The fastest safe response to a suspicious message is simple: do not click anything, check the full sender address, and hover over every link before you trust it. If those checks look off, or the message asks for money, passwords, or urgent action, treat it as fake until proven otherwise. When you need stronger proof, inspect the message headers for SPF, DKIM, and DMARC results before you act on anything inside it.
TL;DR:
- Most phishing emails can be identified quickly by checking sender addresses for spoofing, free email domains, or lookalike domains through close inspection.
- Verifying SPF, DKIM, and DMARC results in raw email headers provides strong proof of authenticity or suspicion, especially when all three pass.
- Hovering over links or long-pressing on mobile reveals true destination URLs, which should match the expected brand and avoid shortened or mismatched links.
- Attachments like executable files, ZIPs, or macro documents should be scanned and handled with extra caution before opening, especially if unexpected.
- After clicking or opening malicious content, disconnect from the internet, reset passwords, enable two-factor authentication, and report the incident promptly.
Table of Contents
ToggleThe 5-second visual checklist to spot fake emails fast
Most fraudulent emails fall apart under a quick look, if you know where to look. Before you read a single line of body text, run through a handful of visual checks that take less time than making coffee.
Start with the sender. A display name like “Amazon Support” means nothing: tap or click it to reveal the full address underneath. A real company almost never emails you from a free address like @gmail.com or @outlook.com, so that mismatch alone is a strong warning sign.
- Check the full address, not just the display name, since spoofed names are trivial to fake.
- Flag free-mail senders claiming to represent a bank, retailer, or government office.
- Treat urgency as a red flag: messages demanding immediate payment, password resets, or login confirmation are classic pressure tactics.
- Hover or long-press every link to preview its destination before tapping.
- Watch for shortened or mismatched URLs that do not match the brand name in the message.
- Don’t rely only on provider warnings: Gmail and Outlook flag some phishing attempts, but always verify independently.
The FTC warns that common phishing lures include fake login alerts, billing problems, delivery notices, and requests to confirm financial information, patterns that repeat across nearly every scam campaign regardless of the brand being impersonated. Spotting that pattern is often enough to stop before you ever touch a link.
Inspecting the sender: how to find lookalike domains and typosquatting
Once the quick visual pass raises a flag, the next step is confirming exactly who sent the message. Email clients hide the real address behind a display name by default, so you have to dig one layer deeper.
In Gmail, click the sender’s name at the top of the message and look at the address next to “from.” In Outlook, hover over the sender’s name or open the message and check the “From” field directly below the subject line. In Apple Mail, tap the sender’s name once to expand the full address. All three take seconds once you know where to look.
What you are hunting for is typosquatting: domains built to look right at a glance but wrong on close inspection.
- Character swaps: “arnazon.com” instead of “amazon.com.”
- Extra words or hyphens: “amazon-support.com” instead of “amazon.com.”
- TLD swaps: “amazon.net” or “amazon.co” instead of “amazon.com.”
- Subdomain tricks: “amazon.com.security-check.net,” where the real domain is buried mid-string.
Display-name spoofing works because most people read the name, not the address. A message that says “PayPal” in bold with a free-mail or unrelated domain underneath should never be trusted on name alone. CISA recommends checking the sender address specifically for these lookalike patterns, since spoofing the display name is far easier than spoofing the actual domain.
If the domain still looks plausible but you are unsure, copy it into a new browser tab (never click the link itself) and run it through a DNS, MX, or SPF lookup tool to confirm it belongs to the organization it claims to represent.
Headers and authentication: how to read SPF, DKIM, and DMARC
When visual checks aren’t conclusive, message headers give you the closest thing to hard proof. Every email carries hidden routing and authentication data that the display view strips out.
To see it: in Gmail, open the message, click the three-dot menu, and select “Show original.” In Outlook, open the message, go to File, then Properties, and look for “Internet headers.” Both reveal the same underlying data in slightly different formats.
- Open the raw header view using the steps above.
- Scroll to the line labeled “Authentication-Results.”
- Look for three tags: spf, dkim, and dmarc.
- Check whether each shows “pass” or “fail.”
- Confirm the domain in the “From” header matches the domain that passed authentication, not just any passing domain.
In plain terms, CISA explains SPF as a check that the sending server is authorized for that domain, DKIM as a digital signature confirming the message wasn’t altered in transit, and DMARC as the policy layer that ties both checks back to the domain shown in your inbox. A pass on all three is a meaningful signal. A fail, especially on DMARC alignment, is a strong sign the message is spoofed.
There are real limits to this method. Forwarded messages, mailing list traffic, and third-party senders (like a marketing platform sending on behalf of a legitimate company) can show SPF or DKIM failures even when the message is genuine, since the message passed through an extra server not covered by the original domain’s policy. Passing authentication also doesn’t guarantee the request inside the message is safe: a correctly signed message can still ask you to do something harmful.
If reading raw headers feels like too much, paste the header block into a reputable header analyzer tool rather than guessing at the syntax yourself.
Pro Tip: Bookmark your email provider’s “show original” or “view headers” menu option so you can jump straight to it the next time something feels off, instead of hunting through settings under pressure.
Links and attachments: safe inspection and verification methods
Links and attachments are where phishing actually does damage, so this is the step worth slowing down for. On desktop, hover your mouse over any link without clicking, and the real destination URL appears in the bottom corner of most browsers and email clients. On mobile, long-press the link instead of tapping it, and a preview of the destination pops up.

Shortened URLs (bit.ly, tinyurl, and similar services) hide the real destination entirely, which is exactly why scammers favor them. The FTC notes that hovering or long-pressing to preview a link is the fastest practical test available, and that HTTPS or a padlock icon only means the connection is encrypted, not that the destination is safe. Paste a shortened link into a reputable URL expander before trusting it, rather than clicking through blind.
Attachments carry their own risk hierarchy:
- .exe and .scr files are almost always dangerous and rarely sent legitimately over email.
- .zip files can hide executable content inside and deserve extra scrutiny.
- Macro-enabled Office documents (.docm, .xlsm) can run malicious code the moment you enable editing.
- PDFs are generally lower risk but can still embed malicious links.
When in doubt, scan attachments with updated security software before opening them, and if you already suspect a device is compromised, switch to a separate clean device to change any passwords rather than typing credentials in on the same machine.
Pro Tip: Never enable “editing” or “macros” on a document you weren’t expecting, even if the sender’s name looks familiar.
If you clicked or opened something: containment and recovery checklist
A click doesn’t have to turn into a loss if you act quickly and in the right order. The FTC’s recovery guidance lays out a clear sequence for limiting damage.
- Disconnect the device from the internet if you suspect malware, then run a full security scan with updated software.
- Switch to a separate, clean device and change passwords for any account you fear was exposed, starting with email and banking.
- Enable two-factor authentication on those accounts if it isn’t already on.
- Contact your bank or payment provider directly if financial information was shared or a payment was made.
- Report the incident to the appropriate national agency, such as the FTC’s ReportFraud.ftc.gov.
A few extra steps protect you beyond the immediate cleanup:
- Preserve the original email, ideally exported as a raw file, since screenshots strip out the header and routing data investigators actually need.
- Avoid forwarding it as a plain copy or screenshot when reporting; attach or export the original instead.
- Consider an identity-protection or dark-web scan if you believe login credentials were exposed, since stolen credentials often surface in breach data well after the original incident.
Moving fast on steps one through three matters more than being thorough about anything else first.
Tools and tests: what automated checks actually prove
Automated email-verification tools are genuinely useful, but only if you understand what each one is actually testing. A syntax validator confirms an address is formatted correctly and nothing more. A DNS or MX lookup confirms a domain can actually receive mail, which catches some fake addresses but says nothing about intent.
- Syntax checks catch typos and malformed addresses, not fraud.
- DNS/MX lookups confirm the domain is configured to receive mail at all.
- SPF/DKIM lookups confirm server authorization and message integrity for that domain specifically.
- Disposable-email detectors flag addresses from temporary mail services, often a sign of throwaway scam infrastructure.
- URL scanners and expanders reveal a shortened link’s real destination, though some log the URLs you submit.
Phishing remains one of the most frequently reported complaint categories tracked by federal investigators, a pattern that holds even as detection tools improve, because scammers adapt their lures faster than any single tool can catch. The practical takeaway: combine automated checks with the manual steps above, and never paste real credentials into an unfamiliar “verification” site to test whether it’s legitimate.
How identity protection, password managers, and dark-web monitoring help after phishing
Even careful readers get caught occasionally, which is why what happens after a click matters as much as spotting the email in the first place. A password manager limits the blast radius of a single stolen credential by keeping every account on a unique password, so one phished login doesn’t unlock the rest of your accounts the way reused passwords do. We built our password manager around that principle, alongside passwordless multi-factor authentication that removes the password as the single point of failure MFA is designed to protect.
If you suspect a credential was exposed, a dark-web scan checks whether that email or password has turned up in known breach data, which is useful confirmation rather than guesswork. We offer dark-web monitoring as part of our identity protection tools, built to flag exposure without promising it can undo a theft already in progress. None of this replaces the verification habits above. It reduces how much a single mistake costs you.
Daily habits that make email detection routine
I treat every unexpected request for money, login details, or urgent action as guilty until proven innocent. That one rule, stop and verify independently before responding, catches more phishing attempts than any tool I use.
Beyond that, I lean on my inbox’s spam filters and “report phishing” button rather than deleting suspicious mail outright, since reporting helps the filter learn and protects the next person who gets the same message. I also keep every account on a unique password through a manager, so a single bad click can’t cascade into a dozen compromised logins.
The balance that works for me: quick triage on everything, deeper header checks only when something still feels wrong after the first pass.
— Mike
An optional layer of protection if a phishing email gets through
Careful verification is still the best defense against fake emails, but no habit catches everything every time. That’s the gap a password manager and identity monitoring are built to cover: unique, randomly generated passwords so one phished login doesn’t compromise every account tied to it, passwordless MFA that removes the password as a single point of failure, and dark-web monitoring that flags exposed credentials before someone else uses them.

Our Premium plan starts free, with paid tiers like Professional at $2.50 a month adding deeper protection if you want it. Try it as a backstop for the verification habits above, not a replacement for them.
FAQ
Can a scammer access my bank account with my email address?
An email address alone usually isn’t enough to access a bank account, but scammers use it as a starting point for phishing attempts that trick you into revealing passwords or one-time codes. The real risk comes from what you click or type in response, not the address itself.
Do spammers know if you open an email?
Many marketing and phishing emails embed tracking pixels that notify the sender when a message is opened, though this varies by email client and whether images load automatically. Disabling automatic image loading in your email settings limits this kind of tracking.
Is this email a phishing email?
Check the full sender address against the official domain, hover over any links to preview their destination, and treat urgent requests for money or login details as a warning sign. If SPF, DKIM, or DMARC checks fail in the message headers, that’s a strong indicator the message is spoofed.
How can I test the validity of an email address?
Run a syntax check to confirm the address is formatted correctly, then a DNS or MX lookup to confirm the domain can actually receive mail. Disposable-email detectors can also flag addresses from temporary mail services, which are common in scam infrastructure.
Sources
- How To Recognize and Avoid Phishing Scams | Consumer Advice (FTC)
- Recognize and Report Phishing | CISA




Password Manager
Identity Theft Protection

Team / Business
Enterprise
MSP

