Phishing

Is This Email a Scam? How to Check

You have a suspicious email open right now. Here is the fastest reliable way to decide whether it is a scam, without clicking anything in it.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Treat the email as a scam until you have checked three things: the sender's full email address (not the display name), where the links actually point, and whether the message is pressuring you to act quickly. If the message asks for a password, a payment, a gift card, a code from a text message, or remote access to your computer, it is almost certainly a scam. Do not click, reply, or call any number in the message. Instead, contact the company yourself using a phone number or website you already trust — or forward the email to check@spamcheck.com and we will tell you in plain English what it looks like.

Warning signs to look for

  • The display name says a company you know, but the actual address is a random Gmail, Outlook, or lookalike domain
  • You are told your account will be closed, suspended, or charged unless you act within hours
  • The message asks for a password, a Social Security number, a card number, or a verification code
  • You are told to pay with gift cards, wire transfer, cryptocurrency, or a payment app
  • A link's visible text and its real destination do not match
  • An unexpected attachment, especially a .zip, .html, or an Office file asking you to enable content
  • Generic greetings, odd grammar, or a tone that does not match how that company normally writes
  • It references an order, invoice, subscription, or delivery you never made

Step 1: Read the real sender address, not the display name

Anyone can set the name that appears at the top of an email. On a phone, tap the sender name to expand it; on a computer, hover over it or open the message details. You are looking for the part after the @ symbol. Legitimate mail from a large company comes from that company's own domain — for example an address ending in @chase.com rather than @chase-secure-alerts.com or @chasebank.support. Extra words, hyphens, number substitutions, and unfamiliar country endings are the most common giveaways. A matching domain is not proof of safety, but a mismatched one is close to proof of a scam.

Step 2: Check where the links really go — without clicking

On a computer, rest your mouse pointer over the link and read the address that appears in the corner of the screen. On a phone, press and hold the link until a preview appears, then release without tapping. Look at the domain immediately before the first single slash — that is the site you would actually land on. Shortened links, addresses with long random strings, and pages hosted on free site builders are all reasons to stop. If the visible text says one thing and the destination says another, that alone is enough to delete the message.

Step 3: Ask what the email wants you to do

Nearly every scam email needs you to take one specific action: enter a password, confirm card details, open an attachment, call a number, install software, or send money. Legitimate companies do send notifications, but they do not need your password, they do not ask for a one-time code, and they do not require gift cards. If the requested action would hand over money, credentials, or control of a device, treat the request as hostile no matter how convincing the design looks.

Step 4: Notice the pressure

Urgency is the engine of fraud. Deadlines measured in hours, threats of account closure, warnings about suspicious activity, legal consequences, or a small refund that will 'expire' are all designed to stop you from checking. Real organizations give you time and let you handle things through your normal account page. If the message makes your heart beat faster, that is the moment to slow down rather than speed up.

Step 5: Verify through a channel you already trust

Do not use the phone number, link, or reply address in the suspicious message — scammers supply their own contact details. Instead, open your banking app, type the company's website address yourself, or use the number printed on the back of your card, on a statement, or on the official app. If the alert is real, you will see the same message inside your account. If nothing is there, the email was fake.

If you are still unsure, have someone look at it

Some scams are genuinely hard to call, especially well-made copies of bank and delivery notices. Forward the original message — not a screenshot — to check@spamcheck.com. SpamCheck reviews the sender details, the link destinations, and the wording, then replies in plain English with what looks safe, what looks suspicious, and what to do next. Your first check is free and there is no signup.

What to do once you have decided

If it is a scam: do not reply, do not click, mark it as spam or phishing in your email app so future messages are filtered, and delete it. In the United States you can report it to the FTC at reportfraud.ftc.gov and forward it to reportphishing@apwg.org. If you already clicked, entered information, or replied, work through our step-by-step recovery guides rather than waiting to see what happens.

Frequently asked questions

Can an email be a scam even if it looks perfect?
Yes. Scammers copy real logos, fonts, footers, and legal disclaimers, often by duplicating a genuine email they received themselves. Appearance is the least reliable signal. Judge the message by the sender domain, the link destinations, and what it is asking you to do.
Is it dangerous just to open a scam email?
Simply opening a message in a modern email app is low risk. The danger comes from clicking links, opening attachments, enabling content in documents, replying, or calling a number in the message. If you only opened it and did nothing else, you are very likely fine.
The email came from a real company's address. Does that make it safe?
Not always. Sender addresses can be spoofed, and criminals sometimes send from genuine accounts they have broken into, including accounts belonging to people you know. A matching domain removes one warning sign, but you should still check the links and the request itself.
Should I reply and ask if it is real?
No. Replying confirms your address is live and puts you in direct contact with the sender, which usually leads to more attempts. Verify through the company's official app, website, or printed phone number instead.
What if the email mentions a password I actually use?
That usually means the password appeared in a past data breach that has nothing to do with the sender. Change that password everywhere you have used it, turn on two-factor authentication, and ignore any demand for payment.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides