Email Security

How to Tell If an Email Is Fake: 12 Phishing Red Flags

Security magnifying glass inspecting a fraudulent email message with highlighted red flags
On this page
  1. Why Criminals Send Fake Emails
  2. 12 Red Flags: How to Spot a Fake Email
  3. How to Identify Fake Emails: Quick Verification Reference
  4. How to Safely Verify a Suspicious Email
  5. What to Do If You Clicked a Suspicious Link
  6. Stay Vigilant and Guard Your Inbox

To tell if an email is fake, examine the sender's actual email address behind the display name, look for artificial urgency demanding immediate action, and inspect embedded links without clicking them. Scammers use forged branding and alarming stories to manipulate your emotions, but technical discrepancies in domain names and URLs often expose a fake email. Checking these details takes only a few seconds and prevents identity theft, financial loss, and account takeover.

Why Criminals Send Fake Emails

Phishing remains the most common entry point for online fraud, account theft, and ransomware. Criminals rely on social engineering rather than breaking complex encryption because exploiting human trust is cheap, fast, and scalable. By imitating reputable banks, shipping couriers, tech platforms, and government agencies, attackers trick recipients into handing over login credentials, credit card numbers, or corporate network access.

Understanding phishing email signs allows you to spot deception before any harm occurs. While basic junk mail is harmlessly annoying, deceptive emails aim to extract sensitive data or silently install malware on your computer or phone.

12 Red Flags: How to Spot a Fake Email

Attackers frequently update their tactics, but their underlying methods remain remarkably consistent. Here are the twelve most common warning signs to watch for whenever an unexpected message lands in your inbox.

1. Mismatched Sender Display Name and Domain

Anyone can configure their email client to show a friendly display name like "PayPal Security" or "Amazon Customer Support." The real indicator of identity is the address inside the angle brackets after the display name. If an email claims to come from Netflix but originates from an address like support@netflix-account-update-alert.biz, the message is fraudulent.

2. Subtle Typosquatting in Domain Names

Sophisticated attackers register domains that look nearly identical to legitimate brand names. They replace letters with numbers or visually similar characters, such as swapping a lowercase "l" for a numeral "1", or an "m" for "rn". Look closely at the domain structure: micros0ft.com or arnazon.com are designed to fool a casual glance.

3. Extreme Urgency and Coercive Language

Phishing attacks rely heavily on panic to bypass logical reasoning. Common subject lines warn that your account will be suspended within 24 hours, an unauthorized purchase of hundreds of dollars was just charged, or legal action is pending. If an email demands that you act immediately to avoid catastrophe, treat it as suspicious.

4. Generic Greetings and Missing Account Details

Companies you do business with usually address you by your full name or account username. Scammers blast identical templates to thousands of stolen addresses, resulting in greetings like "Dear Customer," "Valued Member," or simply "Dear" followed by your email prefix. While some legitimate newsletters use generic salutations, sensitive account alerts from banks and major platforms rarely do.

5. Hidden or Mismatched Hyperlinks

The text displayed in an email link can say anything the sender wants, including a completely legitimate web address like https://www.apple.com. However, the underlying hyperlink may point to an entirely different, malicious server. Hover your mouse cursor over the link—without clicking—to reveal the true destination URL in your browser or email status bar. On a mobile phone, long-press the link to preview the target address.

6. Requests for Personal Credentials or Sensitive Data

Reputable banks, tech companies, and retailers will never send an unprompted email asking you to verify your password, PIN, Social Security number, or full credit card details. Any message asking you to confirm security information via an email reply or an external form is almost certainly an attack.

7. Unexpected or Suspicious Attachments

Malware distribution often relies on malicious email attachments disguised as routine business files. Be deeply suspicious of unsolicited attachments ending in .zip, .iso, .exe, .scr, or macro-enabled documents like .docm and .xlsm. Even standard PDF and Word files can harbor exploits designed to compromise unpatched software.

8. Inconsistent Branding, Layout, and Grammar

While generative artificial intelligence has reduced obvious spelling mistakes, fake emails often display subtle design flaws. Look for outdated corporate logos, awkward formatting, distorted graphics, or unnatural phrasing. If an email from your local utility provider reads like an awkward machine translation, proceed with caution.

9. Invoices or Receipts for Things You Never Ordered

A classic trick involves sending an invoice for an expensive smartphone, software subscription, or computer that you did not purchase. The email lists a "support number" or an "order cancellation" link intended to panic you into calling or clicking. Learn more about specific retail scams in our guide to what a fake Amazon email looks like.

10. Unsolicited Offers That Seem Too Good to Be True

Messages promising surprise lottery winnings, unexpected inheritance distributions, job offers requiring no interview, or cryptocurrency giveaways are always fraudulent. If an offer sounds extraordinarily generous and came out of nowhere, it is a lure designed to separate you from your money or personal identity details.

11. Unusual Requests From Trusted Contacts

Sometimes a fake email appears to come from your boss, a colleague, or a friend whose account has been compromised or spoofed. These messages often request an urgent purchase of gift cards, a wire transfer to a new vendor bank account, or confidential company spreadsheets. Whenever a regular contact makes an atypical financial or credential request, verify it through a completely different communication channel.

12. Vague or Missing Contact Information

Legitimate organizations provide clear physical addresses, verified telephone numbers, legal disclaimers, and working customer service links in their email footers. Phishing emails often have blank footers, broken unsubscribe links, or arbitrary strings of junk characters inserted at the bottom to evade automated spam filters.

How to Identify Fake Emails: Quick Verification Reference

Use this summary table to quickly evaluate whether a suspicious message is authentic or fraudulent.

Verification CheckLegitimate EmailFake or Phishing Email
Sender AddressOfficial root domain (e.g., @chase.com)Lookalike domain, free webmail (@gmail.com), or unrelated domain
GreetingYour registered name or customer ID"Dear user", "Dear customer", or blank
Tone & UrgencyInformative, calm, standard business toneAggressive deadlines, legal threats, panic inducement
LinksDirect links to official corporate domainShortened links (bit.ly), typosquatted domains, IP addresses
Action RequestedPrompts login through established app/siteDemands password entry, remote access, or gift cards
AttachmentsExpected reports or requested documentationUnsolicited archives (.zip), macros, or executable files

How to Safely Verify a Suspicious Email

If you receive a message that triggers your suspicions, never use the links or phone numbers provided within the email itself. Here is how to confirm the truth without exposing yourself to danger:

  1. Go directly to the source: Open a clean browser window, type the official website address directly into your address bar, and log into your account dashboard. If there is a genuine security issue or billing problem, an alert will appear in your account message center.
  2. Call using a verified number: If the email claims to come from your bank or a government agency, use the phone number printed on the back of your physical payment card or on official monthly statements.
  3. Inspect technical email headers: Mail clients receive underlying routing metadata with every message. You can inspect the originating server IP address and authentication checks by following our tutorial on how to read email headers.
  4. Check email authentication standards: Major email services like Gmail, Outlook, and Apple Mail automatically check protocols like SPF, DKIM, and DMARC. When an incoming message fails these checks, modern mail providers often flag it with a prominent warning banner or push it directly into the spam folder.

Privacy Tip: You can minimize your exposure to phishing and credential stuffing by keeping your primary email address private. When signing up for new apps, forum accounts, or public downloads, use a free temporary email from FakeEmail.net. If a marketing site suffers a breach or shares its list with spammers, your real mailbox remains clean and safe.

Mistakes happen. If you accidentally clicked a link or downloaded a file from an email you now suspect is fake, act quickly to contain any potential damage.

Step 1: Disconnect From the Network

If you downloaded and opened an unexpected file, immediately disconnect your device from Wi-Fi or unplug your Ethernet cable. This prevents potential malware from contacting command-and-control servers or spreading across your local home or office network.

Step 2: Change Compromised Passwords Immediately

If you entered your login credentials on a suspicious page, open a separate, secure device and change the password for that account immediately. If you reuse that same password across other services, change those passwords as well and ensure each account has a unique, complex passphrase managed by a reputable password manager.

Step 3: Enable Multi-Factor Authentication (MFA)

Turn on two-factor or multi-factor authentication across all critical accounts, especially your email, banking, and primary shopping platforms. Prioritize hardware security keys or authenticator apps over SMS codes whenever available.

Step 4: Run a Full Antivirus and Anti-Malware Scan

Scan your device with updated security software to ensure no background keyloggers, Trojans, or unauthorized browser extensions were installed during the incident.

Step 5: Alert Your Bank and Credit Bureaus

If you submitted debit or credit card details, contact your bank immediately to freeze the compromised card and dispute any unauthorized transactions. If sensitive identity numbers were exposed, consider placing a temporary credit freeze with national credit reporting agencies.

Step 6: Report the Incident

Reporting phishing helps security teams take down malicious infrastructure before other people fall victim. You can report fraudulent emails to organizations like the Cybersecurity and Infrastructure Security Agency (CISA) or the Federal Trade Commission (FTC). For comprehensive instructions on alerting mailbox providers and law enforcement, read our detailed guide on how to report phishing and fake emails.

Stay Vigilant and Guard Your Inbox

Cybercriminals rely on haste and distraction. By treating unexpected emails with healthy skepticism, verifying sender domains carefully, and refusing to click unverified links, you can neutralize almost every phishing attempt. When signing up for casual web services, using a disposable inbox helps keep your primary address off the radar of data brokers and scammers entirely.

Frequently asked questions

Can opening a fake email infect my computer?

Simply opening and reading a text email in a modern webmail client or updated email app will rarely infect your device. The primary danger occurs when you click embedded links, download and run malicious attachments, or enable interactive macro content.

Why do phishing emails often have spelling mistakes?

Some errors are deliberate filters designed by scammers to weed out observant users, ensuring that only the most credulous recipients respond. Other times, the mistakes simply stem from foreign attackers working across language barriers or rushing out high-volume campaigns.

How can I tell if an email from my bank is authentic?

Never click links or call numbers contained within the email. Instead, open a fresh browser tab, navigate directly to your bank's verified URL, and log in to inspect your secure account message center.

Can an attacker fake the exact 'From' address?

Yes, older email protocols allow basic address spoofing, but modern protections like SPF, DKIM, and DMARC make spoofing major brand domains difficult. When scammers cannot spoof an exact domain, they rely on display name spoofing or subtle lookalike typosquatted domains.

What should I do if an email claims I owe money for an invoice?

Do not reply, click links, or call the phone number listed on the invoice. Check your actual bank or card accounts independently to verify whether any charge was processed, and contact the retailer through their official portal if necessary.

Need a disposable address right now? Get one free in a single click — no sign-up.

Get a temp email

A tech enthusiast and content strategist tracking the pulse of digital transformation, AI, and emerging tools. He specializes in breaking down complex innovations into actionable, reader-friendly insights. When he is not writing, you will likely find him testing new productivity apps over a fresh cup of coffee.

Written with AI assistance and checked against our editorial standards. Editorial Policy

Keep reading