How to Tell If an Email Is a Scam: 10 Checks
Scam emails no longer give themselves away with bad spelling. Many copy a real company’s layout word for word and arrive at the moment you’re expecting a parcel, an invoice, or a password reset. The reliable tells are in the details a scammer can’t easily fake: the sender’s real address, the domain behind it, and what the message asks you to do.
Here are ten checks, roughly in the order you should run them.
1. Look at the real sender address, not the name
The display name (“PayPal Support”, “Microsoft 365”) is free text anyone can type. Tap or hover over it to reveal the actual address. A message signed as your bank but sent from secure.alerts2291@gmail.com is a scam, however convincing the logo looks.
Legitimate companies send from their own domain. Banks, payment services, and large retailers don’t send account notices from Gmail, Outlook, or Yahoo addresses.
2. Read the domain from right to left
Scammers hide fake domains inside longer ones. In paypal.com.account-review.net, the domain that actually controls the email is account-review.net. Everything to its left is a subdomain the scammer created.
Also look for lookalike characters: rn passing for m (rnicrosoft.com), a digit 1 standing in for a lowercase L, or an extra word such as amazon-billing.com.
3. Check whether “Reply-To” points somewhere else
A scam can arrive from a real-looking address but send your reply to a different one. Hit reply without sending and check the address in the To field. If a message from your supplier’s domain replies to a free mailbox, stop.
4. Check the sender authentication results
Email has built-in checks called SPF, DKIM, and DMARC that confirm whether a message really came from the domain it claims. You can see the results:
- Gmail: open the message, tap the three-dot menu, and choose “Show original”. Look for PASS or FAIL next to SPF, DKIM, and DMARC.
- Outlook on the web: open the message menu and choose View → View message details, then look for “Authentication-Results”.
- Apple Mail: View → Message → All Headers.
A FAIL on a message claiming to be from a big brand is a strong warning sign. A PASS only proves the message came from that domain. Scammers can register their own domain and pass every check, which is why checks 1 and 2 still matter.
5. Find out how old the domain is
Scam domains are often registered days before the campaign. Look up the domain on ICANN Lookup and check the creation date. A “bank” or “courier” domain registered last week is almost never legitimate.
Our free scam email checker runs checks 1, 2, and 4 in one go. It shows the provider behind the address, whether it’s disposable, and whether the domain publishes SPF and DMARC, without contacting the sender.
6. Hover over every link before you click
On a computer, hover over a link and read the address in the corner of the browser. On a phone, press and hold the link to preview it. The text “View your invoice” can point anywhere. If the link’s domain doesn’t match the company, don’t open it.
Watch for QR codes in emails too. Scammers use them because email filters can’t read the link inside an image, and phones hide the address when you scan.
7. Be suspicious of certain attachments
Unexpected attachments are one of the most common ways malware gets in. Be especially careful with:
- .html or .htm files, which open a fake login page locally in your browser
- .zip, .iso, or .img archives that hide programs inside
- Office documents that ask you to “Enable content” or enable macros
- PDFs whose only content is a button or QR code leading to a login page
8. Notice pressure and secrecy
Scams work by rushing you past your own judgment. Typical lines: your account will be closed in 24 hours, a payment failed, a package is held until you pay a fee, or “keep this between us”. Real companies give you time and never ask you to bypass normal processes.
9. Treat payment changes as scams until confirmed
Business email compromise is one of the costliest scams: an email that looks like it’s from a supplier, landlord, or colleague says their bank details have changed. Sometimes it comes from a real, hacked mailbox, so every technical check passes.
Never act on new bank details sent by email. Call the person on a number you already have, not one from the message.
10. Watch for unusual payment methods
Gift cards, cryptocurrency, wire transfers, and payment apps are favored by scammers because the money is hard to recover. No tax office, utility, or tech support team asks to be paid in gift cards.
What to do with a scam email
- Don’t reply, click, or open attachments. Replying confirms your address is active.
- Report it in your mail app. Gmail and Outlook both have a “Report phishing” option, which improves filtering for everyone.
- Forward phishing emails to the Anti-Phishing Working Group at
reportphishing@apwg.org. If the email impersonates a company, forward it to that company’s official abuse address as well. - In the US, report fraud to the FTC at ReportFraud.ftc.gov.
If you already clicked or paid
Act quickly. Change the password on the affected account, and on any other account using the same password, then turn on two-factor authentication. If you entered card or bank details, call your bank using the number on your card and ask them to block the payment. In the US, report losses to the FBI’s IC3. The sooner a transfer is reported, the better the chance of stopping it.
Not sure about a sender right now? Run the address through a free email owner check before you reply.
Frequently asked
Can a scam email come from a real company address?
Yes. Display names are easy to fake, domains without DMARC can be spoofed, and real mailboxes get hacked. That is why you should confirm payment or account requests through a channel you already trust.
Is it dangerous to open a scam email?
Opening it is usually low risk in modern email apps. The danger is clicking links, opening attachments, replying, or scanning QR codes inside it.
Where do I report a phishing email?
Use Report phishing in Gmail or Outlook, forward it to reportphishing@apwg.org, and in the US report fraud at ReportFraud.ftc.gov.