Check the sender's address carefully, because typos and lookalike domains are the most common way phishing emails fool people

The first thing to do is read the email address itself — not the display name, which anyone can fake. Look at the part after the @ symbol. Scammers often use addresses that look almost right: amaz0n.com instead of amazon.com, or paypa1.com instead of paypal.com. The number zero instead of the letter O, or the number one instead of the letter L, are classic tricks.

If you know the person or company, compare the address to one you have received from them before. If a friend suddenly emails you from a different address, that is a sign their account may have been compromised. If a company you do business with emails you from a domain you do not recognize, do not click links in that email — instead, go to the company's official website directly and log in to check your account.

Pay special attention to the exact spelling of the domain. Gmail.com is real. Gmial.com is not. Paypal.com is real. Paypa1.com (with a one instead of an L) is not. These small differences are deliberate.

Key Takeaways

  • Read the actual email address after the @ symbol, not the display name, because display names can be anything.
  • Compare suspicious emails to previous messages from the same sender to spot domain typos and lookalike addresses.
  • If an email asks you to click a link or log in, go directly to the company's website instead of using the link in the email.
  • Hover over links (without clicking) to see where they actually point before you open them.
  • If you are unsure, contact the sender through a phone number or website you know is real, not through the email itself.

Hover over links to see the real destination

Emails can display one web address as a link but send you somewhere completely different. To see where a link actually goes, hover your mouse over it without clicking. Most email programs will show you the real address in a small popup or at the bottom of the screen.

If the link says "Click here to verify your account" but the real address points to a random website or a misspelled domain, that is a phishing attempt. Legitimate companies link to their own domains. If you see a mismatch, do not click the link.

On a phone, this is harder because you cannot hover. Instead, press and hold the link (on iPhone) or long-press it (on Android) to see the destination. If you cannot see where it goes, or if it looks wrong, do not tap it.

Check the email headers to see where it actually came from

Email headers are the technical information behind every message — they show the servers the email passed through and the actual sender. Most email programs hide headers by default, but you can usually turn them on in settings.

In Gmail, open the email and click the three dots menu, then select "Show original." You will see a lot of technical information. Look for the line that says "From:" — that is the real sender. Look also for "Return-Path:" which shows where bounce-back messages go. If these do not match the email address shown in your inbox, something is wrong.

In Outlook, right-click the email and select "Message Options," then look for "Internet Headers." In Apple Mail, go to the View menu and select "Message" then "All Headers."

Reading headers takes practice, but the key thing to look for is whether the domain in the "From:" line matches what you expect. If an email claims to be from your bank but the header shows it came from a different domain entirely, it is fake.

Use reverse email lookup tools to research unfamiliar addresses

If you receive an email from someone you do not know, you can search for that address online to see if it appears on public websites, social media, or business directories. This does not tell you whether the email is legitimate, but it can tell you whether the address exists and what it is associated with.

Tools like Hunter.io, RocketReach, or a simple Google search can show you whether an email address is tied to a real person or company. If an address claims to be from a major company but does not appear anywhere online, that is suspicious.

Be aware that this method is not foolproof. Scammers can use real email addresses that belong to compromised accounts, or they can use addresses that look real but are brand new. Use this as one piece of information, not the only piece.

Verify unexpected requests by contacting the sender directly

If an email asks you to confirm a password, update payment information, or take urgent action, do not reply to the email or click its links. Instead, contact the sender through a phone number or website you know is real.

If the email claims to be from your bank, call the number on your bank card or go to your bank's website and log in to your account. If it claims to be from a company you do business with, find their phone number on an official invoice or their website. Ask them directly whether they sent the email.

This is the single most reliable way to verify an email, because you are checking with the real organization, not trusting the email itself. It takes a few minutes but catches almost all phishing attempts.

Watch for common phishing red flags in the message itself

Beyond the address and links, the content of the email itself often gives away a scam. Phishing emails often have spelling or grammar mistakes, use generic greetings like "Dear Customer" instead of your name, or create false urgency ("Your account will be closed in 24 hours").

Legitimate companies usually address you by name, use professional language, and do not threaten you into action. If an email from your credit card company says "URGENT: Verify now or lose access," that is almost certainly phishing. Real companies give you time to respond and do not use all-caps threats.

Be suspicious of emails that ask for information a real company would never request by email — passwords, full credit card numbers, or Social Security numbers. Banks and payment companies do not ask for these things via email.

Frequently Asked Questions

Can I trust the display name in an email?

No. The display name (the part that appears before the @ symbol in your inbox) can be anything. Someone can send you an email that says "From: Amazon" but actually comes from a fake address. Always check the actual email address, not the display name.

What should I do if I already clicked a phishing link?

If you clicked a link but did not enter any information, you are probably fine. If you entered a password or payment information, change that password immediately and contact the real company to report the phishing attempt. If the email claimed to be from your bank, call your bank directly.

Is it safe to reply to a suspicious email to ask if it is real?

No. Replying confirms to the scammer that your email address is active and monitored, which makes you a better target for future attacks. Instead, contact the company directly using a phone number or website you know is real.

Do I need special software to check if an email is valid?

No. You can check the sender address, hover over links, and read headers using only your email program. You do not need to download anything. Reverse lookup tools are optional and free, but not necessary for basic verification.

What if the email address looks real but I still think it is fake?

Trust your instinct. If something feels off — the tone is wrong, the request is unusual, or the timing is suspicious — contact the sender through a method you know is real. A few minutes of verification is worth the peace of mind.