Technology

Signs That an Email Isn't What It Claims to Be

Fraudulent emails are designed to look legitimate. Learn the specific red flags that reveal a suspicious message before you click anything.

Signs That an Email Isn't What It Claims to Be

Photo: HorizonMetric.com | One Destination For Everyday Insights editorial

—— In This Article
  1. Why Spotting a Fake Email Is Harder Than It Sounds
  2. The Red Flag Checklist: What to Examine Before You Trust Any Email
  3. What to Do When You Spot These Signs

Key Takeaways

  • The sender's display name can be faked; always check the actual email address behind it.
  • Urgency and fear are the most common emotional levers scammers use to rush you into mistakes.
  • Hover over links before clicking — the real destination often has nothing to do with the claimed sender.
  • Legitimate organizations rarely ask for passwords, Social Security numbers, or payment details by email.
  • Even well-crafted fraudulent emails leave behind small, detectable inconsistencies if you know where to look.

Why Spotting a Fake Email Is Harder Than It Sounds

Scammers no longer send obviously garbled messages full of typos and wild promises. Today's fraudulent emails are polished — they borrow real logos, mimic authentic formatting, and copy the exact tone a bank or delivery service might use. That polish is the point: the harder it is to distinguish a fake from the real thing, the more likely someone clicks.

Understanding how these messages work is the first step. For a broader look at how email scams fit into the wider landscape of digital fraud, see our guide on phishing, smishing, and vishing. This checklist focuses specifically on the signals inside an individual email that can reveal it isn't what it claims to be — before you click, reply, or download anything.

Required

Email client's 'Show Original' or 'View Headers' feature

Reveals the full technical path an email traveled, helping you spot spoofed sender addresses or suspicious routing.

Required

Link preview (hover-over)

Shows the real destination URL of any hyperlink before you click — built into nearly every desktop email client and modern browser.

Required

Official website or customer service line of the claimed sender

Lets you verify independently whether a message is genuine without relying on any contact information in the suspicious email.

Optional

FTC ReportFraud portal (reportfraud.ftc.gov)

Allows you to report suspected fraud to U.S. federal authorities, contributing to broader consumer protection efforts.

The Red Flag Checklist: What to Examine Before You Trust Any Email

Work through each group below whenever an email makes you pause. You don't need to find every warning sign — even one or two should prompt caution.

Sender Identity

Check the actual email address, not just the display name — hover over or tap the sender name to reveal the underlying address. Must
Look for slight misspellings in the domain (e.g., "paypa1.com" or "amazon-support.net" instead of "amazon.com"). Must
Be suspicious if a company email arrives from a free webmail address like Gmail or Yahoo rather than a corporate domain. Must
Check whether the reply-to address differs from the sender address — a mismatch is a common fraud technique. Should

Tone and Pressure Tactics

Flag any message that creates extreme urgency — "Your account will be closed in 24 hours" is a classic manipulation tactic. Must
Be wary of threats, such as claims that you owe money, face legal action, or will lose access to an account. Must
Notice if the email asks you to keep the communication confidential or act without telling anyone — legitimate businesses don't do this. Should

Links and Attachments

Hover your cursor over any link (without clicking) to preview the destination URL — if it doesn't match the claimed sender's domain, don't click. Must
Be cautious with shortened URLs (e.g., bit.ly links) that hide the real destination address. Must
Do not open unexpected attachments, especially files ending in .exe, .zip, .docm, or .xlsm, even if the sender appears familiar. Must
Verify that any linked website uses HTTPS — though note that HTTPS alone does not guarantee a site is legitimate. Our article on what HTTPS actually protects explains the difference. Should

Content and Requests

Treat any request for your password, Social Security number, or full credit card number as an automatic red flag — legitimate companies don't ask for these by email. Must
Read the greeting carefully — generic salutations like "Dear Customer" or "Dear User" suggest the sender doesn't actually know who you are. Should
Look for inconsistencies in logos, fonts, or color schemes that differ subtly from what the organization normally sends. Should
Question any unexpected prize, refund, or inheritance offer — unsolicited windfalls are almost always fraudulent. Must

Language and Formatting

Scan for unusual grammar, odd phrasing, or awkward sentence structure that feels slightly off even if the overall design looks polished. Should
Look for mismatched fonts, broken images, or layout errors that wouldn't appear in a genuine corporate communication. Nice to have

Clicking 'Unsubscribe' on a Suspicious Email Can Backfire

On genuine marketing emails, the unsubscribe link works as intended. On a fraudulent message, clicking it can confirm to the sender that your address is active — potentially increasing the volume of scam attempts you receive. If an email looks suspicious, mark it as spam through your email provider rather than engaging with any links inside it.

What to Do When You Spot These Signs

Finding one or more of these red flags doesn't mean you're helpless. The safest immediate step is to not interact with the message at all — don't click links, don't open attachments, and don't reply. If the email claims to be from your bank, a government agency, or a service you actually use, contact that organization directly through their official website or a phone number you find independently, not one provided in the email.

Most email providers let you report a message as phishing or spam, which helps their systems protect other users too. If you've already clicked a link and entered information, change your passwords immediately and, if financial data was involved, contact your bank or card issuer. An inbox full of suspicious messages is also worth addressing systematically — our guide on reclaiming your inbox from spam covers practical steps to reduce the noise.

If You've Already Clicked, Act Quickly

Time matters if you've interacted with a fraudulent email. Change your password for any affected accounts immediately, using a device you're confident is secure. If you entered payment information, call your bank or card issuer directly to report potential fraud. Avoid using the same compromised password on any other account — password reuse gives attackers access far beyond the original target.

This article is for informational purposes only. It is general digital safety education, not legal or security consulting advice. If you believe you've been the victim of fraud, contact your financial institution and consider reporting the incident to the FTC at reportfraud.ftc.gov.

Technology Editorial Team

Technology Editorial Team

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View author profile
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.