This site is privately owned and the information provided is free of charge. Learn more here.
Email addresses follow a basic structure that scammers often try to copy or imitate. Every email has three main parts: the local part (the name before the @), the @ symbol, and the domain name (everything after the @). Legitimate companies and individuals follow standard email formatting rules, but fraudsters frequently make small changes that look almost real at first glance.
Get Your Free Smart TV WiFi Connection Guide →
The domain name is where most fake emails reveal themselves. For example, a real Amazon email comes from amazon.com, but a fake might use amazom.com (with an 'o' instead of an 'a'), amaz0n.com (with a zero instead of the letter 'o'), or amazon-secure.com. These tiny differences are intentional—they exploit the fact that people scan emails quickly without reading carefully.
Professional organizations use consistent email patterns. Banks typically use their official domain name directly in employee emails. If you receive an email claiming to be from your bank but the domain is completely different, that's a red flag. For instance, Chase Bank uses @chase.com addresses, not @chasebanking.co or @secure-chase-login.com.
Many companies also use subdomains, which appear before the main domain name. A legitimate Apple security email might come from security.apple.com, while a fake might use apple.security.net (reversing the order) or security-apple.com (adding a hyphen). The key difference is that the main domain always belongs to the company—the part that comes before the final .com, .org, or country code.
Free email services like Gmail, Yahoo, and Outlook are real services, but scammers use them to impersonate companies. If a company claims to be contacting you from their "official" Gmail account, that's suspicious. Real companies have their own domain names and professional email systems. They rarely contact customers from generic free email providers.
Practical takeaway: When you receive an email from a company, hover over the sender's name (without clicking) to reveal the actual email address. Check that the domain name matches the company's official website. Look for slight misspellings, extra characters, or rearranged words in the domain—these are classic fake email tricks.
Scammers use several proven techniques to create email addresses that look legitimate at a glance. Understanding these methods helps you spot them before you click a link or provide information.
Free Guide to Dental Implant Options in Maple Ridge →
Homograph attacks are among the most common tricks. These use letters that look identical or nearly identical to real letters. The number "1" (one) looks like the letter "l" (lowercase L). The number "0" (zero) looks like the letter "O". The number "5" can resemble the letter "S". A scammer might register paya1.com (with the number one) instead of payal.com, or amaz0n.com (with the number zero) instead of amazon.com. Many people don't notice these differences when reading quickly.
Another technique involves adding extra words or characters to legitimate domains. A scammer might create paypal-secure.com, paypal-verify.com, or verify-paypal-account.com. While these domains contain the real company name, they're not actually owned or controlled by PayPal. The hyphen or added words make the address feel official without being authentic.
Subdomain manipulation is another popular method. A scammer buys a legitimate-sounding domain, then creates fake subdomains. For example, they might own example-security.com and set up mail.paypal@example-security.com or secure.amazon@example-security.com. The fake part comes last, making it harder to spot. The real domain (example-security.com) is what the scammer owns, not PayPal or Amazon.
Some scammers register domains that are completely different but send emails claiming to be from major companies. They rely on the message content and company logos (which are easy to copy) to seem legitimate. A scammer might register newsbriefs.net and send an email with a Bank of America logo, claiming urgent account action is needed.
International domain extensions also create confusion. While .com is standard in the United States, other countries use different extensions (.uk for Britain, .de for Germany, .ca for Canada). Scammers sometimes use these different extensions to create fake versions of American companies. For instance, amazon.co.uk is real and legitimate, but amazon.uk (without the .co) is not an official Amazon domain.
Practical takeaway: Always verify the exact domain by checking the company's official website directly. Type the company name into your browser's address bar yourself rather than clicking links in emails. Once you're on the real website, look for official contact information. Compare any email address you receive to the official contact details shown on the genuine website.
Email headers contain hidden information that reveals where an email truly originated. While most email programs don't show this information by default, learning to access and read it provides strong evidence of fake emails. Headers include routing information, timestamps, and authentication details that scammers cannot easily fake.
Get Your Free Guide to Texas Workforce Commission Contact Information →
In Gmail, you can view headers by opening an email, clicking the three-dot menu button, and selecting "Show original." In Outlook, right-click the email and choose "Message Options," then look for "Internet Headers." Different email providers have slightly different methods, but all allow access to this information. Once you view the headers, you're looking at the complete journey the email took from sender to your inbox.
The "Return-Path" field shows where bounce-back messages are sent if the email cannot be delivered. If this doesn't match the claimed sender's company, the email is likely fake. Similarly, the "Received" lines show each mail server the message passed through. If these servers don't match the company's official infrastructure, someone else sent the email.
Authentication protocols like SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance) verify that emails truly come from the company they claim to represent. If an email fails these checks, your email provider should flag it as suspicious or send it to spam. Some email clients display authentication results as a small icon or note. A failed authentication is strong evidence that an email is fraudulent.
The "Message-ID" field contains a unique identifier created when the email was sent. Legitimate companies use proper formatting for these identifiers, while spoofed emails sometimes show obviously fake or malformed versions. The "Date" field can also reveal problems—if an email claims to be from today but the timestamp shows it was sent weeks ago, something is wrong.
Looking at the complete sender information (not just the display name) in headers reveals the reality. An email might display "Amazon Customer Service <support@amazon.com>" in your inbox, but headers show it actually came from "support@totally-different-domain.net." The display name is easy to fake, but the actual email address in headers is much harder to manipulate.
Practical takeaway: If you suspect an email is fake, view the headers and look for the "Return-Path" and topmost "Received" fields. These should match the company's official domain. If you don't recognize the domains listed, the email likely didn't come from the company it claims to represent. You can also use online header analysis tools to interpret technical information if the details seem confusing.
Beyond the email address itself, fraudulent emails often contain warning signs in their content and appearance. Scammers typically rush their work or use templates that don't perfectly match real company communications. Learning these patterns helps you recognize fakes even before checking the email address.
Free Guide to San Bernardino DMV Services and Hours →
Urgent or threatening language is a major red flag. Legitimate companies rarely pressure customers with messages like "Your account will be closed in 24 hours" or "Verify your information immediately." Banks and major retailers typically give customers reasonable timeframes to respond to genuine security issues. They also tend to use calm, professional language. Scammer emails frequently use all-caps words, multiple exclamation marks, or phrases designed to trigger panic and bypass your careful thinking.
Generic greetings are another common problem. Real companies usually address you by name when they have your account information. If an email says "Dear Customer" or "
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.