How to Check Whether an Email Is Suspicious
How to check whether an email is suspicious — quick answer
Start by checking who actually sent the message, what it asks you to do, and whether it contains unexpected attachments or links. Look for mismatched sender details, urgent or unusual requests for money or credentials, poor spelling or logos that look off. Verify by hovering over links, viewing the full message headers, contacting the sender using a known phone number or separate email, and do not reply or click until you confirm the message is legitimate.
Fast checklist: the three-minute triage
- Confirm the sender address: does the domain match the organization you expect?
- Watch the ask: is it requesting credentials, payments, or urgent action you did not expect?
- Inspect attachments and links before opening: unknown file types and shortened URLs are red flags.
- Look for odd language, fake logos, or greetings that don't match how the sender normally writes.
- When in doubt, verify via a separate channel (phone call, separate email) and do not reply directly.
Step-by-step process to analyze a suspicious email
- Pause. Do not click or reply. A single click can activate tracking pixels or malicious sites.
- Check the visible sender details. Look at the email address behind the display name. Many scams use a genuine-looking name with a mismatched address.
- Hover over links and inspect destinations. Move your cursor over any link (without clicking) to see the URL preview. If it points to an unrelated domain or a URL-shortening service you do not trust, do not click.
- Inspect attachments safely. Avoid opening executables, script files, or compressed archives from unknown senders. If you must examine an attachment, scan it with up-to-date antivirus software or ask the sender to share via a trusted file service.
- Read the raw headers. The full header can reveal the actual sending server and path. If you are unsure how to read headers, follow this Read headers guide to identify spoofing or forged paths.
- Verify through a different channel. Send a new message to a known address or call the organization using a phone number from their official website, not a number listed in the suspicious email.
- Report and remove. If the message is clearly malicious, report it to your email provider or employer and follow your policies to delete or quarantine the message. For public guidance on reporting, see how to Report phishing.
How to hover and inspect links safely
Hover the pointer over each link and read the full destination that appears. Copy the link address without visiting it and paste it into a text editor to inspect. Shortened URLs (for example, bit.ly) can hide the real destination; expand them with a preview service before trusting them. If a link claims to be a bank but the domain is not the bank's official domain, treat it as suspicious.
Handling attachments without risk
- Never open .exe, .scr, or .bat attachments that arrive unexpectedly.
- Be cautious with compressed files (.zip, .rar) that contain documents; attackers use them to bypass filters.
- Use antivirus scanning, sandboxed viewers, or request the document be shared through an authenticated cloud folder.
Email header analysis: what to look for
Message headers show the route an email took. Look for these practical signals:
- Discrepancies between the visible 'From' and the originating domain in Received lines.
- SPF, DKIM, or DMARC results if your client or service exposes them — a failing result can indicate forgery, although absence of a pass does not always mean fraud.
- Unexpected originating IP addresses or servers located in countries unrelated to the sender organization.
If you need help interpreting header fields, consult the Read headers resource for step-by-step guidance and example fields to compare.
Worked example: walk-through of a suspicious invoice email
Imagine you receive an email titled "Outstanding Invoice" from a vendor you use. Here is how to check it.
- Look at the sender. The display name is "Acme Supplies" but the email is acme.billing123@gmail.com. That mismatch suggests fraud.
- Open the message without clicking links. The body uses a generic greeting, poor grammar, and pushes for immediate payment to a new bank account. Those are standard red flags.
- Hover over the invoice link. The URL preview goes to a different domain, not acmesupplies.com. Do not click.
- Request confirmation. Use the phone number you already have for Acme or log into their official portal and ask whether they issued an invoice. Do not use contact details provided in the suspicious email.
- If the vendor confirms they did not send it, report the message using formal channels and delete it.
Common mistakes people make when judging email safety
- Trusting a familiar logo or layout. Attackers copy branding precisely.
- Assuming a message is safe because it passes a spell-check — social engineering often uses simple language to seem legitimate.
- Replying to the message to "ask a question." Replying can confirm your address and encourage further malicious contact.
- Using a password reset or link from the message itself instead of logging into the service directly through a bookmark or official site.
After you confirm an email is malicious: practical next steps
Take immediate steps to limit damage and protect others:
- Report the message to your email provider and your IT or security team if you have one. See how to Report phishing for common channels and advice.
- If you clicked a link or opened an attachment, run a full antivirus scan and change relevant passwords from a clean device.
- Enable or re-check multi-factor authentication on important accounts — resources on Secure accounts explain how this reduces account takeover risk.
- Inform colleagues who might receive similar messages so they can watch for the same campaign.
Closing: err on the side of caution
Suspicious emails often look just plausible enough to make you act quickly. The most reliable defenses are simple: pause, inspect addresses and links, verify through a separate channel, and report confirmed scams. Keep recovery steps handy and teach colleagues the same process so your whole team responds consistently and safely.