Phishing

How to Check If an Email Is Legitimate

Verifying a legitimate email is a different job from spotting an obvious scam. Here is how to confirm a message really came from who it claims.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

An email is legitimate when three things line up: the address after the @ symbol belongs to the company's real domain, every link points to that same domain, and the same information appears when you log into your account independently. If any of those three fails, treat the message as fake. Verification always means going to the company yourself — never using a phone number, link, or reply address supplied by the message you are trying to check.

Warning signs to look for

  • The reply-to address is different from the visible sender address
  • Links point to a domain that is similar to, but not the same as, the company's website
  • The message arrived at an email address you never gave that company
  • There is no reference to your account beyond a generic 'Dear Customer'
  • The claim in the email does not appear anywhere in your account when you log in normally

Match the domain exactly, character by character

Read the part after the @ symbol slowly and compare it with the company's real website address. Fraudulent domains rely on details your eye skips: an extra word (paypal-billing.com), a hyphen, a different ending (.net instead of .com), a doubled or dropped letter, or a subdomain trick where the real domain sits at the end (secure.chase.com.login-verify.net is not Chase). Large companies also use dedicated sending domains for marketing, so an unfamiliar-but-related domain is not automatically fake — which is exactly why you also check the links and your account.

Inspect links before you trust them

Hover on a computer or long-press on a phone to reveal the true destination. Legitimate account notices link to the company's own site, usually to a login or account page. Be sceptical of link shorteners, addresses with long random strings, pages hosted on free website builders, and anything that opens a login form as soon as you arrive. When in doubt, ignore the link entirely and type the company's address into your browser yourself.

Read the message details or headers

Most email apps let you see more than the summary line. In Gmail, open the message, click the three dots, and choose 'Show original'. In Outlook, open the message and use File → Properties or the message details view. You are looking for SPF, DKIM, and DMARC results — three checks mail servers run automatically. 'pass' on all three means the message really was sent by a server authorised for that domain. A 'fail' or 'softfail' on a message claiming to be from a large bank is a strong sign of forgery. These checks are technical, so treat them as supporting evidence rather than the whole answer.

Confirm inside your account, not inside the email

This is the single most reliable step and it works even when the technical details are beyond you. Close the email. Open the company's official app or type its website address yourself. Log in and look for the same notice: the alert, the order, the invoice, the delivery, the password reset. Real notifications are almost always mirrored in your account or message centre. If nothing is there, the email is fake — regardless of how convincing it looked.

Call using a number you already have

Use the number on the back of your card, on a paper statement, or inside the official app. Never call a number written in the email itself, and never let anyone who calls you talk you into installing remote-access software or moving money to a 'safe account'. Real staff will not object to you hanging up and calling back on a published number.

When verification is genuinely hard

Some legitimate emails come from third-party services a company hired, which makes the domain look unfamiliar. Some scams pass technical checks because they were sent from a compromised but genuine mailbox. If you have worked through the steps and still cannot tell, forward the original email to check@spamcheck.com. SpamCheck will look at the sender, the authentication results, and the link destinations, and reply with a plain-English explanation of what it found.

Frequently asked questions

Does a padlock or 'https' on the linked website mean it is legitimate?
No. The padlock only means the connection is encrypted; scam sites obtain those certificates freely and in minutes. Judge the domain name, not the padlock.
What do SPF, DKIM, and DMARC actually tell me?
They tell you whether the sending server was authorised to send mail for that domain and whether the message was altered in transit. Passing all three means the domain is very likely genuine. Failing them on a message from a major brand is a serious warning sign.
The email is addressed to me by name. Is that a good sign?
It is weak evidence at best. Names, addresses, and even partial account numbers circulate in breach data, and criminals use them to make messages feel personal.
Can I check an email by forwarding it to the company?
Yes, and it helps them. Many companies publish an abuse or phishing address for exactly this purpose. Just be aware that replies can take days, which is why an independent login check is the faster way to protect yourself right now.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides