What To Do After a Scam
Should You Reply to a Suspicious Email?
It feels harmless to fire back a one-line reply. It is not. Here is what a scammer learns the moment you press send.
Quick answer
No — do not reply, even to say 'stop' or 'take me off your list'. Replying confirms three valuable things at once: your address is monitored by a real human, that human reads emails at this hour, and they are willing to engage. That is exactly what a scammer needs to move from a mass blast to a targeted follow-up. Instead: report the message as phishing inside your email app (this trains the filter), forward it to reportphishing@apwg.org and to the impersonated company's abuse address, then delete it. If you already replied, do not reply again, watch for follow-up scams, and change your password if you shared any personal details.
Warning signs to look for
- You feel an urge to correct the sender or point out obvious mistakes
- The email accuses you of something and you want to defend yourself
- It is a 'sextortion' or blackmail email and you want to prove you are not scared
- It looks like a real invoice you did not authorize and you want to say 'wrong person'
- The email offers a job, prize, or refund and you 'just want to see if it is real'
- It appears to come from someone you know but the writing feels off
What a scammer actually learns from your one-line reply
When you reply — even with 'no', 'stop', or 'wrong person' — the scammer's system records four things: your address is live, a human reads it, they read at a predictable time of day, and they respond to prompts. That signal is worth far more than the address itself. Live, responsive addresses are re-sold on scam-lead marketplaces at a premium, and get moved from mass blast lists to hand-worked 'targeted' lists. Silence is not rude; it is the single cheapest defense you have.
The specific traps that beg for a reply
Some scam templates are engineered to bait a response. 'We shipped your $499 iPhone — reply if this was not you.' 'Your PayPal account has been charged. Call or reply within 24 hours.' 'I have compromising video of you.' 'Are you available? I need a favor.' In each case, the whole scam only starts working after you reply. The 'reply if not you' number or address goes to the scammer, not to Apple or PayPal.
Special case: emails 'from someone you know'
If a message appears to come from a friend, family member, coworker, or your boss but the tone or request is off — a gift-card errand, a wire transfer, a change to payroll direct deposit — do not reply and do not use any phone number in the email. Contact the person on a channel you already have (their known cell number, in person, or a fresh text thread you start). Business email compromise scams almost always fall apart the second the target calls the real person.
Special case: sextortion and blackmail emails
These emails claim the sender has hacked your webcam or has embarrassing videos, and demand payment (usually in Bitcoin). Almost all of them are mass-sent bluffs, often using an old password from a public data breach to seem credible. Do not reply, do not pay, do not negotiate down. Change the password if you still use it anywhere, enable two-factor authentication on your important accounts, and report the message at ic3.gov. The FBI has published specific guidance confirming these are overwhelmingly empty threats.
What to do instead of replying
1) Use the 'Report phishing' or 'Report spam' button in your email app — in Gmail it is under the three-dot menu; in Outlook it is on the ribbon; on Apple Mail it is 'Move to Junk'. This trains the filter for you and for millions of other users. 2) Forward the full message to reportphishing@apwg.org (the Anti-Phishing Working Group) and, if a real company was impersonated, to that company's abuse address (for example, phishing@paypal.com, reportphishing@apple.com, phish@amazon.com, abuse@microsoft.com). 3) In the U.S., report to the FTC at reportfraud.ftc.gov. 4) Then delete it.
How to forward a phishing email correctly
Use 'Forward as attachment' when your email app offers it — that preserves the original headers, which is what abuse teams actually need. In Gmail on the web: open the message → three-dot menu → 'Forward as attachment'. In Outlook: right-click → 'Forward as Attachment' or use the menu. On Apple Mail: hold Shift and choose 'Forward as Attachment'. A regular forward is still useful, but attachment-style is better.
You already replied — is it bad?
It is not a disaster, but do the following: stop the conversation now (no 'one last message'), do not click any link they send in response, and change the password on any account whose details you mentioned. Watch your inbox for a spike in scam messages over the next few weeks — that is the resale effect. If you shared a phone number, expect scam calls; do not answer unknown numbers and let voicemail screen. If you shared financial details or a password, treat this as a compromised account and follow the steps in our guide 'I Gave a Scammer My Password'.
How SpamCheck can help
If you are tempted to reply because 'what if it is real?' — that is exactly the moment to send it to us instead. Forward the original message to check@spamcheck.com and we will reply in plain English with whether it looks legitimate, what specifically gave it away, and how to verify with the real company if there is any doubt.
Frequently asked questions
- But what if the email is actually from my bank?
- Real banks are fine with you not replying. Log into your bank's app or website directly, or call the number on the back of your card. If the message is real, the same alert will be waiting for you inside your account. If it is not, you have lost nothing.
- Does clicking 'unsubscribe' count as replying?
- For lists from real companies you signed up with, unsubscribe is safe and legally required to work. For obvious scam or spam email, unsubscribe links can be trackers or worse — treat those the same as any other link and use your email app's 'Report spam' button instead.
- Is it safe to reply with 'STOP' like on a text message?
- 'STOP' works on legitimate SMS marketing under U.S. carrier rules. It does not work on email, and it does not work on scam texts either — for those, forward the message to 7726 (SPAM) on most U.S. carriers and delete it.
- The email threatens legal action if I do not respond. Should I reply?
- No. Courts, the IRS, and legitimate law firms do not initiate legal action by email demanding a reply. If you are genuinely worried, look up the supposed sender independently and call them — never through the email.
- I want to mess with the scammer. Any harm in that?
- Yes: it wastes your time, marks your address as 'engaged', and can escalate. If you enjoy that kind of thing, do it from a throwaway address you do not care about, never your real one. For most people, the best revenge is a report to APWG and the FTC that helps take the operation down.
Sources
SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.
About SpamCheck
SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.
Related guides
I Replied to a Scam Email — What Should I Do?
Replying to a scam email is not a disaster, but it does mark you as a live target. Here is how to shut the conversation down and protect what matters.
Is This Email a Scam? How to Check
You have a suspicious email open right now. Here is the fastest reliable way to decide whether it is a scam, without clicking anything in it.
10 Things Scammers Say (Word for Word)
Scam scripts are recycled across thousands of criminals. Learn these ten exact phrases and you'll recognize the play in the first sentence.
7 Red Flags That an Email Is a Scam
You don't need to be technical. These seven signs catch the overwhelming majority of scam emails before you click.
I Clicked a Phishing Link — What Should I Do?
Clicking a phishing link is usually recoverable — especially if you did not type anything on the page that opened. Work through these steps in order.
I Downloaded an Attachment From a Suspicious Email
Downloaded — or opened — an attachment you shouldn't have? Work through these steps in order. Most people are fine, but the next hour matters.