Scams9 min readUpdated August 26, 2026
How to Detect Scams in Your Email
A real message and a fake one can look almost identical. Here is exactly where to look, in what order, and what to do when you are still not sure.

A genuine email from your bank and a counterfeit one can look practically identical. The logo will be right. The typeface will be right. The tone will be right. Scammers copy real emails — often by receiving one themselves and editing it.
So “it looked real” is not a failure of judgement. It looked real because somebody worked hard to make it look real. What follows is not about looking harder. It is a procedure, in a fixed order, that works regardless of how convincing the message is.
Step 1 — Ask what the message wants you to do
Skip the design and find the request. Almost every scam email wants one of five things, and recognising the ask is faster than assessing the packaging:
- Click a link to “verify”, “confirm”, or “secure” your account
- Call a phone number printed in the message
- Open an attachment — an invoice, a delivery slip, a receipt
- Send money, or buy gift cards, or move funds “for safety”
- Reply with information — a code, a password, a card number, your date of birth
If a message wants none of those things, it is probably harmless. If it wants one of them urgently, keep reading — the rest of the checks are worth the two minutes.
Step 2 — Check the sender's real address, not the display name
Email shows a display name, which anyone can set to anything. “Amazon Customer Service” is a nickname, not proof. What matters is the actual address behind it.
On a computer, hover over the sender's name or click the small arrow next to it. On a phone, tap the sender's name. You are looking for what comes after the @ symbol, and specifically the last two words before the .com:
service@amazon.com— genuineservice@amazon.security-update.com— not Amazon. The real domain here issecurity-update.com. Amazon is decoration.appleid@icloud-verify-support.net— not Applechase.alerts@gmail.com— no bank sends alerts from a free Gmail address
Step 3 — Look at where the link actually goes
Link text lies. A link can read “www.wellsfargo.com” and lead anywhere at all. To see the truth without clicking:
- On a computer: rest the mouse pointer over the link — without pressing — and the real address appears at the bottom of the window.
- On a phone or tablet: press and hold the link for a second or two. A preview appears showing where it leads. Then choose Cancel.
Apply the same last-two-words check. And be wary of shortened links (bit.ly, tinyurl) in any message about money or accounts — a legitimate bank has no reason to hide its own address.
Step 4 — Notice the pressure
Scams need you to act before you check, so nearly all of them manufacture a reason to hurry. Read the message again and look for the squeeze:
- A deadline measured in hours — “within 24 hours your account will be closed”
- A threat — suspension, legal action, a fine, loss of benefits
- A prize or refund that expires
- An instruction to keep it confidential
- A charge you do not recognise, designed to make you react rather than think
Genuine organisations do write to you about real problems. What they do not do is give you one hour, demand secrecy, or threaten you in the first message.
Step 5 — The details that still give it away
These are weaker signals than the four above — plenty of real email is badly written, and plenty of scam email is now polished — but they are worth a glance:
- A generic greeting. “Dear Customer” or “Dear user” from a company that knows your name.
- Details that are slightly wrong. The last four digits of a card that is not yours. An order for something you did not buy.
- An unexpected attachment. Especially a
.zip,.html, or a document that asks you to “enable content”. - Odd punctuation and spacing, or a sentence that reads as though it was translated.
- A reply-to address that differs from the sender.
Step 6 — Verify independently, then act
If you have any doubt at all, the answer is always the same, and it works every time: go to the company yourself, through a route you already trust, and ask them.
- Type the company's address into your browser yourself, or use your own bookmark
- Use the app on your phone, if you have it
- Call the number on the back of your card, or on a statement that arrived by post
- If there is a genuine problem, it will be waiting for you when you log in normally
Then delete the message and, if your email program offers it, mark it as phishing or junk. That trains your inbox to catch the next one.
A worked example
Here is a message of the kind we are sent several times a week:
From: Amazon Support <support@amazon-account-verify.com>
Subject: Unusual sign-in activity — action requiredDear Customer, we detected a sign-in to your Amazon account from a new device in Ohio. If this was not you, your account will be locked within 24 hours. Verify your identity now to prevent suspension. [Verify My Account]
Working through the procedure, it fails four checks in about forty seconds:
- The ask: click a link to “verify”. One of the five.
- The sender: last two words are
amazon-account-verify.com. Notamazon.com. This is the decisive one on its own. - The pressure: a 24-hour deadline and a threat of suspension.
- The greeting: “Dear Customer” — Amazon knows your first name.
Verdict: scam — do not respond. And note what was never needed to reach that conclusion: no technical skill, and no clicking. Just the order of operations.
What to do if you have already clicked
First: this happens to careful people, and speed matters much more than blame.
- If you entered a password — change it immediately on the real site, and change it anywhere else you used the same one. Turn on two-step verification while you are there.
- If you gave card or bank details — call the number on the back of your card now and tell them. They deal with this daily and can freeze and reissue.
- If you let someone connect to your computer — disconnect it from the internet, then get help before using it again. Remote-access software may still be installed.
- If money has moved — contact your bank immediately; some transfers can still be stopped in the first hours. Then report it at reportfraud.ftc.gov.
- Do not delete the message. It is evidence. Take a photograph of the screen before anything else.
Then call us on (832) 952-7770. We will work through our emergency checklist with you — email first, then passwords, then accounts and active sessions — and we will tell you plainly where a bank, an attorney, or law enforcement needs to take over from us.
Make the checking easy, not heroic
Nobody sustains vigilance forever, and you should not have to. The realistic version of safety is having somewhere to send things — a person, not a habit of suspicion.
Want to know where your own gaps are? , or read Five Ways to Stay Safe Online for the five habits that prevent most of this in the first place.
Written by the Tech Peace team
We wrote this from the questions our clients actually ask. If something here is unclear, or you want to check a specific message you have received, call (832) 952-7770 — we will not charge you to look at one email.

