How to Check If an Email Is a Scam (2026) — EmailLeaked
Guides

How to Check If an Email Is a Scam (2026)

How to check if an email is a scam: read the real sender and link, never the logo. Free steps to catch phishing after a data breach. Updated August 2026.

On this page

To check if an email is a scam, ignore the logo and read the real From address and every hidden link. If the message wants a password, code, or payment on a deadline, do not use its buttons — open the real site from a bookmark. Last updated: August 2026.

Phishing works because it looks like the last legitimate email you got from that company. The check is mechanical: sender, links, ask. You can do it in under a minute.

APWG and similar industry trackers have counted hundreds of thousands of phishing sites in active quarters through 2024–2025. As of 2026, more than 12 billion stolen credentials are also in known breach datasets, which is why the email can include your name, old password hints, or a service you actually use.

How do you check if an email is a scam step by step?

  1. Read the From address, not the display name. “PayPal” can sit on service@random-domain.net.
  2. Preview links without clicking. Hover or long-press. See how to check if a link is safe.
  3. Name the ask. Password, one-time code, gift card, wire, remote access — those are the payload.
  4. Check the clock. “Act in 15 minutes or your account closes” is a script.
  5. If you still need the real company, go around the email. Type the domain or use the app you already installed.

Paste any URL into the website checker before you open it.

What sender tricks do scam emails use?

  • Lookalike domains (rn for m, extra hyphens).
  • Free inboxes pretending to be “security@” a brand.
  • Compromised real accounts — your colleague’s address sending a weird invoice.

You cannot authenticate a company from a logo in the header. You can authenticate a domain you type yourself.

What should you never do with a suspicious email?

  • Do not enter passwords on pages the email opened.
  • Do not read out a one-time code to anyone who called you.
  • Do not install remote-support software because a pop-up said so.
  • Do not “confirm your identity” by sending a photo of your ID to an address in the thread.

If the story is a package, open the carrier’s site from a bookmark and check tracking there. If the story is a bank, use the app or the number on your card.

Check the link, not the logo: Paste the URL →

Why do breach victims get better phishing?

Because the list is better. After incidents like LinkedIn or other large dumps, inboxes that actually exist get more “reset your password” mail. That is not proof you were hacked today. It is proof your address is valuable.

Check whether your email is in a known breach →

If a password was exposed, follow what to do if your password was leaked. Attackers try that password on email next — that is credential stuffing.

What should you do if you already interacted with a scam email?

  • Clicked only: close, delete, no password change required unless you typed one.
  • Typed a password: change it on the real site, unique password, 2FA, password leak check, and the password reuse change checklist.
  • Sent money: call the bank or the payment provider the same day.
  • Gave a code: assume the attacker used it; lock the account from a device you trust.

Then scan the inbox for other messages from the same campaign. One phish is rarely alone. If a leak started this, finish with what to do after a data breach and 2FA and passkeys after a breach.

Marketers and criminals both use the same inboxes. After you delete a campaign, search for the brand name plus “verify” or “urgent” in the same week. Real companies rarely send three countdown emails in one afternoon.

If you use a shared family computer, sign out of webmail on that browser after you clean up. Leftover sessions are how a clicked page becomes a second login later.

When is an email probably legitimate?

When you expected it (a receipt for an order you placed), the From domain matches the company, the links go to that same domain, and it does not demand a surprise login. Even then, prefer the bookmark for anything involving money or passwords.

For a full after-incident list, use what to do after a data breach. For how those addresses get on lists in the first place, read how hackers get your email.

Frequently asked questions

How do I check if an email is a scam?
Ignore the display name and logo. Open the real From address, preview every link without clicking, and look for urgency plus a request for a password, code, or payment. Paste any URL into a link checker. If anything is off, delete the message and log in from a bookmark instead.
Can a scam email come from a real company’s address?
Display names are easy to fake. The underlying From address is harder, but not impossible if an account was compromised. Always read the full sender, not the friendly name. When in doubt, do not use the email’s buttons — open the real site yourself.
What is the biggest sign an email is phishing?
A surprise login, payment, or one-time-code request combined with a deadline. Real banks and shops let you sign in from their homepage without a ten-minute countdown. The second sign is a link whose real domain does not match the brand.
Should I reply to ask if the email is real?
No. Replying confirms your address is active. Do not call numbers in the email either. Use a phone number from the company’s official site or the back of your card.
I already clicked a link in a scam email. What now?
Close the page. If you typed a password, change it on the real site, turn on two-factor authentication, and check whether that password or your email appears in known leak data. If you did not type anything, you are usually fine — just delete the message.
Why am I getting more phishing after a data breach?
Leaked addresses are sold and reused. Attackers know the inbox works. Checking whether your email appeared in a known breach tells you why the volume jumped, and which passwords to rotate if a password was exposed too.

Founder and editor of EmailLeaked. A software and web developer, he built the site's breach checker and its no-storage privacy model, and writes its plain-English guides for people who need a straight answer about a leak — not a data dump. LinkedIn

Our editorial standards →
Breach education

Read the data breach guide

Learn how breaches happen, how stolen data is used, and how to check your exposure.

Open the hub

Get monthly breach alerts — free

One email per month. Biggest breaches, what was exposed, what to do. No spam.

No spam · Unsubscribe anytime · Your email is never shared

Find out where you stand.

Check which breaches include your email — free, instant, never stored.

Check my email — free
No signup · Under 2 seconds · Never stored