Free tool · phishing signals

Scam email checker

Enter the sender's address from a suspicious email. The scam email checker shows the warning signs it finds, from look-alike brand domains to a Reply-To that leads somewhere else, and explains each one. Signals, not a verdict.

Copy it from the email, with the name if you like: PayPal Service <service@example.net>

Add the email headers (optional, more signals)

Runs in your browser. To check the domain, its name (never the full address or the headers) goes to Cloudflare's public DNS resolver and to rdap.org for the registration date.

The scam email checker looks at who a suspicious email claims to come from: the sender’s address and the domain behind it. It checks whether the domain imitates a known brand, whether it’s a free webmail or throwaway address, whether it exists and can receive mail, when it was registered, and whether it publishes SPF and DMARC. Paste the email headers too, and it also reads the Reply-To address, the display name and the SPF, DKIM and DMARC results your provider recorded. Each finding comes with a plain explanation, because none of them alone proves a scam.

Signals the phishing email checker looks for

SignalWhat the checker doesWhat it means
Address formatChecks the address against the syntax rulesA malformed address can’t be a real company mailbox.
Look-alike domainCompares the domain with about 230 official domains of brands that phishing often imitatesexamp1e.com, example-security.com or example.com.verify.example.net are built to be mistaken for the real thing. The real domain and its subdomains are never flagged.
Free webmailChecks the domain against our list of free email providersAnyone can open such an account. A bank or shop writing from one is a red flag.
Disposable domainChecks against our list of disposable email domainsThrowaway inboxes don’t belong to businesses.
Mail server (MX)Looks up the domain’s MX recordsNo MX record or no domain at all: replies can’t arrive. See the MX lookup for details.
SPF and DMARCReads the domain’s SPF and DMARC recordsShows whether the domain owner protects it against forgery. A scammer’s own domain can have both, so this is context, not proof.
Domain ageAsks the domain registry for the registration date (RDAP)A domain registered days ago has no history. If the registry doesn’t answer, the checker says so.
Brand in the nameLooks for brand names in the display name and before the @"Example Bank Security" <alerts@example.net> uses a name the domain doesn’t back up.
Reply-To, authentication results (with headers)Reuses the email header analyzerReplies going to another domain, a display name hiding another address, and failed DMARC are typical signs of spoofing.

The checks run in your browser. The domain name (never the full address or the headers) goes to Cloudflare’s public DNS-over-HTTPS resolver for MX, SPF and DMARC, and to rdap.org for the registration date. To find out whether a mailbox exists at all, use the free check for is this a real email address.

Common scam email patterns

Look-alike domains

The scammer registers a domain that reads like the brand at a glance:

  • Swapped characters: 1 for l, 0 for o, rn for m, or letters from another alphabet that look identical. A Cyrillic “а” makes pаypal.com a different domain from paypal.com; in the DNS it’s written as xn--pypal-4ve.com. The checker decodes such names and shows both forms.
  • Typos: a letter added, dropped or swapped, like amazom.com.
  • Extra words: the brand plus “security”, “support”, “login” or “delivery”, like brand-account-verify.com.
  • The brand in front of another domain: in paypal.com.account-check.example, the domain that counts is the end, account-check.example. Whoever owns it can put any text in front.

Display-name spoofing

Most mail apps show the sender’s name and hide the address. A message from "PayPal" <billing@example.net> shows up as “PayPal” in the inbox. A name that contains an address, such as "service@paypal.com" <billing@example.net>, goes one step further. Open the sender details in your mail app to see the real address, or paste the headers into the checker.

Reply-To switch

The From address is real or looks real, but the Reply-To header sends your answer elsewhere. Fake invoices and payment requests can work this way, because the scammer needs your answer, not a click. Before you answer an unusual request, check where the reply would go.

Free webmail posing as a company

paypal.service.team@gmail.com is a Gmail account like any other; the brand before the @ means nothing. The checker flags brand names in front of free webmail domains.

Real accounts, false stories

When a supplier’s or colleague’s mailbox is hacked, scam mail comes from a genuine address and passes SPF, DKIM and DMARC. No sender check catches that. Watch for changed bank details, unusual urgency and requests to keep things confidential, and confirm by phone using a number you already have.

Official sender domains of big brands

The look-alike check compares the sender with the official domains of about 175 brands that phishing often imitates: banks and payment services, online shops, parcel carriers, streaming and social platforms, mobile carriers and tax authorities. A few examples:

BrandOfficial domains on the list
PayPalpaypal.com, paypal.co.uk, paypal.de
Amazonamazon.com, amazon.co.uk, amazon.de and other country domains
Microsoftmicrosoft.com, outlook.com, hotmail.com, live.com, office.com and others
Metafacebook.com, facebookmail.com, meta.com
Appleapple.com, icloud.com, me.com
UPS, USPS, FedEx, DHLups.com, usps.com, fedex.com, dhl.com

Subdomains belong to the owner of the domain, so mail.instagram.com or accountprotection.microsoft.com are as official as the main domain. Brands also own more domains than any list holds, which is why a match on “same name, different ending” (like example.co for example.com) is a point to check rather than a warning. And an official domain in the From line only proves something if DMARC passed: without that check, the From address can be forged. Your provider records the result in the Authentication-Results header; the email header analyzer shows it, and what is a DMARC record explains how domain owners publish their policy.

What to do with a suspicious email

  1. Don’t click, don’t reply, don’t open attachments. If the message might be real, go to the company’s website or app by typing the address yourself.
  2. Report it to your mail provider. In Gmail on a computer: open the message, click More next to Reply, then Report phishing (Google’s help page).
  3. Forward it to the Anti-Phishing Working Group at reportphishing@apwg.org. APWG asks you to use “Forward as attachment” if your mail app has it (APWG’s reporting page).
  4. Report fraud to the authorities. In the US at ReportFraud.ftc.gov, as the FTC recommends; in the UK, forward suspicious emails to report@phishing.gov.uk (NCSC).
  5. If you already clicked or typed a password: change that password and any account that uses the same one, turn on two-factor authentication, and call your bank if you entered card or account details.

Then delete the message.

Frequently asked questions

How can I check if an email is a scam?

Look at the sender's real address, not just the name: enter it in the scam email checker above. A domain that imitates a brand, a free webmail or disposable address for a company, a domain registered days ago, or a Reply-To on another domain are warning signs. Then check what the email wants: urgent payment, a login link or an attachment you didn't expect are the classic scam requests.

How do I know if an email is really from a company?

The domain after the @ must be the company's own domain or a subdomain of it, like mail.example.com for example.com. Then open the full headers: the topmost Authentication-Results line should show dmarc=pass for that domain. The email header analyzer reads it for you. If in doubt, contact the company through its website or app, never through the links in the email.

Can I find out who sent an email?

You can find out which domain and which mail server sent it: the headers show the sending server's IP address and whether SPF, DKIM and DMARC passed for the sender's domain. They don't reveal the person behind a free webmail account or a scammer's own domain. Report the email to your provider and, if money or data is at stake, to the authorities.

Is an email from a real company domain always safe?

No. A real domain proves the message came from that company's systems only if DMARC passed. Even then, a hacked account or a compromised mailing tool can send scams from a genuine address. Treat unexpected requests for money, passwords or codes with suspicion whatever the sender.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Free email tools

Start using our email validation software today!

Get 100 validations per month for free