Skip to main content

Verified technicians, ready to help

(832) 952-7770Call Tech Peace at (832) 952-7770
Tech Peace

Scams9 min readUpdated August 26, 2026

How to Detect Scams in Your Email

A real message and a fake one can look almost identical. Here is exactly where to look, in what order, and what to do when you are still not sure.

An older man leaning close to his laptop screen, reading a message with a concerned expression

A genuine email from your bank and a counterfeit one can look practically identical. The logo will be right. The typeface will be right. The tone will be right. Scammers copy real emails — often by receiving one themselves and editing it.

So “it looked real” is not a failure of judgement. It looked real because somebody worked hard to make it look real. What follows is not about looking harder. It is a procedure, in a fixed order, that works regardless of how convincing the message is.

Step 1 — Ask what the message wants you to do

Skip the design and find the request. Almost every scam email wants one of five things, and recognising the ask is faster than assessing the packaging:

  • Click a link to “verify”, “confirm”, or “secure” your account
  • Call a phone number printed in the message
  • Open an attachment — an invoice, a delivery slip, a receipt
  • Send money, or buy gift cards, or move funds “for safety”
  • Reply with information — a code, a password, a card number, your date of birth

If a message wants none of those things, it is probably harmless. If it wants one of them urgently, keep reading — the rest of the checks are worth the two minutes.

Step 2 — Check the sender's real address, not the display name

Email shows a display name, which anyone can set to anything. “Amazon Customer Service” is a nickname, not proof. What matters is the actual address behind it.

On a computer, hover over the sender's name or click the small arrow next to it. On a phone, tap the sender's name. You are looking for what comes after the @ symbol, and specifically the last two words before the .com:

  • service@amazon.com — genuine
  • service@amazon.security-update.comnot Amazon. The real domain here is security-update.com. Amazon is decoration.
  • appleid@icloud-verify-support.net — not Apple
  • chase.alerts@gmail.com — no bank sends alerts from a free Gmail address

Step 3 — Look at where the link actually goes

Link text lies. A link can read “www.wellsfargo.com” and lead anywhere at all. To see the truth without clicking:

  • On a computer: rest the mouse pointer over the link — without pressing — and the real address appears at the bottom of the window.
  • On a phone or tablet: press and hold the link for a second or two. A preview appears showing where it leads. Then choose Cancel.

Apply the same last-two-words check. And be wary of shortened links (bit.ly, tinyurl) in any message about money or accounts — a legitimate bank has no reason to hide its own address.

Step 4 — Notice the pressure

Scams need you to act before you check, so nearly all of them manufacture a reason to hurry. Read the message again and look for the squeeze:

  • A deadline measured in hours — “within 24 hours your account will be closed”
  • A threat — suspension, legal action, a fine, loss of benefits
  • A prize or refund that expires
  • An instruction to keep it confidential
  • A charge you do not recognise, designed to make you react rather than think

Genuine organisations do write to you about real problems. What they do not do is give you one hour, demand secrecy, or threaten you in the first message.

Step 5 — The details that still give it away

These are weaker signals than the four above — plenty of real email is badly written, and plenty of scam email is now polished — but they are worth a glance:

  • A generic greeting. “Dear Customer” or “Dear user” from a company that knows your name.
  • Details that are slightly wrong. The last four digits of a card that is not yours. An order for something you did not buy.
  • An unexpected attachment. Especially a .zip, .html, or a document that asks you to “enable content”.
  • Odd punctuation and spacing, or a sentence that reads as though it was translated.
  • A reply-to address that differs from the sender.

Step 6 — Verify independently, then act

If you have any doubt at all, the answer is always the same, and it works every time: go to the company yourself, through a route you already trust, and ask them.

  • Type the company's address into your browser yourself, or use your own bookmark
  • Use the app on your phone, if you have it
  • Call the number on the back of your card, or on a statement that arrived by post
  • If there is a genuine problem, it will be waiting for you when you log in normally

Then delete the message and, if your email program offers it, mark it as phishing or junk. That trains your inbox to catch the next one.

A worked example

Here is a message of the kind we are sent several times a week:

From: Amazon Support <support@amazon-account-verify.com>
Subject: Unusual sign-in activity — action required

Dear Customer, we detected a sign-in to your Amazon account from a new device in Ohio. If this was not you, your account will be locked within 24 hours. Verify your identity now to prevent suspension. [Verify My Account]

Working through the procedure, it fails four checks in about forty seconds:

  • The ask: click a link to “verify”. One of the five.
  • The sender: last two words are amazon-account-verify.com. Not amazon.com. This is the decisive one on its own.
  • The pressure: a 24-hour deadline and a threat of suspension.
  • The greeting: “Dear Customer” — Amazon knows your first name.

Verdict: scam — do not respond. And note what was never needed to reach that conclusion: no technical skill, and no clicking. Just the order of operations.

What to do if you have already clicked

First: this happens to careful people, and speed matters much more than blame.

  1. If you entered a password — change it immediately on the real site, and change it anywhere else you used the same one. Turn on two-step verification while you are there.
  2. If you gave card or bank details — call the number on the back of your card now and tell them. They deal with this daily and can freeze and reissue.
  3. If you let someone connect to your computer — disconnect it from the internet, then get help before using it again. Remote-access software may still be installed.
  4. If money has moved — contact your bank immediately; some transfers can still be stopped in the first hours. Then report it at reportfraud.ftc.gov.
  5. Do not delete the message. It is evidence. Take a photograph of the screen before anything else.

Then call us on (832) 952-7770. We will work through our emergency checklist with you — email first, then passwords, then accounts and active sessions — and we will tell you plainly where a bank, an attorney, or law enforcement needs to take over from us.

Make the checking easy, not heroic

Nobody sustains vigilance forever, and you should not have to. The realistic version of safety is having somewhere to send things — a person, not a habit of suspicion.

Want to know where your own gaps are? , or read Five Ways to Stay Safe Online for the five habits that prevent most of this in the first place.

Written by the Tech Peace team

We wrote this from the questions our clients actually ask. If something here is unclear, or you want to check a specific message you have received, call (832) 952-7770 — we will not charge you to look at one email.

How protected are you right now?

Ten plain statements, two minutes, and a Protection Score out of 100 with the specific gaps we spotted. It opens right here — you will not lose this article.

Got a question about this?

Send us the thing you are unsure about

Forward the email, text a photo of the screen, or read it to us over the phone. You get one plain answer — safe, suspicious, or scam. There is no charge for a single check, member or not.

Would rather just talk? Call (832) 952-7770. A real person answers. No phone trees, no hold music.

Monday–Saturday, 8am–8pm (your local time)

Not ready to talk? Find out where you stand first.

Request a free call

Three details and a real person will be in touch within one business day.

This is the fastest way for us to reach you. We never share it.

Who is this for?

No obligation, no sales pressure. We'll never ask for a password or payment on a first call.