Skip to content

Check something

How to Check if an Email Is a Scam

The convincing part of a phishing email is the part you already trust — the name in the From line. It is also the part that costs nothing to fake.

5 min readUpdated 5 steps

The display name is not the sender

Every mail client shows a friendly name in large type and the actual address in small type, or not at all. The friendly name is free text chosen by whoever sent the message. It can say your bank, your employer, or your own name, and none of that required anything but typing it.

So the first move is always the same: expand the sender and read the address itself. What matters is the domain — the part to the right of the @ — and specifically its last two labels, for exactly the reason set out in our guide to checking a website.

  • A real brand with an extra word: support-yourbank.example rather than yourbank.example.
  • The brand as a subdomain of something else, where yourbank.example.mail-secure.example belongs to mail-secure.example.
  • A free mail provider for something that would never use one. No bank, tax authority or payroll department sends from a consumer webmail address.
  • A near-miss on the spelling, which is the same character-swap trick used on domains.

Check where a reply would go

A message can be sent from one address and quietly set to reply to another. It is a normal feature, used by mailing lists and ticketing systems, and it is also how a convincing invoice fraud works: the mail appears to come from a supplier you know, and your reply goes somewhere else entirely.

Most clients will show the reply-to address if you start a reply and look at the To field before typing. If it does not match the sender, that is worth understanding before you answer, particularly on anything about payment details.

Do not act on the link

The link is the whole delivery mechanism, and inspecting it is a game you do not need to play. Hovering shows a destination, but the visible text, the destination and where it finally lands after a redirect can all be different, and a shortened link shows you nothing at all.

The habit that removes the question: reach anything important the way you already know how. Type the address, use your own bookmark, or open the organisation's app. If the message is genuine, whatever it wants you to see will be waiting for you when you arrive under your own steam.

  • A login page reached from an email is the single most common way credentials are taken.
  • A QR code in an email is a link you cannot read at all, and it is used precisely because of that.
  • An unsubscribe link in a message you never subscribed to confirms your address is live. Mark it as spam instead.

Ask what it is trying to take

Phishing messages vary enormously in their story and hardly at all in what they want. Naming the target is often quicker than assessing the story.

  • A credential: a login page for mail, banking, a delivery account or a workplace system.
  • A one-time code, asked for by a follow-up call or message. The code authorises something happening at that moment; reading it out is the authorisation.
  • A payment: an invoice, a fee, a fine, or changed bank details on an expected transfer.
  • An installation: an attachment, a document that asks you to enable content, or a support tool that grants remote access.
  • A reply, on its own. Some campaigns only want to establish that a person reads the address before a human takes over.

Attachments, and anything that asks for permission

An unexpected attachment is worth more suspicion than an unexpected link, because the failure is quieter. Documents that ask you to enable editing, enable content or allow macros are asking for permission to run something, and the request is the payload rather than a step towards it.

The same applies to any message that ends with installing software, granting access to a device, or connecting an account to a third-party app you have not heard of.

Check the identifiers against community reports

An email hands you more to check than most approaches do: the sender address, the reply-to address, the domain of any link, and often a payment handle or an amount. Those are all identifiers, and they are worth checking individually rather than as one impression.

Sending addresses are cheap and get burned quickly, so an address with no reports is close to meaningless as reassurance. The domain the link points at, and the account it eventually asks you to pay, are the durable parts and the ones most likely to be on file already.

Frequently asked questions

The email came from the company's real address. Is it safe?
Not necessarily. Sending addresses can be forged, and genuine accounts are regularly compromised and used to mail their own contacts. A correct address raises the odds that a message is real; it does not settle it, and it should not change how you handle a request for money, credentials or a code.
Is it dangerous to open a phishing email?
Opening the message itself is generally not the risk. What matters is what you do next: following the link, opening an attachment, enabling content, replying, or entering anything on a page it took you to. Treat the message as inert and the actions it invites as the hazard.
How can I tell if a login page is fake?
Do not try. A copied login page can be pixel-perfect, and the address bar is the only reliable signal — which is exactly what you skip past when you arrive by clicking. Reach the site by typing the address or using your own bookmark, and the question does not arise.
They knew my name, my employer and a recent order. Doesn't that prove it is genuine?
No. Details like these circulate widely after data breaches, and plenty of them are simply public. Knowing something true about you is the standard opening of a convincing approach, not evidence that the sender is who they say.
Reported email addressesAddresses reported for phishing, advance-fee and business-impersonation approaches.

Related guides

The app

Check before you send money

Look up a website, phone number, payment account or crypto wallet against what the community has already reported.

Download Exposing Scams — free

Store links appear here as soon as the app is published in your region.