Skip to main content

Email Checker

Is this email a scam?

Most scam emails fail on one detail: where they were really sent from, or what they ask you to do next.

Short answer

Read the sending address, not the display name. Then ask what the email wants from you — a password, a payment, a one-time code, or a click that leads to one of those. A message that creates urgency and asks for credentials is a scam however professional it looks.

Warning signs

  • The display name and the address disagreePayPal Support <billing@paypa1-secure.example> is not PayPal. The display name is free text that anyone can type in seconds.
  • The reply-to points somewhere elseWhen the visible sender and the reply address belong to different domains, your reply is routed to the attacker.
  • It asks for a code or a passwordNo legitimate company asks for a one-time code, a password or a full card number by email. Not one, not ever, not as a security check.
  • The link goes to a login pageThe email exists only to get you to a fake login form. The form is the payload — the rest is packaging.

How to check it yourself

  1. Read the real addressOpen the sender details and read the address after the @ sign. That domain is the only part the sender had to own.
  2. Check the reply-toIf it differs from the sender, treat the message as hostile and do not reply.
  3. Ignore the designLogos, footers and legal disclaimers are copied from the real site in seconds. Production quality is the cheapest part of a phishing kit.
  4. Verify out of bandContact the company using a number from your own statement or card. Never use a number or a link that came inside the email.

Frequently asked questions

The email came from a real address. Can it still be fake?

Yes. Addresses can be spoofed, and a genuine account can be taken over. Judge the request, not only the address.

What if I did not click anything?

Nothing is lost. Delete the message, or report it as phishing in your email client so it is filtered for other people too.

I entered my password. What should I do now?

Change that password immediately, then change it everywhere you reused it, and enable two-factor authentication. Check your mailbox rules for forwarding you did not create.

Are attachments safer than links?

Usually worse. A document that asks you to enable macros, or to sign in again, is an attack with an extra step.