Not sure if an email is really from the company it claims to be? Learn how to check the sender address, inspect links without clicking, spot lookalike domains, and verify suspicious emails safely.
An email can look completely legitimate and still be a scam.
The company logo may be familiar. The colors may look right. The message may mention a service you actually use. It might even contain your name.
That is why checking an email based only on how professional it looks is risky.
Scammers regularly pretend to be banks, online stores, delivery companies, streaming services, technology companies, and other organizations people recognize. Their goal is usually simple: get you to click a link, open an attachment, provide information, or make a payment.
The good news is that you do not have to guess.
There are several practical ways to check whether a suspicious email is really from the company it claims to represent. For a broader set of warning signs, see our guide on how to tell if an email is a scam, and for the wider picture of how these attacks work, read what phishing is and how phishing scams work.
The first thing to check is the complete email address, not just the name displayed beside it.
For example, an email might display:
Apple Support
But the actual address could be something completely unrelated.
A sender name is easy to imitate. The full email address provides much more useful information.
Look carefully at the domain after the @ symbol.
If an email claims to come from a company but uses a strange or unrelated domain, that is a strong warning sign.
However, do not assume that a familiar-looking domain automatically proves the email is genuine. Sophisticated scams can use convincing addresses, compromised accounts, or other tricks.
The sender address is one clue, not the entire answer.
When you reply to most emails, your response goes back to the person who sent the message. But that is not always the case.
An email can include a separate Reply-To address. If one is set, your reply is routed there instead of the address shown in the From field.
This feature has legitimate uses. A company might send a newsletter from one address but want replies to reach a different support inbox. A person might send mail from one account but want responses sent to another.
It can also be misused. A scammer may send an email that appears to come from a familiar company, while quietly setting the Reply-To address to a personal inbox they control. If you reply, your message, and any information you include, goes to the scammer rather than the organization shown in the From field.
A mismatch between the From address and the Reply-To address deserves attention, especially when the Reply-To points to an unrelated domain or a free personal email service.
But a mismatch alone does not prove an email is malicious. Legitimate organizations do sometimes use a different Reply-To address for practical reasons. Treat it as one more clue to consider alongside the sender address, the request, and the context of the message.
Not every email provider shows the Reply-To address in a normal view. You may need to open the full message details or headers to see it, as described later in this guide.
Some scam emails use domains designed to look similar to legitimate ones.
A scammer might use a spelling variation, an extra word, a different domain ending, or a name that looks familiar at a quick glance.
For example, a scammer could try to make a domain look similar to the name of a real company by changing a character or adding another word.
Read the domain slowly.
Do not rely on the logo or the sender's display name.
An email might contain a button saying:
Verify your account
The visible text does not tell you where the button actually goes.
If you are on a computer, you can often move your pointer over a link without clicking it and inspect the destination.
If the destination does not match the company you expected, stop.
Google also recommends checking whether the sender address and sender name match and examining suspicious links before interacting with them.
Do not click a suspicious link just to find out where it goes.
If an email claims that something is wrong with your account, payment, order, subscription, or security, do not use the contact information provided in the suspicious message.
Instead, go to the company's official website yourself.
Type the address into your browser or use a bookmark you already trust.
Then sign in through the normal website or contact the company using information found there.
The Federal Trade Commission recommends contacting a company through a phone number, website, or other contact information that you know is genuine rather than using the information contained in an unexpected message.
This simple habit can prevent a convincing fake email from sending you to a scammer.
A common phishing tactic is to create a problem that needs your immediate attention.
The email might claim:
Your account has been locked.
Your payment failed.
There was suspicious activity.
Your subscription will be cancelled.
Your package cannot be delivered.
Your refund is waiting.
Your account needs verification.
The message then provides a link or asks you to provide information.
These situations are worth checking carefully. The FTC specifically identifies unexpected messages about account problems, suspicious activity, payment information, and requests for personal information as common phishing tactics.
The important point is not that every account warning is fake.
The important point is that you should verify the warning independently.
Scammers often want you to make a decision before you have time to think.
You might be told that you have only a few minutes to respond or that something serious will happen if you do not act.
Take a step back.
A legitimate problem can usually be checked through the company's normal website or official support channel.
CISA advises people to be cautious of messages that demand immediate action, request personal information, or create fear about an account or other problem.
Urgency does not prove an email is fraudulent, but it should make you slow down and verify it.
Be especially careful if an unexpected email asks for information such as:
Passwords
Banking details
Credit card information
Security codes
Identity information
Account recovery information
Some legitimate services may need information when you intentionally contact them through their official channels. That is different from receiving an unexpected email asking you to provide sensitive information through a link.
Never assume that a request is legitimate simply because the email uses a company's branding.
Ask yourself a simple question:
Was I actually expecting this?
If an email says you placed an order but you did not buy anything, investigate before clicking.
If it says your account has a payment problem but you have not used the service recently, do not follow the email's instructions automatically.
If it claims you requested a password reset that you did not request, go directly to the company's official website and check your account.
Context matters.
An unexpected message deserves more scrutiny than a message that matches something you knowingly did.
Poor spelling, strange grammar, and awkward wording can be useful warning signs.
But do not depend on them alone.
Modern scam emails can be professionally written, and legitimate companies can occasionally send messages containing mistakes.
A polished email can still be phishing.
A poorly written email can still be legitimate.
Look at the sender, the request, the links, the context, and how the message asks you to respond.
A fake email may provide a phone number that appears to belong to customer support.
Calling that number can put you directly in contact with the scammer.
Instead, find the company's contact information independently through its official website, a trusted statement, an existing account, or another source you already know is genuine.
The FTC has also warned that scammers can create fake customer service information, so finding contact details independently matters.
This is where many people make a mistake.
They think:
"It looks professional, so it must be real."
That is not a reliable test.
Phishing messages can copy logos, colors, writing styles, and other visual details from legitimate organizations.
The FTC has specifically warned that phishing messages can look like they come from companies people know and trust.
Instead of asking only whether the email looks real, ask:
Can I independently verify the request?
That is a much stronger question.
Beyond the sender address you can see, email systems use technical checks to evaluate where a message really came from. These checks are known as email authentication.
You do not need to memorize the technical details. But understanding the basics can help you interpret what an email provider tells you about a suspicious message.
SPF (Sender Policy Framework) lets the owner of a domain publish a list of servers that are allowed to send mail on its behalf. When a message arrives, the receiving server can check whether the sending server is on that list.
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to the message. The receiving server can verify that the message was signed by a key associated with the sending domain and that the message was not altered in transit.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) builds on SPF and DKIM. It lets a domain owner set a policy for what should happen when messages fail those checks, and it helps align the visible From domain with the domain that passed authentication.
Google's documentation describes SPF, DKIM, and DMARC as the core methods senders use to authenticate their email and help protect recipients from spoofed messages.
One more detail you may encounter is the Authentication-Results header. This is a line added by the receiving email server that records how the message performed against SPF, DKIM, and DMARC checks.
Here is the important part.
Authentication provides technical evidence about how a message was sent. It does not automatically prove that an email is safe or legitimate.
A message can pass SPF, DKIM, and DMARC and still come from a compromised account, a lookalike domain, or a sender with bad intentions. A marketing email from a real company can pass authentication, and so can a fraudulent message sent through a service the scammer controls.
Conversely, an authentication failure does not automatically mean an email is a scam. Legitimate mail can fail authentication because of misconfiguration, forwarding, mailing list software, or other technical reasons.
Treat authentication results as one more piece of context, not as a final verdict on whether to trust a message.
Most email providers do not show SPF, DKIM, and DMARC results in the normal reading view. To see them, you usually need to open the underlying message details.
Different providers use different wording for this. You may see options such as:
The exact name depends on your email service and device. In Gmail, for example, you can open a message, select the options menu (often shown as three dots), and choose Show original. Other providers place the option under message settings, security details, or a View headers link.
Do not assume every email service uses the same wording. If you cannot find it, check your provider's help documentation.
Once you open the full details, look for a line that begins with Authentication-Results. This is where the receiving server records its authentication checks.
You may see entries such as:
You may also see fail, softfail, neutral, none, or temperror instead of pass. Each value has a specific technical meaning.
These results need to be interpreted in context. A pass result tells you that a particular technical check succeeded. It does not tell you that the sender is trustworthy, that the request is legitimate, or that the message is safe to act on. A fail result is worth paying attention to, but it can also occur for innocent technical reasons.
If reading raw headers feels overwhelming, you do not have to do it manually. The Scamlify Email Header Analyzer can help you examine email headers, including authentication results, and present the information in a more readable form.
For analyzing the message content itself rather than the technical headers, you can also use the Scamlify Email Scam Checker.
Both tools are aids for investigation. They do not replace independent verification through a company's official website or app.
If you are still unsure about an email, you can use the Scamlify Email Scam Checker to analyze the message and identify potential warning signs.
The result should be treated as an additional layer of analysis, not as a guarantee that an email is safe.
For important accounts, payments, or personal information, always verify the situation directly with the organization through a trusted channel.
Do not reply to the scammer.
Do not click additional links.
Do not open unexpected attachments.
Do not provide passwords, financial information, or verification codes.
Report the message using the appropriate reporting tools available through your email provider or relevant organization.
The FTC recommends reporting phishing attempts and then deleting the message.
If you already provided sensitive information, take action quickly. Change affected passwords, enable multi-factor authentication where available, and follow the recovery guidance provided by the relevant service.
You do not need to become an expert in email security to avoid many phishing scams.
When an unexpected email asks you to click, pay, verify, log in, or provide information, stop.
Do not use the links or contact details in the message.
Go to the company's official website yourself and verify the situation there.
If you are still unsure, get a second opinion and use a scam-checking tool as another layer of analysis.
A few extra seconds of verification can be far more valuable than trusting an email simply because it looks convincing.
Yes. A scammer can copy logos, colors, and other branding. Visual appearance alone does not prove that an email is genuine.
Check the complete sender address, inspect the destination of links without opening them, and independently visit the company's official website instead of following the email's instructions.
No. Display names can be misleading. Check the complete sender address and consider the message's request and context.
It is safer not to reply. Contact the organization through a trusted website, phone number, or other independently verified channel.
Yes. Some phishing messages are designed to look very convincing. That is why independent verification is more reliable than appearance alone.
A Reply-To address is a separate address the sender can set so that your reply goes somewhere other than the From address shown on the email. It has legitimate uses, but a mismatch can be a warning sign, especially when the Reply-To points to an unrelated address.
No. Passing these authentication checks means the message met certain technical requirements. It does not prove that the sender is trustworthy or that the message is safe. Authentication is evidence, not a guarantee.
Open the full message details in your email provider. The option may be called Show original, View source, View message details, or Full headers, depending on the service. Look for an Authentication-Results line showing spf, dkim, and dmarc values.
Yes. Legitimate mail can fail SPF, DKIM, or DMARC because of misconfiguration, forwarding, mailing lists, or other technical reasons. A failure deserves attention but does not by itself prove the email is a scam.