement Directorate.
  2. The escalation. You are transferred to a "senior officer" on a video call. The background is dressed as a police station, the person wears a uniform, and you may be shown a forged arrest warrant or a letter carrying an agency's logo and seal.
  3. The confinement. You are told you are now under "digital arrest". You must stay on camera, alone in a closed room, and tell no one — not your family, not your bank — because the investigation is "confidential". Victims have been held on video like this for hours, sometimes days.
  4. The extraction. To "prove your innocence" or have your money "verified", you are told to transfer funds to a "secure government account", break fixed deposits, or take an instant loan. You are promised everything will be refunded once verification is complete. It never is.

One fact dismantles the entire script: there is no such thing as a digital arrest under Indian law. The Indian Cyber Crime Coordination Centre (I4C) has put it plainly — the CBI, police, customs, the ED and judges do not arrest anyone on a video call. No genuine agency will ask you to keep a call secret from your family, and none will ask you to transfer money to "verify" it.

Scam two: phishing links and lookalike addresses

Phishing moves you from a message to a counterfeit page that harvests what you type. The message claims your KYC has expired, your account will be frozen tonight, your electricity will be disconnected, your reward points are about to lapse, or a parcel is waiting for a small redelivery fee. The link opens a page that looks exactly like your bank. Every keystroke is relayed to the fraudster, who logs into your real account at the same moment — which is why the page so often asks you to "confirm" the OTP that has just arrived.

The design of a fake page can be perfect. The address almost never is. Learn to read it the way a bank's security team does:

  • Only one part of an address is the real website. It is the name immediately before the first single forward slash. In examplebank.bank.in/login, the site is examplebank.bank.in. In examplebank.bank.in.kyc-update.top/login, the site is actually kyc-update.top — the bank's name has simply been placed at the front as decoration.
  • Lookalike spellings. A digit 1 in place of a letter l, an extra letter, two letters swapped, or a hyphen added to a familiar name: examp1ebank-kyc.com is not your bank.
  • Shortened links and throwaway endings. Banks do not send KYC or account-blocking notices through link shorteners, and they do not operate from domains ending in .top, .xyz or .live.
  • Anything that asks you to install an APK file. A genuine banking app comes from the Google Play Store or Apple's App Store. An app file sent over WhatsApp or SMS can read your messages and capture every OTP.

India now has a structural defence worth knowing. The Reserve Bank of India directed banks to move their websites to the exclusive .bank.in domain, which only regulated banks can register, through the Institute for Development and Research in Banking Technology (IDRBT), with a migration deadline of 31 October 2025. An Indian bank's genuine website should now end in .bank.in, and a separate .fin.in domain has been planned for other financial entities. Treat this as a strong signal, not a guarantee — the safest habit of all is to type the address yourself or open the bank's official app, and never to follow a link to reach your bank.

Scam three: reverse-charge payment traps

These frauds reverse your instinct about which way money is moving. The victim believes they are about to receive money — a refund, a buyer's payment for something listed online, a cashback prize — and is walked through steps that actually send it.

  • "Scan this to receive your payment." A "buyer" on a marketplace sends a QR code. Scanning a QR code and entering your UPI PIN always pays the other side; a QR code cannot pull money towards you.
  • "Enter your PIN to accept the refund." A payment request appears in your UPI app with a note reading "Refund" or "Prize credit". The note is text the fraudster typed. The National Payments Corporation of India discontinued person-to-person collect requests on UPI from 1 October 2025, which removed the most common form of this trap — but merchant payment requests, payment links and fake merchant handles still exist, and fraudsters have moved to them.
  • The "extra payment" story. Someone says they sent ₹20,000 instead of ₹2,000 by mistake and asks you to return the difference, often with a forged screenshot or a fake SMS as "proof". Always open your own bank app and check your actual balance before believing any screenshot.
  • Remote-access "help". A fake customer-care agent asks you to install a screen-sharing app "to process your refund", then simply watches your OTPs arrive on your own screen.

The engine inside every scam: a manufactured deadline

Look back at each fraud above and you will find a clock. The arrest is happening now. The account will be blocked tonight. The refund expires in ten minutes. The buyer is waiting. Urgency is not decoration — it is the mechanism. A person with an hour to think, to call a relative, or to open their bank's own app will almost always see through the story, so every script is engineered to make sure you never get that hour.

That makes delay your most powerful defence. No legitimate bank, courier, regulator or police force will penalise you for ending a call, finding their official number yourself, and calling back tomorrow.

Hardening your digital wealth: a practical checklist

  • Keep SMS and email alerts switched on for every debit, however small — and actually read them. Fraudsters often test an account with a tiny debit first.
  • Set sensible daily limits for UPI, card and net-banking transfers inside your bank's app, and lower them for channels you rarely use.
  • Switch off online, international and contactless card use when you are not using them; most bank apps let you toggle these instantly.
  • Use a strong, unique password for net banking and the email address linked to it, and never reuse it on shopping or social sites.
  • Never install an app, or share your screen, because someone on a call asked you to.
  • Keep your current mobile number and email registered with every bank and wallet you use, so that alerts reach you and not an old SIM.
  • Report suspicious calls and messages through the Chakshu facility on the government's Sanchar Saathi portal at sancharsaathi.gov.in, even when you lost nothing. Every report helps disconnect numbers used for fraud.

If money has already left your account

  1. Call 1930 immediately and file a complaint at cybercrime.gov.in. The first hours matter most: the reporting system alerts banks along the chain and can freeze money while it is still sitting in the first "mule" accounts.
  2. Call your bank on the number printed on your card or shown in its official app. Block cards, UPI and net banking, report the transaction as fraud, and note the complaint reference number.
  3. Follow up in writing by email or through the app's complaint section, and keep every acknowledgement, screenshot, transaction ID and phone number involved.
  4. Know the timelines that apply to you. Under the RBI's current rules, if an unauthorised electronic transaction was caused by a third-party breach and you report it within three working days, your liability is generally zero, and the bank must credit the disputed amount within ten working days while it investigates. If you shared an OTP or authorised the payment yourself, today's rules treat the loss as yours up to the moment you report it — so report instantly. From 1 January 2027, RBI's revised framework asks customers to report within five calendar days to both their bank and 1930 or the National Cyber Crime Reporting Portal, and introduces a one-time compensation for eligible small-value frauds, including those where the victim was tricked into authorising the payment: 85% of the net loss, up to ₹25,000, for losses of up to ₹50,000.
  5. Escalate if your bank does not resolve it. If there is no reply within 30 days, or the reply does not satisfy you, complain to the RBI Ombudsman at cms.rbi.org.in or on the toll-free number 14448. Under the Integrated Ombudsman Scheme, 2026, you must do this within 90 days. Filing is free.

Fraudsters are organised, patient and well rehearsed. But every script shares the same weakness: it only works on someone who is rushed and alone. Slow down, bring in one person you trust, and verify through a channel you chose yourself — and the script collapses.

Decoding Banking Identifiers: The Strategic Role of IFSC, MICR, and SWIFT Codes

Every rupee that moves between Indian banks follows a route written in code. What IFSC, MICR and SWIFT codes each identify, how the RBI and NPCI secure the clearing route, and exactly what to do, step by step, if a transfer lands in the wrong account.

By the IFSCTool.in editorial desk

Why money needs an address

When you send money from one bank to another, the two banks do not talk to each other directly. The instruction travels through central infrastructure: for most rupee transfers, systems operated by the Reserve Bank of India (NEFT and RTGS) or by the National Payments Corporation of India (IMPS and UPI). Every instruction needs an unambiguous destination, just as a letter needs a PIN code. Banking identifiers are those destinations.

Keep one principle in mind throughout this guide, because it explains almost everything that can go right or wrong: the routing code finds the bank and branch; the account number finds the person. A code can be perfectly valid while the account number beside it belongs to a complete stranger.

IFSC: the address for electronic transfers

The Indian Financial System Code is an eleven-character alphanumeric code that the RBI uses to identify every bank branch taking part in electronic fund transfers. It has three parts:

  • Characters 1–4 identify the bank. SBIN is State Bank of India, HDFC is HDFC Bank, and UTIB is Axis Bank — a reminder of its original name, UTI Bank.
  • Character 5 is always the digit zero, reserved by the RBI for future use. It is never the letter O.
  • Characters 6–11 identify the branch. They are often digits but can include letters.

The IFSC is what three of India's main payment rails use to route money:

  • NEFT (National Electronic Funds Transfer) settles in half-hourly batches, has run around the clock since December 2019, and has no minimum amount.
  • RTGS (Real Time Gross Settlement) settles each payment individually and immediately. It is designed for large payments, with a minimum of ₹2 lakh, and has operated 24×7 since December 2020.
  • IMPS (Immediate Payment Service), run by NPCI, credits the beneficiary instantly at any hour.

UPI hides all of this behind a simple virtual payment address such as a phone number or handle — but underneath, the money still lands in a bank account held at a specific branch.

MICR: the address printed on your cheque

MICR stands for Magnetic Ink Character Recognition. It is the nine-digit number printed in special magnetic ink along the bottom edge of a cheque, where machines can read it reliably even if the paper has been stamped, folded or signed over. It is read in three blocks of three digits:

  • Digits 1–3: the city, which usually matches the first three digits of that city's PIN codes.
  • Digits 4–6: the bank.
  • Digits 7–9: the branch.

For example, 700002021 decodes as 700 (Kolkata), 002 (State Bank of India) and 021 (the specific branch). You can see this for yourself by verifying SBIN0000001 in the IFSC finder at the top of this page.

MICR drives cheque clearing through the Cheque Truncation System (CTS), in which the paper cheque stays with the bank where it was deposited and only its image and MICR data travel electronically. Since October 2025, CTS has been moving from fixed batches to continuous clearing, so a cheque is typically cleared on the same day it is presented.

CTS also carries a safeguard many people never use: the Positive Pay System. For cheques of ₹50,000 and above, you can pre-register the key details — date, amount, payee name and cheque number — with your bank through its app, net banking or branch. When the cheque is presented, those details are checked against what you registered, which makes an altered or stolen cheque far harder to clear. Banks may make Positive Pay mandatory for cheques of ₹5 lakh and above.

SWIFT and BIC: the address for money that crosses borders

IFSC and MICR work only inside India. International transfers use SWIFT codes, formally known as Business Identifier Codes (BICs) under the international ISO 9362 standard. A BIC has either eight or eleven characters:

  • 4 letters for the bank;
  • 2 letters for the country — IN for India;
  • 2 characters for the location;
  • an optional 3-character branch code, where XXX or no branch code usually means the head office.

Not every Indian branch handles foreign currency directly, which is why many branches show no SWIFT code in an IFSC lookup; inward remittances are often routed through a designated branch or an intermediary bank. If you are expecting money from abroad, ask your own bank for the exact SWIFT code, and any intermediary bank details, it wants senders to use. Do not rely on a code copied from a search result, and never give an IFSC to a sender abroad when they ask for your "bank code".

How the system keeps the route secure

Several independent layers work together so that money reaches the account it was meant for:

  • Regulated participants only. NEFT and RTGS are operated by the RBI, and only banks and entities the RBI has authorised can send or receive instructions on them. Messages travel over dedicated, secured financial networks rather than the open internet.
  • Beneficiary name look-up. Since 1 April 2025, the RBI has required banks to let you see the name registered to the destination account before you complete an RTGS or NEFT transfer — in internet banking, mobile banking and at the branch — free of charge. The name is fetched from the destination bank's own core banking records, so the person asking you for money cannot edit it.
  • Name display on UPI. UPI apps show the registered name of the person or merchant before you enter your PIN.
  • Positive Pay for high-value cheques, as described above.
  • Mule-account detection. Banks and the RBI increasingly use analytics and AI tools, such as the RBI's MuleHunter.AI, to identify accounts that are rented or stolen to receive fraud proceeds.
  • Verified bank domains. Indian banks' official websites have moved to the exclusive .bank.in domain, which makes counterfeit banking sites easier to spot.

Every one of those layers, however, depends on the last one: you reading the name on the screen before you approve.

What actually happens when a code or account number is wrong

Three situations, three very different outcomes:

  • Wrong branch, correct account, same bank. The transfer usually succeeds. Most Indian banks run centralised core banking systems that locate an account by its number, so the branch named in the IFSC matters less than it once did.
  • An IFSC or account number that does not exist. The transfer fails and the money returns to your account, typically within a few hours to a couple of working days depending on the rail.
  • A valid account number that belongs to someone else. This is the dangerous case. The money is credited to a real account holder, and a bank cannot take money back out of a customer's account without that customer's consent or a legal order.

That third case is exactly why the beneficiary name check exists. Read it every single time.

Step by step: recovering money sent to the wrong account

  1. Act within minutes, not days. Call your bank on the number printed on your card or shown in its official app, or visit your branch. Give the transaction reference — the UTR number for NEFT and RTGS, or the RRN for IMPS and UPI — along with the date, amount and the account number and IFSC you sent to. Ask the bank to raise a request for recovery of a wrong credit with the beneficiary's bank.
  2. Put it in writing the same day. Send an email or written complaint to your home branch or through the bank's grievance portal, and keep the acknowledgement and complaint number. Every later step relies on this written record.
  3. Let the banks talk to each other. Your bank contacts the beneficiary's bank, which contacts its customer and asks for consent to return the money. Most unintended recipients agree when approached formally by their own bank.
  4. If the recipient refuses or cannot be reached, recovery becomes a legal matter: file a police complaint with your transaction evidence, and seek legal advice about a civil claim for recovery. Keep every document.
  5. Escalate if your bank does not act. If your bank does not reply within 30 days, or you are dissatisfied with its reply, you can complain to the RBI Ombudsman under the Reserve Bank – Integrated Ombudsman Scheme, 2026, which has applied since 1 July 2026. File at cms.rbi.org.in, by email to crpc@rbi.org.in, or by calling the toll-free number 14448, within 90 days of the bank's reply or of the 30-day window expiring. There is no fee.

A thirty-second routine before every new transfer

  • Copy the account number and IFSC from something the beneficiary gave you directly — a cancelled cheque, a passbook page, or a message from their own number. Never retype them from memory.
  • Verify the IFSC and confirm that the bank and branch match what the beneficiary told you.
  • Read the beneficiary name your bank displays before you confirm. If it does not match, stop, whatever explanation you are offered.
  • For a first payment to someone new, send a small test amount and confirm it arrived.
  • For a large payment, confirm the bank details by calling the beneficiary on a number you already had — not one supplied in the same email or message as the bank details. Fraudsters routinely intercept emails and alter the account details on genuine invoices.

Banking identifiers are not bureaucratic clutter. They are the addressing system that lets hundreds of millions of payments a day find the right home. Understanding them turns a moment of doubt into a thirty-second check — and turns a potential loss into a non-event.

The Psychology of Financial Fear and Greed: Becoming a Conscious Digital Citizen

Scams do not defeat your intelligence; they bypass it, by triggering the two oldest impulses we have. What the Bhagavad Gita and the Upanishads observed about fear, greed and discernment — and a practical checklist for pausing before any money moves.

By the IFSCTool.in editorial desk

Why intelligent people get scammed

The victims of financial fraud in India include doctors, engineers, senior officials, teachers and people who have spent their careers in banking. Intelligence does not protect them, because a modern scam is not a puzzle to be solved. It is an emotional event designed to be experienced.

Under a sudden threat — "you are under investigation" — or a sudden windfall — "you have won ₹25 lakh" — the mind shifts into a narrow, urgent mode. Attention tunnels onto the immediate problem, and the slower, reflective thinking we rely on for good decisions is pushed aside. Fraudsters do not need you to be foolish. They only need you to be rushed.

The four levers every script pulls

Scam scripts are built to keep you in that narrowed state. Almost all of them combine four levers:

  • Urgency — act in the next ten minutes, or lose everything.
  • Authority — a uniform, a logo, an official-sounding title, a case number.
  • Isolation — "do not tell anyone; this is confidential".
  • Reward or threat — a prize you must claim, or a penalty you must avoid.

Each lever on its own is weak. Pulled together, they can overwhelm anyone who has not prepared in advance. The good news is that preparation works — and one of the oldest descriptions of how it works comes from India's own philosophical tradition.

What Vedanta observed about the mind under pressure

Long before behavioural psychology had a name, the Vedantic tradition mapped how desire and fear cloud judgement. Its account is strikingly close to what a scammer exploits. In the Bhagavad Gita, Krishna describes a chain reaction:

dhyāyato viṣayān puṁsaḥ saṅgas teṣūpajāyate …
smṛti-bhraṁśād buddhi-nāśo buddhi-nāśāt praṇaśyati

Brooding on an object breeds attachment; attachment breeds desire; desire, when obstructed, breeds anger; anger breeds delusion; delusion clouds memory; and when memory fails, discernment is destroyed — and with it, the person is lost.

Bhagavad Gita 2.62–63

Replace "an object" with "a lottery prize" or "the fear of arrest", and you have a precise description of a victim's afternoon: fixation, rising emotion, confusion, forgetting everything they know about how banks and police actually work, and finally a transfer that makes no sense in hindsight.

The Gita (16.21) also names three "gates" through which a person walks towards self-destruction: kāma (desire), krodha (anger) and lobha (greed). Every financial fraud tries to push you through at least one of them.

The Katha Upanishad (1.2.1–2) offers the classic antidote in its distinction between śreyas, what is truly good, and preyas, what is merely pleasant. Both approach every person, it says; the wise examine them and choose the good, while the unwise grab at the pleasant. A message promising a quick windfall is preyas in its purest form. The pause you take to verify it is śreyas.

Four Vedantic principles for the digital age

  • Viveka — discernment. The capacity to distinguish the real from the merely apparent. In money matters it becomes a habit of one question: "How do I actually know this is true?" — answered only through channels you chose yourself, never through the channel that contacted you.
  • Vairāgya — non-attachment. Not indifference to money, but freedom from being driven by it. A person who is not gripped by the thought of a jackpot cannot be hooked by one.
  • Sākṣī bhāva — witness awareness. The practice of observing your own mind as a calm witness. When you can notice, "my heart is racing and I feel I must act right now", the noticing itself is the brake. The emotion is still there, but it is no longer in charge.
  • Sthitaprajña — steady wisdom. The Gita (2.56) describes the person of steady wisdom as one whose mind is not shaken by sorrow, who does not crave pleasures, and who is free from attachment, fear and anger. It is a remarkably exact description of the one person a fraudster cannot manipulate.

How fear is weaponised

Fear-based scams — "digital arrest", account-blocking warnings, fake legal notices, a caller claiming a family member has been detained — all try to replace your judgement with obedience. They share the same features: they arrive without warning, they invoke authority, they demand secrecy, and they offer exactly one escape route, which always involves paying.

Genuine authority behaves in the opposite way. It gives notice in writing. It allows time. It lets you consult a lawyer or your family. And it never asks you to transfer money to "clear your name" or to "verify" your savings. When a threat can only be resolved by an immediate, secret payment, the threat itself is the fraud.

How greed is weaponised

Greed-based scams — lotteries you never entered, "guaranteed" trading returns, part-time jobs that pay you for liking videos before asking for a deposit, investment groups full of screenshots of other people's profits — all promise gain without effort or risk. Many of them begin by actually paying you a little, because a small real win is the most effective way to switch off suspicion before the large "investment" is requested.

The principle is ancient and simple: when a return is described as guaranteed, high and quick, at least one of those three words is untrue.

The pause-and-verify checklist

Keep this list somewhere you will see it, and share it with parents and grandparents, who are among the most frequently targeted.

  1. Pause. Before any money moves because of a call, message or link, stop. Take three slow breaths and tell yourself: "I have time."
  2. Name the feeling. Am I afraid? Excited? Rushed? Ashamed? A strong emotion around money is a signal to slow down, never to speed up.
  3. Break the isolation. Tell one person you trust what is happening. Any instruction to keep it secret is, by itself, proof of fraud.
  4. Verify through your own channel. End the call. Find the official number on your card, passbook or the organisation's official website — for a bank, an address ending in .bank.in — and contact them yourself.
  5. Check the direction of money. Am I being asked to enter a PIN, scan a code or pay a fee in order to receive something? If yes, it is a scam.
  6. Test the promise or the threat. Is the reward guaranteed, high and quick? Can the danger only be solved by paying immediately? Then neither is real.
  7. Sleep on it. No genuine opportunity and no genuine authority requires your money tonight.
  8. Report it. Even if you lost nothing, report the call or message through Chakshu on sancharsaathi.gov.in or at cybercrime.gov.in. If money has left your account, call 1930 at once.

Becoming a conscious digital citizen

A conscious digital citizen is not someone who never feels fear or desire — that is neither possible nor necessary. It is someone who notices those feelings arrive and does not hand them the steering wheel. That practice protects far more than your own savings. Every scam you recognise, refuse and report is one fewer phone number, one fewer mule account and one fewer rehearsed script available to hurt the next person.

uttiṣṭhata jāgrata prāpya varān nibodhata

Arise, awake, and learn by approaching those who know.

Katha Upanishad 1.3.14

In a world of instant payments, wakefulness is no longer only a spiritual ideal. It is a financial skill — and like any skill, it grows stronger every time you use it.

Facts in these guides were checked against Reserve Bank of India, NPCI and Government of India sources in September 2026. Rules and limits change — confirm the current position with your bank or at rbi.org.in before acting on a specific figure.

Reference

Banking terms in plain language

NEFT
National Electronic Funds Transfer. Settles in batches, available around the clock, with no minimum amount. The default choice for ordinary transfers.
RTGS
Real Time Gross Settlement. Each instruction settles individually and immediately. Minimum two lakh rupees, used where finality matters right away.
IMPS
Immediate Payment Service. Instant transfer available at all hours including public holidays, typically used for smaller amounts.
UPI
Unified Payments Interface. Links bank accounts to an app-based ID. Your UPI PIN authorises money leaving your account and is never needed to receive.
Beneficiary
The person or business receiving the money. Their registered account name is displayed by your bank when you add them — always read it.
MICR
Magnetic Ink Character Recognition. The nine-digit number at the foot of a cheque, used by the cheque clearing system rather than for electronic transfers.
Collect request
A UPI feature that let someone ask you to pay. NPCI switched off person-to-person collect requests on 1 October 2025; merchant requests remain. Approving any request sends money out, whatever its note claims.
Limited liability
The Reserve Bank framework limiting what a customer loses in an unauthorised electronic transaction if it is reported promptly — today, generally within three working days. A revised framework applies to transactions from 1 January 2027, with a five-day reporting window and compensation for eligible small-value frauds.