Start with the sender's address, not the display name
The name that appears in your inbox — "Amazon Customer Service" or "Your Bank" — can be anything. Anyone can type any name into the display field. The only part that matters is the actual email address, the one that comes after the @ symbol. If you received a message that says it's from your bank but the address is something like support@amaz0n-help.com (with a zero instead of the letter O), it's not from your bank.
Hover over or tap the sender's name to reveal the full email address. On Gmail, click the down arrow next to the sender's name. On Outlook, click "From" to expand it. On Apple Mail, right-click the sender and select "Copy Address". Write down what you see. If the domain — the part after the @ — doesn't match the organization's real website, stop there. Do not click links or read attachments.
Real organizations use their own domain names. Amazon uses @amazon.com. Your credit card company uses their registered domain. If you're unsure what the real domain is, go to the organization's website directly (type it into your browser yourself, don't click a link in the email) and look for contact information or a support page. That will show you what their real email addresses look like.
Key Takeaways
- The display name in an email can be faked; only the actual email address after the @ symbol matters.
- Hover over or tap the sender's name to see the full email address, and check that the domain matches the organization's official website.
- Legitimate organizations use their own registered domain names, not free email services like Gmail or Yahoo for official communications.
- Links and attachments in suspicious emails can contain malware, so verify the sender's address before clicking anything.
- When in doubt, contact the organization directly using a phone number or website address you find yourself, not one provided in the email.
Look for mismatches between the domain and the organization
Scammers often use domains that look similar to the real thing at a glance. They might use a free email service (Gmail, Yahoo, Outlook.com) and claim to represent a company that would never do that. A real bank will not send official communications from a Gmail account. A real retailer will not use Yahoo. These services are for personal use, not business.
Watch for subtle misspellings. A domain might be paypa1.com (with the number 1 instead of the letter l), or appleid-verify.com (adding extra words to make it sound official). These are designed to fool you in a quick glance. When you hover over the address, read it slowly, character by character. Compare it to the official domain you found on the organization's real website.
Some scammers use subdomains — addresses like support.amazon.com.fake-site.net. The real domain is the last part before the top-level extension (.com, .org, .net). Everything before that is a subdomain. In this example, the real domain is fake-site.net, not Amazon. If you're not sure, copy the email address and paste it into a search engine. Legitimate organizations' official email addresses will appear in their help articles or on their websites.
Check whether the email uses encryption or authentication
Some email providers show you whether a message was encrypted or authenticated — that is, whether it passed security checks that prove it actually came from the claimed sender. These indicators are not foolproof, but they are a useful second check after you've verified the sender's address.
On Gmail, look for a lock icon or a question mark icon next to the sender's name. A lock means the message was encrypted in transit. A question mark or exclamation point means Gmail could not verify the sender's identity. Click on it to see what the issue was. On Outlook, look for an "Authentication" label or a shield icon. On Apple Mail, check the Details section for "Signed" or "Encrypted" status.
If an email claims to be from your bank or a payment service but shows no authentication, that's a red flag. Legitimate financial institutions use authentication protocols like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance). These are technical standards that let email systems verify a message really came from the organization's servers. Your email provider checks these automatically, but you can see the results if you look for the authentication indicator.
Be skeptical of urgent requests for personal information
Even if the sender's address looks correct, pause before responding to any email that asks you to confirm passwords, account numbers, Social Security numbers, or payment information. Legitimate organizations almost never ask for this information by email. Banks know your account number already. Payment services don't need you to "verify" your password. These are classic phishing tactics.
If an email says your account will be closed, your payment failed, or you need to act when ready, that's pressure designed to make you skip your normal checks. Real organizations send these notices through your account dashboard or by phone, not just by email. If you're worried, close the email and contact the organization directly using a phone number or website you find yourself. Do not use contact information from the suspicious email.
Legitimate companies also don't ask you to click a link to "verify" or "confirm" anything. If you need to take action on your account, you should log in to the official website or app directly. Type the web address into your browser yourself. Do not click links in emails, even if the sender's address looks right. Scammers can make links appear to go one place while actually sending you somewhere else.
Verify sender details through a separate channel
If an email is important — a payment confirmation, a password reset, a legal notice — and you're not completely sure it's real, contact the organization through a different method. Call their customer service number. Use the phone number on their official website, not one provided in the email. Log into your account on their website and check your message center or notifications there.
This takes a few extra minutes, but it's the only way to be certain. A scammer can fake an email address and make it look authentic, but they can't intercept your phone call to the real company or access your account dashboard. If the email is real, the organization will have a record of it when you contact them. If it's fake, they'll tell you when ready.
Keep a list of the official contact numbers for organizations you deal with regularly — your bank, your email provider, your insurance company, your utility. Store these in your phone or a notebook. When you get a suspicious email, use these numbers to verify. This is especially important for financial or medical information, where a mistake could cost you money or expose your health data.
Understand what you can and cannot tell from an email header
If you're comfortable looking at technical details, you can examine an email's full header to see the path the message took from sender to your inbox. This shows every server the email passed through. However, headers are complex and straightforward to misread. A message can appear to come from one server while actually being sent from another. Scammers can also forge headers, though it takes more skill than faking a display name.
To view the full header, right-click the email in most programs and select "View Message Source" or "Show Original". In Gmail, click the three dots next to the sender's name and select "Show Original". You'll see lines like "From:", "Return-Path:", "Received:", and "Authentication-Results:". The "Authentication-Results:" line is the most useful — it tells you whether SPF, DKIM, and DMARC checks passed.
If you're not familiar with reading headers, don't spend time trying to decode them. The sender's address and the authentication indicator are enough for most people. If you want to learn more, your email provider's help center has guides on reading headers. But for day-to-day safety, verifying the sender's address and contacting the organization directly is more reliable than trying to interpret technical details.
Frequently Asked Questions
Can I trust an email if it has a lock icon next to it?
A lock icon means the email was encrypted while traveling to you, which is good, but it doesn't prove who sent it. Scammers can also send encrypted emails. Always check the sender's address first. Encryption protects the message from being read in transit, but it doesn't verify the sender's identity.
What should I do if I already clicked a link in a suspicious email?
Don't panic, but act quickly. If you entered a password or personal information, change your password when ready using the official website or app. If you downloaded a file, run a virus scan on your device. Contact the organization directly to report the suspicious email and ask whether your account was accessed. Monitor your accounts for unusual activity over the next few weeks.
Why do some legitimate emails fail authentication checks?
Small organizations, nonprofits, and some automated systems may not have authentication set up correctly, even though they're real. This is frustrating but common. If the sender's address matches the organization's official domain and the content makes sense in context, it's probably legitimate. When in doubt, contact them directly to confirm.
Is it safe to reply to an email to ask if it's real?
No. If the email is fake, replying confirms your email address is active and monitored, which makes you a target for more scams. Instead, find contact information on the organization's official website and reach out that way. This also gives you a record of your inquiry.
What's the difference between a domain and a subdomain?
A domain is the main registered name, like amazon.com or yourbank.com. A subdomain is a section of that domain, like support.amazon.com. Scammers sometimes use fake subdomains to trick you — for example, amazon.com.scam-site.net looks like it contains "amazon.com" but the real domain is actually scam-site.net. Always check what comes after the last dot.