Suspicious email

Is this email a scam? How to check in under a minute.

Most scam emails are not obvious. They are built to look ordinary, so the old advice about bad spelling and dodgy logos no longer helps much. What does help is a short, repeatable check you can run on anything that lands in your inbox. Here it is.

The three-question check

Before you click, reply, or pay, ask:

  • Who is it really from? Not the display name, the actual address behind it. Read it character by character.
  • What does it want? A payment, a login, a change of bank details, an urgent favour. The bigger the ask, the more it deserves a pause.
  • How much is it rushing you? Genuine organisations rarely demand that you act within the hour, or that you keep it quiet.

If any of those feel off, treat the email as suspicious until you have checked.

What to look at more closely

  • The sender address. A swapped letter, a .co instead of .com, or an extra word added to the domain.
  • The links. Hover to see where they really go, and never log in through a link. Type the address in yourself instead.
  • Anything unexpected. An attachment you were not expecting, a request out of the blue, a reply-to that differs from the sender.
  • The tone. Fear, urgency, secrecy, or a deal too good to check first.

The one move that always works

You do not have to become an expert to stay safe. When something feels off, do not act on the email. Verify through a channel you already trust: type the website in yourself, or phone the organisation on a number you already have. It takes a minute, and it beats every trick in this list.

Want a second opinion? Forward it, free.

Send the email to Sender Registry and we assess the sender, the domain, and what the wider network already knows about it. No account, no card. You get a plain-English verdict back.

Or analyse the email yourself, free →

Common questions

How can I tell if an email is a scam?

Look at three things before anything else: who it is really from, what it wants you to do, and how much pressure it applies. A genuine, safe email rarely rushes you, rarely asks you to move money or log in through a link, and comes from an address that matches the organisation exactly. When any of those feel off, treat it as suspicious until you have checked.

The email looks professional and has no spelling mistakes. Does that mean it is safe?

No. Bad spelling and clumsy design used to be reliable warning signs, but scams have got sharper, and many now look flawless. Judge an email by what it asks you to do and where it really comes from, not by how polished it looks.

Is it safe to click a link just to check where it goes?

It is safer not to. A link can lead to a fake login page built to steal your password. If you need to reach an organisation, type its address into your browser yourself, or use a number you already have, rather than following the link.

What is the safest way to check a suspicious email?

Do not act on the email itself. Verify through a channel you already trust: type the website in yourself, or phone the organisation on a number from their official site or a past statement, never the number in the email. If you want a second opinion, forward it to Sender Registry, free, and we will assess it.

For the full guide: how to spot a phishing email →