To check if an email is a scam, ignore the logo and read the real From address and every hidden link. If the message wants a password, code, or payment on a deadline, do not use its buttons — open the real site from a bookmark. Last updated: August 2026.
Phishing works because it looks like the last legitimate email you got from that company. The check is mechanical: sender, links, ask. You can do it in under a minute.
APWG and similar industry trackers have counted hundreds of thousands of phishing sites in active quarters through 2024–2025. As of 2026, more than 12 billion stolen credentials are also in known breach datasets, which is why the email can include your name, old password hints, or a service you actually use.
How do you check if an email is a scam step by step?
- Read the From address, not the display name. “PayPal” can sit on
service@random-domain.net. - Preview links without clicking. Hover or long-press. See how to check if a link is safe.
- Name the ask. Password, one-time code, gift card, wire, remote access — those are the payload.
- Check the clock. “Act in 15 minutes or your account closes” is a script.
- If you still need the real company, go around the email. Type the domain or use the app you already installed.
Paste any URL into the website checker before you open it.
What sender tricks do scam emails use?
- Lookalike domains (
rnform, extra hyphens). - Free inboxes pretending to be “security@” a brand.
- Compromised real accounts — your colleague’s address sending a weird invoice.
You cannot authenticate a company from a logo in the header. You can authenticate a domain you type yourself.
What should you never do with a suspicious email?
- Do not enter passwords on pages the email opened.
- Do not read out a one-time code to anyone who called you.
- Do not install remote-support software because a pop-up said so.
- Do not “confirm your identity” by sending a photo of your ID to an address in the thread.
If the story is a package, open the carrier’s site from a bookmark and check tracking there. If the story is a bank, use the app or the number on your card.
Check the link, not the logo: Paste the URL →
Why do breach victims get better phishing?
Because the list is better. After incidents like LinkedIn or other large dumps, inboxes that actually exist get more “reset your password” mail. That is not proof you were hacked today. It is proof your address is valuable.
Check whether your email is in a known breach →
If a password was exposed, follow what to do if your password was leaked. Attackers try that password on email next — that is credential stuffing.
What should you do if you already interacted with a scam email?
- Clicked only: close, delete, no password change required unless you typed one.
- Typed a password: change it on the real site, unique password, 2FA, password leak check, and the password reuse change checklist.
- Sent money: call the bank or the payment provider the same day.
- Gave a code: assume the attacker used it; lock the account from a device you trust.
Then scan the inbox for other messages from the same campaign. One phish is rarely alone. If a leak started this, finish with what to do after a data breach and 2FA and passkeys after a breach.
Marketers and criminals both use the same inboxes. After you delete a campaign, search for the brand name plus “verify” or “urgent” in the same week. Real companies rarely send three countdown emails in one afternoon.
If you use a shared family computer, sign out of webmail on that browser after you clean up. Leftover sessions are how a clicked page becomes a second login later.
When is an email probably legitimate?
When you expected it (a receipt for an order you placed), the From domain matches the company, the links go to that same domain, and it does not demand a surprise login. Even then, prefer the bookmark for anything involving money or passwords.
For a full after-incident list, use what to do after a data breach. For how those addresses get on lists in the first place, read how hackers get your email.