How to check an email

Protection

A sender name is freely faked and the real address hides behind it. What to look at, and in what order.

The sender name in an email is simply text the sender types themselves. It can say anything: “Support Team”, the name of your bank, the name of your colleague. That is not the thing to check.

2steps
Is all it takes to filter out most fake emails

Look at the real sender address, and look at where the link goes. Both take seconds and need no expertise.

Step one: the real address

Mail clients show the name and hide the address behind it. Tap or click the sender name and the full address unfolds.

Look at the part after the @ and read it right to left, as with a link. If a mail “from your bank” arrives from support@bank-security-team.com, the domain is bank-security-team.com and it has nothing to do with the bank.

Step two: where the links go

Hover and the real address appears in the status bar. On a phone, a long press does the same. The link text may say anything, including the correct address.

After that it is the ordinary domain check: what exactly to look at in an address.

Attachments

TypeRiskWhat to do
Executable filesHigh — they run with your privilegesDo not open; nobody sends these by email
Password-protected archivesHigh — the password exists to bypass scanningDo not open
Documents with macrosHigh — a macro is a programOpen in view mode, never enable macros
PDFMedium — usually just a link insideOpen in the browser, check links inside
ImagesLowBut they confirm the message was read
A cloud linkMedium — a login form instead of a fileCheck the domain of the page you land on
Lists of extensions change; the principle does not. Dangerous is whatever can execute, and whatever asks for a password.

Signs visible without checking

  • Urgency. “Your account will be blocked within a day”, “confirm within the hour”.
  • No name. “Dear customer” from a service that knows what you are called.
  • An email you were not expecting. A receipt for a purchase you never made is bait to make you click “dispute”.
  • A request to enter a password via a link. Real services ask you to sign in yourself.
  • Small inconsistencies. An old logo, odd line breaks, mixed fonts.

If a password has already been entered through a link, see what to do after a leak. For how fake pages are built, see phishing.

Copied