Free tool · email & phishing safety
Email Scam Checker
Got an email that doesn’t feel right? Phishing emails impersonate banks, retailers, and colleagues to steal your password or your money. Learn how to spot the signs — and paste an email’s sender, subject, and wording below to check it for common phishing tricks.
100% private. This runs entirely in your browser. Nothing you paste is sent anywhere, stored, or shared.
What Is a Phishing Email?
A phishing email is a message built to look like it’s from someone you trust — your bank, a retailer, a delivery company, or even a colleague — so you’ll hand over a password, card details, or money. It’s the most common way scams and account takeovers begin.
The email usually pushes you toward a single action: click a link to a fake login page, open an attachment, or reply with details. It leans on a trusted name and a sense of urgency so you act before you check the sender address or the link.
How to Spot a Phishing Email
No single sign is proof on its own, but the more of these that stack up, the more careful you should be:
Display name vs real address mismatch
The email shows a trusted name — “Amazon”, your bank — but the actual address after the @ is something unrelated. Display names are trivial to fake; the address is what matters.
A free-mail sender posing as a company
Banks, governments, and real companies email you from their own domain — not from gmail.com, outlook.com, or yahoo.com. A “billing department” on a free account is a red flag.
A lookalike domain
The address is almost right but off by a character or two — “security@amaz0n-alerts.com”, “@paypal-support.co”. Read the domain carefully.
Urgency or threats
“Your account will be suspended”, “unusual login detected”, “pay within 24 hours or face a fine”. Pressure is meant to stop you thinking.
Links to fake login pages
A button or link that takes you to a page asking for your password or card details. Hover to see where it really goes — or better, don’t click at all.
Unexpected attachments
Invoices, receipts, or “documents” you weren’t expecting, especially .zip, .html, or files that ask you to “enable content”. These can carry malware.
A generic greeting
“Dear customer”, “Dear user”. A company you actually deal with usually knows your name.
Requests for credentials or payment
Any email asking you to confirm a password, enter card details, or make a payment through its link. Legitimate organisations don’t ask you to do this by email.
Check an Email
Paste the email’s sender, subject, and body and we’ll check them for common phishing signs.
Runs in your browser. Nothing you paste is sent anywhere — the check happens entirely on your device.
Paste the real sender address, not just the display name — you can usually tap the sender’s name at the top of the email to reveal the full address after the @.
Paste a email above to check it
This checks the sender, subject, and wording for common phishing signs — it can't prove an email is genuine. If it asks you to log in or pay, go to the site directly instead of using its links.
If You Clicked or Replied
If you clicked a link, opened an attachment, or replied with details, move fast — the sooner you act, the better your chance of limiting the damage.
- 1
If you entered a password, change it now — and anywhere you reused it — and turn on two-factor authentication.
- 2
If you shared card or bank details, contact your bank or card issuer immediately to freeze, dispute, or recall the payment and have the card reissued. In India, call 1930.
- 3
Report it — here’s who to contact wherever you live. And see how to get your money back after a scam.
Frequently Asked Questions
What does this email checker actually check?
It examines the sender address, the subject, and the wording of the body for common phishing signals — display-name spoofing, free-mail senders posing as companies, lookalike domains, urgency and threats, requests for credentials or payment, and suspicious links.
Is my email sent anywhere?
No. Everything runs entirely in your browser. Nothing you paste — the sender, subject, or body — is transmitted, stored, or logged.
How do I see the real sender address?
Don’t rely on the display name. On a phone, tap the sender’s name at the top of the message to reveal the full address after the @. On a computer, hover over or click the sender name. Paste that real address into the checker, not just the name shown.
It looks fine — is the email definitely safe?
No. This tool catches common phishing signs, but it can’t prove an email is genuine. If a message asks you to log in or pay, go to the organisation’s website directly by typing the address yourself, rather than using any link in the email.
What should I do if I clicked a link or entered my password?
Act fast. Change the password you entered — and anywhere you reused it — and turn on two-factor authentication. If you shared card or bank details, contact your bank to freeze or dispute the payment, then report it. See our guide on getting your money back after a scam, and who to report to wherever you live.
Last reviewed: August 2026
Keep Going
Want to check a link from the email, or browse the rest of our free tools?