The display name is not the sender
Every mail client shows a friendly name in large type and the actual address in small type, or not at all. The friendly name is free text chosen by whoever sent the message. It can say your bank, your employer, or your own name, and none of that required anything but typing it.
So the first move is always the same: expand the sender and read the address itself. What matters is the domain — the part to the right of the @ — and specifically its last two labels, for exactly the reason set out in our guide to checking a website.
- A real brand with an extra word: support-yourbank.example rather than yourbank.example.
- The brand as a subdomain of something else, where yourbank.example.mail-secure.example belongs to mail-secure.example.
- A free mail provider for something that would never use one. No bank, tax authority or payroll department sends from a consumer webmail address.
- A near-miss on the spelling, which is the same character-swap trick used on domains.
Check where a reply would go
A message can be sent from one address and quietly set to reply to another. It is a normal feature, used by mailing lists and ticketing systems, and it is also how a convincing invoice fraud works: the mail appears to come from a supplier you know, and your reply goes somewhere else entirely.
Most clients will show the reply-to address if you start a reply and look at the To field before typing. If it does not match the sender, that is worth understanding before you answer, particularly on anything about payment details.
Do not act on the link
The link is the whole delivery mechanism, and inspecting it is a game you do not need to play. Hovering shows a destination, but the visible text, the destination and where it finally lands after a redirect can all be different, and a shortened link shows you nothing at all.
The habit that removes the question: reach anything important the way you already know how. Type the address, use your own bookmark, or open the organisation's app. If the message is genuine, whatever it wants you to see will be waiting for you when you arrive under your own steam.
- A login page reached from an email is the single most common way credentials are taken.
- A QR code in an email is a link you cannot read at all, and it is used precisely because of that.
- An unsubscribe link in a message you never subscribed to confirms your address is live. Mark it as spam instead.
Ask what it is trying to take
Phishing messages vary enormously in their story and hardly at all in what they want. Naming the target is often quicker than assessing the story.
- A credential: a login page for mail, banking, a delivery account or a workplace system.
- A one-time code, asked for by a follow-up call or message. The code authorises something happening at that moment; reading it out is the authorisation.
- A payment: an invoice, a fee, a fine, or changed bank details on an expected transfer.
- An installation: an attachment, a document that asks you to enable content, or a support tool that grants remote access.
- A reply, on its own. Some campaigns only want to establish that a person reads the address before a human takes over.
Attachments, and anything that asks for permission
An unexpected attachment is worth more suspicion than an unexpected link, because the failure is quieter. Documents that ask you to enable editing, enable content or allow macros are asking for permission to run something, and the request is the payload rather than a step towards it.
The same applies to any message that ends with installing software, granting access to a device, or connecting an account to a third-party app you have not heard of.
Check the identifiers against community reports
An email hands you more to check than most approaches do: the sender address, the reply-to address, the domain of any link, and often a payment handle or an amount. Those are all identifiers, and they are worth checking individually rather than as one impression.
Sending addresses are cheap and get burned quickly, so an address with no reports is close to meaningless as reassurance. The domain the link points at, and the account it eventually asks you to pay, are the durable parts and the ones most likely to be on file already.
Frequently asked questions
The email came from the company's real address. Is it safe?
Is it dangerous to open a phishing email?
How can I tell if a login page is fake?
They knew my name, my employer and a recent order. Doesn't that prove it is genuine?
Related guides
- How to Check if a Website Is a ScamSeven checks you can run on a suspicious website in minutes: the real domain, its age, contact details, payment methods, off-site reviews and community reports.
- How to Check a Payment Request Before You Send MoneyWhich payment methods can be reversed and which cannot, why the method itself is the strongest signal, and the checks to run on a handle before you send anything.
- Scam Warning Signs and What They Actually MeanThe eight signals that recur across almost every scam, what each one is doing to you, and why the combination matters far more than any single sign.
The app
Check before you send money
Look up a website, phone number, payment account or crypto wallet against what the community has already reported.
Store links appear here as soon as the app is published in your region.
Scan to Download