The sender name in an email is simply text the sender types themselves. It can say anything: “Support Team”, the name of your bank, the name of your colleague. That is not the thing to check.
Look at the real sender address, and look at where the link goes. Both take seconds and need no expertise.
Step one: the real address
Mail clients show the name and hide the address behind it. Tap or click the sender name and the full address unfolds.
Look at the part after the @ and read it right to left, as with a link. If a mail “from your bank” arrives from support@bank-security-team.com, the domain is bank-security-team.com and it has nothing to do with the bank.
Step two: where the links go
Hover and the real address appears in the status bar. On a phone, a long press does the same. The link text may say anything, including the correct address.
After that it is the ordinary domain check: what exactly to look at in an address.
Attachments
| Type | Risk | What to do |
|---|---|---|
| Executable files | High — they run with your privileges | Do not open; nobody sends these by email |
| Password-protected archives | High — the password exists to bypass scanning | Do not open |
| Documents with macros | High — a macro is a program | Open in view mode, never enable macros |
| Medium — usually just a link inside | Open in the browser, check links inside | |
| Images | Low | But they confirm the message was read |
| A cloud link | Medium — a login form instead of a file | Check the domain of the page you land on |
Signs visible without checking
- Urgency. “Your account will be blocked within a day”, “confirm within the hour”.
- No name. “Dear customer” from a service that knows what you are called.
- An email you were not expecting. A receipt for a purchase you never made is bait to make you click “dispute”.
- A request to enter a password via a link. Real services ask you to sign in yourself.
- Small inconsistencies. An old logo, odd line breaks, mixed fonts.
If a password has already been entered through a link, see what to do after a leak. For how fake pages are built, see phishing.