Phishing emails are designed to appear as though they came from a person or organization you trust. Attackers may copy a company’s logo, colors, writing style, and email layout. However, one important detail can expose the deception: the sender’s actual email address.
Checking that address should be one of the first things you do before clicking a link, opening an attachment, replying, or providing information.
The Display Name Can Be Misleading
Most email programs prominently display a sender’s name, such as:
- Your Bank
- Microsoft Support
- Amazon Billing
- Company Payroll
Unfortunately, the sender can usually choose almost any display name. An attacker could enter “Your Bank” even though the message was sent from an unrelated address.
The name alone does not prove who sent the email. You must reveal and inspect the complete email address behind it.
How to Reveal the Full Address
The exact steps vary between email programs, but you can normally reveal the complete address by:
- Clicking or tapping the sender’s name.
- Selecting a small arrow beside the sender.
- Opening the message details.
- Hovering your mouse pointer over the sender’s name on a computer.
Do not click any links inside the message while checking the sender.
After revealing the address, read it carefully from beginning to end. On a phone, the screen may shorten a long address, so open the sender details if the entire address is not visible.
Understand the Parts of an Email Address
An email address contains a username, the @ symbol, and a domain:
support@example.com
In this example:
supportis the username.example.comis the domain.
The domain is especially important because it identifies the email system that sent or authorized the message.
An attacker might create an address such as:
amazon-support@example.com
The word “amazon” appears in the username, but the actual domain is still example.com. The address does not belong to Amazon.
Always focus on what appears after the @ symbol.
Watch for Lookalike Domains
Phishing addresses often use domains that resemble legitimate ones. Attackers may:
- Add an extra letter.
- Remove a letter.
- Replace a letter with a similar-looking character.
- Insert words such as “secure,” “billing,” or “support.”
- Add extra words before the real ending of the domain.
- Use an unfamiliar domain ending.
For example, an attacker could register a domain that looks similar to a well-known company’s domain when read quickly.
Be especially careful with addresses containing long strings of words. In an address such as:
security@company.example.com.attacker.example
the real controlling domain is at the end—not the familiar company name near the beginning.
Compare It with a Trusted Source
If you are uncertain, do not use contact information provided in the suspicious email.
Instead, compare the sender’s domain with one obtained independently from:
- The organization’s official website.
- A previous message you know is genuine.
- A saved contact created from a trusted source.
- A bank card, statement, invoice, or other official document.
- A company directory.
- A phone number you already know is legitimate.
Type the organization’s web address yourself or use a trusted bookmark. Do not reach the official website by following a link in the questionable message.
If the email appears to come from a coworker, friend, or family member, contact that person through a different method. A phone call or a new message sent to a known address is safer than replying directly.
Check the Reply-To Address
Some messages use one address in the From field but direct replies to a different Reply-To address.
A different Reply-To address is not automatically malicious. Businesses sometimes use separate systems to send and receive email. However, an unexpected or unrelated Reply-To domain is a reason to investigate further.
Your email program may reveal the Reply-To address in the message details or full header information.
Advanced Check: Review Authentication Results
Email headers may contain authentication results for technologies called SPF, DKIM, and DMARC. These systems help receiving mail services determine whether a server was authorized to send mail for a domain and whether parts of the message were altered.
Depending on your email provider, these results may appear under options such as:
- View message details
- Show original
- View source
- View headers
- View security details
Results showing a failure can be a strong warning. However, a passing result does not guarantee that the message is safe. A criminal can send authenticated email from a domain they own, and a legitimate account could also be compromised.
Email authentication is useful evidence, but it should not replace careful judgment.
A Matching Address Is Not Proof of Safety
A familiar address lowers suspicion, but it does not prove that a message is legitimate. Attackers may compromise real email accounts or manipulate visible sender information.
Continue to be cautious if a message:
- Creates extreme urgency or fear.
- Requests a password or verification code.
- Asks for payment, gift cards, or financial information.
- Includes an unexpected attachment.
- Directs you to sign in through a link.
- Changes familiar payment instructions.
- Makes an unusual request that does not sound like the sender.
When an important request is unexpected, verify it through a separate, trusted communication channel.
A Quick Sender-Address Checklist
Before trusting an email, ask:
- Did I reveal the complete sender address?
- Does the domain after the
@symbol belong to the claimed sender? - Are any letters missing, added, or replaced?
- Is the address unusually long or confusing?
- Does the Reply-To address point somewhere different?
- Can I confirm the address through an independent source?
- Does the message contain any other warning signs?
Checking an email address only takes a few seconds, but it can prevent stolen passwords, malware infections, fraudulent payments, and identity theft. Make it a habit to inspect the sender before acting—especially when an email requests money, credentials, sensitive information, or immediate action.
