Is this email a scam? How to check in under a minute.
Most scam emails are not obvious. They are built to look ordinary, so the old advice
about bad spelling and dodgy logos no longer helps much. What does help is a short,
repeatable check you can run on anything that lands in your inbox. Here it is.
The three-question check
Before you click, reply, or pay, ask:
Who is it really from? Not the display name, the actual address behind it. Read it character by character.
What does it want? A payment, a login, a change of bank details, an urgent favour. The bigger the ask, the more it deserves a pause.
How much is it rushing you? Genuine organisations rarely demand that you act within the hour, or that you keep it quiet.
If any of those feel off, treat the email as suspicious until you have checked.
What to look at more closely
The sender address. A swapped letter, a .co instead of .com, or an extra word added to the domain.
The links. Hover to see where they really go, and never log in through a link. Type the address in yourself instead.
Anything unexpected. An attachment you were not expecting, a request out of the blue, a reply-to that differs from the sender.
The tone. Fear, urgency, secrecy, or a deal too good to check first.
The one move that always works
You do not have to become an expert to stay safe. When something feels off, do not act on
the email. Verify through a channel you already trust: type the website in yourself, or
phone the organisation on a number you already have. It takes a minute, and it beats every
trick in this list.
Want a second opinion? Forward it, free.
Send the email to Sender Registry and we assess the sender, the domain, and what the
wider network already knows about it. No account, no card. You get a plain-English
verdict back.
Look at three things before anything else: who it is really from, what it wants you to do, and how much pressure it applies. A genuine, safe email rarely rushes you, rarely asks you to move money or log in through a link, and comes from an address that matches the organisation exactly. When any of those feel off, treat it as suspicious until you have checked.
The email looks professional and has no spelling mistakes. Does that mean it is safe?
No. Bad spelling and clumsy design used to be reliable warning signs, but scams have got sharper, and many now look flawless. Judge an email by what it asks you to do and where it really comes from, not by how polished it looks.
Is it safe to click a link just to check where it goes?
It is safer not to. A link can lead to a fake login page built to steal your password. If you need to reach an organisation, type its address into your browser yourself, or use a number you already have, rather than following the link.
What is the safest way to check a suspicious email?
Do not act on the email itself. Verify through a channel you already trust: type the website in yourself, or phone the organisation on a number from their official site or a past statement, never the number in the email. If you want a second opinion, forward it to Sender Registry, free, and we will assess it.
Every object in the registry (a sender, a domain, a campaign) moves through five
stages as independent evidence builds:
UNSEENNothing reported yet.
OBSERVEDOne report exists. A single data point, not yet corroborated.
CORROBORATEDA second, independent organisation has reported the same thing.
NETWORK CONFIRMEDFive or more independent organisations agree.
VERIFIEDTen or more independent organisations, the strongest confidence level.
This is deliberately separate from Risk and Confidence. How much of the network agrees
is a different question from how dangerous something looks, or how certain we are.
How Threat DNA works
Every campaign gets scored across 8 axes: infrastructure, domain patterns, message
templates, link behaviour, attachment patterns, target industries, target roles, and
campaign velocity. All plotted as a fingerprint.
Sender Registry compares every campaign's fingerprint against every other campaign's
using cosine similarity: the same technique used to compare documents by meaning, not
just matching words. A high match (we only ever suggest one above 55% similarity) means
two campaigns that look unrelated on the surface may share real infrastructure, even
under completely different domain names.
How the Intelligence Map works
Senders, domains, URLs, attachments, campaigns, brands and suppliers all become nodes
in a shared relationship graph, built from real evidence: a sender using a domain, a
domain appearing in the same report as another domain, a report belonging to a campaign.
On a phone, we deliberately don't force a giant graph onto a small screen. Instead you
get a focused view: the object you're looking at, and everything directly connected to
it, with a tap to move to any of those connections in turn.
How push notifications work
Add Sender Registry to your home screen and turn on notifications from your account -
both free, both take under a minute. From then on, anything urgent (a payment-diversion
campaign, an executive impersonation attempt) reaches you as a real notification on your
lock screen, the same way any other app alerts you.
Every notification is sent end-to-end encrypted directly to your device - nothing is
readable in transit by anyone other than your phone.
How the QR scanner works
Open Verify Before You Act, point your camera at a QR code, and capture it. The image is
decoded and the destination it leads to is checked exactly the same way we already check
a QR code found inside a forwarded email - the same detection, just with your camera as
the front door.
You'll see whether the destination is safe, blocked, or worth a second look, with a plain
explanation either way.
How sharing to Sender Registry works
On Android, once the app is added to your home screen, "Sender Registry" simply appears
as an option in your phone's normal Share menu - the same one you'd use to send a photo
to a friend. Share a suspicious text or link straight in, review it, and submit.
On iPhone, Apple's own software doesn't allow a website to appear in the Share menu
automatically. A short, one-time setup (a free "Shortcut") gets you the same result -
after that one step, it behaves identically on both phones.