Free tool · phishing signals
Scam email checker
Enter the sender's address from a suspicious email. The scam email checker shows the warning signs it finds, from look-alike brand domains to a Reply-To that leads somewhere else, and explains each one. Signals, not a verdict.
The scam email checker looks at who a suspicious email claims to come from: the sender’s address and the domain behind it. It checks whether the domain imitates a known brand, whether it’s a free webmail or throwaway address, whether it exists and can receive mail, when it was registered, and whether it publishes SPF and DMARC. Paste the email headers too, and it also reads the Reply-To address, the display name and the SPF, DKIM and DMARC results your provider recorded. Each finding comes with a plain explanation, because none of them alone proves a scam.
Signals the phishing email checker looks for
| Signal | What the checker does | What it means |
|---|---|---|
| Address format | Checks the address against the syntax rules | A malformed address can’t be a real company mailbox. |
| Look-alike domain | Compares the domain with about 230 official domains of brands that phishing often imitates | examp1e.com, example-security.com or example are built to be mistaken for the real thing. The real domain and its subdomains are never flagged. |
| Free webmail | Checks the domain against our list of free email providers | Anyone can open such an account. A bank or shop writing from one is a red flag. |
| Disposable domain | Checks against our list of disposable email domains | Throwaway inboxes don’t belong to businesses. |
| Mail server (MX) | Looks up the domain’s MX records | No MX record or no domain at all: replies can’t arrive. See the MX lookup for details. |
| SPF and DMARC | Reads the domain’s SPF and DMARC records | Shows whether the domain owner protects it against forgery. A scammer’s own domain can have both, so this is context, not proof. |
| Domain age | Asks the domain registry for the registration date (RDAP) | A domain registered days ago has no history. If the registry doesn’t answer, the checker says so. |
| Brand in the name | Looks for brand names in the display name and before the @ | "Example Bank Security" <alerts@example uses a name the domain doesn’t back up. |
| Reply-To, authentication results (with headers) | Reuses the email header analyzer | Replies going to another domain, a display name hiding another address, and failed DMARC are typical signs of spoofing. |
The checks run in your browser. The domain name (never the full address or the headers) goes to Cloudflare’s public DNS-over-HTTPS resolver for MX, SPF and DMARC, and to rdap.org for the registration date. To find out whether a mailbox exists at all, use the free check for is this a real email address.
Common scam email patterns
Look-alike domains
The scammer registers a domain that reads like the brand at a glance:
- Swapped characters:
1forl,0foro,rnform, or letters from another alphabet that look identical. A Cyrillic “а” makespаypal.coma different domain frompaypal.com; in the DNS it’s written asxn--pypal-4ve.com. The checker decodes such names and shows both forms. - Typos: a letter added, dropped or swapped, like
amazom.com. - Extra words: the brand plus “security”, “support”, “login” or “delivery”, like
brand-account-verify.com. - The brand in front of another domain: in
paypal.com.account-check.example, the domain that counts is the end,account-check.example. Whoever owns it can put any text in front.
Display-name spoofing
Most mail apps show the sender’s name and hide the address. A message from "PayPal" <billing@example.net> shows up as “PayPal” in the inbox. A name that contains an address, such as "service@paypal.com" <billing@example.net>, goes one step further. Open the sender details in your mail app to see the real address, or paste the headers into the checker.
Reply-To switch
The From address is real or looks real, but the Reply-To header sends your answer elsewhere. Fake invoices and payment requests can work this way, because the scammer needs your answer, not a click. Before you answer an unusual request, check where the reply would go.
Free webmail posing as a company
paypal.service.team@gmail.com is a Gmail account like any other; the brand before the @ means nothing. The checker flags brand names in front of free webmail domains.
Real accounts, false stories
When a supplier’s or colleague’s mailbox is hacked, scam mail comes from a genuine address and passes SPF, DKIM and DMARC. No sender check catches that. Watch for changed bank details, unusual urgency and requests to keep things confidential, and confirm by phone using a number you already have.
Official sender domains of big brands
The look-alike check compares the sender with the official domains of about 175 brands that phishing often imitates: banks and payment services, online shops, parcel carriers, streaming and social platforms, mobile carriers and tax authorities. A few examples:
| Brand | Official domains on the list |
|---|---|
| PayPal | paypal.com, paypal.co.uk, paypal.de |
| Amazon | amazon.com, amazon.co.uk, amazon.de and other country domains |
| Microsoft | microsoft.com, outlook.com, hotmail.com, live.com, office.com and others |
| Meta | facebook.com, facebookmail.com, meta.com |
| Apple | apple.com, icloud.com, me.com |
| UPS, USPS, FedEx, DHL | ups.com, usps.com, fedex.com, dhl.com |
Subdomains belong to the owner of the domain, so mail.instagram.com or accountprotection.microsoft.com are as official as the main domain. Brands also own more domains than any list holds, which is why a match on “same name, different ending” (like example.co for example.com) is a point to check rather than a warning. And an official domain in the From line only proves something if DMARC passed: without that check, the From address can be forged. Your provider records the result in the Authentication-Results header; the email header analyzer shows it, and what is a DMARC record explains how domain owners publish their policy.
What to do with a suspicious email
- Don’t click, don’t reply, don’t open attachments. If the message might be real, go to the company’s website or app by typing the address yourself.
- Report it to your mail provider. In Gmail on a computer: open the message, click More next to Reply, then Report phishing (Google’s help page).
- Forward it to the Anti-Phishing Working Group at
reportphishing@apwg.org. APWG asks you to use “Forward as attachment” if your mail app has it (APWG’s reporting page). - Report fraud to the authorities. In the US at ReportFraud.ftc.gov, as the FTC recommends; in the UK, forward suspicious emails to
report@phishing.gov.uk(NCSC). - If you already clicked or typed a password: change that password and any account that uses the same one, turn on two-factor authentication, and call your bank if you entered card or account details.
Then delete the message.
Frequently asked questions
How can I check if an email is a scam?
How do I know if an email is really from a company?
Can I find out who sent an email?
Is an email from a real company domain always safe?
Email validation API
Validate emails in your app
emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.
/v1/info Email validation API Read the documentation
100 free validations every month. No credit card required.
GET https://api.emailvalidation.io/v1/info?
{
"email": "support@emailvalidation.io",
"user": "support",
"tag": "",
"domain": "emailvalidation.io",
"format_valid": true,
"mx_found": true,
"smtp_check": true,
"catch_all": null,
"role": true,
"disposable": false,
"free": false,
"score": 0.64,
"state": "deliverable",
"reason": "valid_mailbox",
"did_you_mean": ""
}