How to Check Whether an Email Is Suspicious

How to check whether an email is suspicious — quick answer

Start by checking who actually sent the message, what it asks you to do, and whether it contains unexpected attachments or links. Look for mismatched sender details, urgent or unusual requests for money or credentials, poor spelling or logos that look off. Verify by hovering over links, viewing the full message headers, contacting the sender using a known phone number or separate email, and do not reply or click until you confirm the message is legitimate.

Fast checklist: the three-minute triage

Step-by-step process to analyze a suspicious email

  1. Pause. Do not click or reply. A single click can activate tracking pixels or malicious sites.
  2. Check the visible sender details. Look at the email address behind the display name. Many scams use a genuine-looking name with a mismatched address.
  3. Hover over links and inspect destinations. Move your cursor over any link (without clicking) to see the URL preview. If it points to an unrelated domain or a URL-shortening service you do not trust, do not click.
  4. Inspect attachments safely. Avoid opening executables, script files, or compressed archives from unknown senders. If you must examine an attachment, scan it with up-to-date antivirus software or ask the sender to share via a trusted file service.
  5. Read the raw headers. The full header can reveal the actual sending server and path. If you are unsure how to read headers, follow this Read headers guide to identify spoofing or forged paths.
  6. Verify through a different channel. Send a new message to a known address or call the organization using a phone number from their official website, not a number listed in the suspicious email.
  7. Report and remove. If the message is clearly malicious, report it to your email provider or employer and follow your policies to delete or quarantine the message. For public guidance on reporting, see how to Report phishing.

How to hover and inspect links safely

Hover the pointer over each link and read the full destination that appears. Copy the link address without visiting it and paste it into a text editor to inspect. Shortened URLs (for example, bit.ly) can hide the real destination; expand them with a preview service before trusting them. If a link claims to be a bank but the domain is not the bank's official domain, treat it as suspicious.

Handling attachments without risk

Email header analysis: what to look for

Message headers show the route an email took. Look for these practical signals:

If you need help interpreting header fields, consult the Read headers resource for step-by-step guidance and example fields to compare.

Worked example: walk-through of a suspicious invoice email

Imagine you receive an email titled "Outstanding Invoice" from a vendor you use. Here is how to check it.

  1. Look at the sender. The display name is "Acme Supplies" but the email is acme.billing123@gmail.com. That mismatch suggests fraud.
  2. Open the message without clicking links. The body uses a generic greeting, poor grammar, and pushes for immediate payment to a new bank account. Those are standard red flags.
  3. Hover over the invoice link. The URL preview goes to a different domain, not acmesupplies.com. Do not click.
  4. Request confirmation. Use the phone number you already have for Acme or log into their official portal and ask whether they issued an invoice. Do not use contact details provided in the suspicious email.
  5. If the vendor confirms they did not send it, report the message using formal channels and delete it.

Common mistakes people make when judging email safety

After you confirm an email is malicious: practical next steps

Take immediate steps to limit damage and protect others:

  1. Report the message to your email provider and your IT or security team if you have one. See how to Report phishing for common channels and advice.
  2. If you clicked a link or opened an attachment, run a full antivirus scan and change relevant passwords from a clean device.
  3. Enable or re-check multi-factor authentication on important accounts — resources on Secure accounts explain how this reduces account takeover risk.
  4. Inform colleagues who might receive similar messages so they can watch for the same campaign.

Closing: err on the side of caution

Suspicious emails often look just plausible enough to make you act quickly. The most reliable defenses are simple: pause, inspect addresses and links, verify through a separate channel, and report confirmed scams. Keep recovery steps handy and teach colleagues the same process so your whole team responds consistently and safely.