Reading a Suspicious Email: Addresses, Links, and Attachments

Phishing email has outgrown bad grammar. What to check instead: the real sending address, the true link destination, attachments, and out-of-band verification.

STOPTHESCAM Team5 min read
  • scam recognition
  • phishing
  • prevention

The advice most people carry about phishing email is a decade out of date. Look for typos. Watch for blurry logos. Check whether it says "Dear Customer."

None of that helps anymore. Modern phishing is well written, pixel-accurate, and personalized with details pulled from breach data. Some of it is a forwarded copy of a real email with one link changed.

What has not improved is the underlying structure. An email that wants something from you has to reveal, somewhere, where it actually came from and where it actually goes.

Check the address, not the name

Every email carries two separate pieces of identity: a display name, which the sender types in freely, and an address, which is the account that actually sent it.

Your mail app shows the display name because it is friendlier. That is the vulnerability. Chase Fraud Alerts is a display name. Anyone can set it in thirty seconds.

Tap or hover the sender name to reveal the address underneath, then read the part after the @ the same way you read a link: from the right. alerts@chase.com.security-review.net is not Chase. The owner of that address is security-review.net, and chase.com is a subdomain chosen to fill the space your eye scans first.

Also watch for:

  • Free mail providers. A bank does not email you from @gmail.com.
  • Character swaps. rn in place of m, a digit 1 for a lowercase l, an accented character in a familiar word. Zoom in if a domain looks right but feels wrong.
  • Reply-To differences. Some clients show a different reply address than the sender. If replying would send mail somewhere else entirely, that is deliberate.

An address that fails these checks settles the matter. An address that passes proves less than you would like, because a compromised real account sends real mail from a real domain. That is why the last section of this article exists.

The visible text of a link has no relationship to its destination. www.irs.gov can point anywhere.

On a computer, hover the link and read the destination in the status bar. On a phone, press and hold to preview it. Then read the domain from the first single slash backward, exactly as described in how to read a smishing message, which covers link anatomy in detail.

Two extra cases show up more often in email than in text:

  • Shortened links (bit.ly and similar) hide the destination entirely. In an unexpected message, treat a shortener as a refusal to say where you are going.
  • Redirect chains through a legitimate service. A link may genuinely start at a well-known domain and then bounce through a redirect parameter to somewhere else. If a URL contains another full URL inside it, read the second one.

Our Chrome extension shows a link's real destination when you hover it and analyzes the destination before the page opens, which is the same check performed automatically. Vision is free on the Chrome Web Store.

Attachments: what is dangerous and what is not

Danger comes from what a file can execute, not from how it looks.

Treat as hostile in an unexpected email: .html or .htm attachments, which open a local phishing page that no web filter ever sees; archives such as .zip, .rar, or .iso, which hide their contents from scanners; anything executable, including .exe, .msi, .dmg, .scr, .js, and .lnk.

Treat with caution: Office documents that prompt to "enable content" or "enable macros." That prompt is the attack. A real invoice never needs macros to display.

Usually low risk to view, but not to act on: plain PDFs and images. The common danger with these is not code, it is the phishing link or QR code printed inside, and the QR code is popular precisely because it moves you onto a phone where checking a destination is harder.

The rule that covers all of it: do not open an attachment you were not expecting, no matter who appears to have sent it. If a colleague or family member appears to send a strange file, message them separately and ask. Compromised accounts send mail to their own contact lists first.

The email formats worth recognizing

  • Account verification. Your account will be suspended unless you confirm your details. Real suspensions do not depend on you clicking a link in an email.
  • The invoice you do not recognize. A receipt for a charge you never made, with a phone number to call and dispute it. The number is the scam; calling it starts a phone script. This format works because it turns your alarm into an outbound call, which feels safe because you dialed.
  • The password reset you did not request. Sometimes phishing, sometimes a real signal that someone is trying to break in. Never click the link. Go to the site directly and change the password there.
  • Business payment changes. A supplier, contractor, or title company emails updated banking details. Always verify by phone at a number you already had. This one carries the largest average losses in the United States.
  • Shared document notifications. A file "shared with you" that leads to a fake sign-in page. Check whether you were expecting it, and get to the document through the service's own app rather than the email.

The step that ends the question

Every check above can be defeated by a good enough forgery or a compromised real account. One thing cannot:

Verify through a channel the email does not control.

Call the company at the number on your statement. Open your bank's app rather than the link. Text your colleague. Type the website address by hand. If the email is genuine, thirty seconds are lost. If it is not, the whole thing collapses, because the sender's power ends at the boundary of the message.

Practical hygiene that lowers the volume

  • Never enter credentials on a page you reached from an email. Navigate there yourself, every time. This single habit neutralizes most credential phishing.
  • Use a password manager. Beyond generating unique passwords, it refuses to autofill on a look-alike domain, which makes it a better phishing detector than most people are.
  • Turn on two-factor authentication, preferring an authenticator app or a passkey over text messages.
  • Do not unsubscribe from spam you did not sign up for. For unsolicited mail, that link mostly confirms a live reader. Mark it as junk instead.
  • Report phishing to the Federal Trade Commission at reportfraud.ftc.gov, and forward workplace phishing to your IT team.

The same machine, a different envelope

Unexpected contact, an artificial deadline, a request that routes through a channel the sender controls: this is the same structure described in the seven signals that show up in almost every scam. Email adds attachments and a wider canvas for imitation, but nothing new underneath.

If an email has already led to a payment or a password, work through what to do in the first 24 hours.

  • 6 min read

    Text Message Scams: How to Read a Smishing Message

    Unpaid tolls, held packages, bank alerts, wrong numbers. How to read a scam text, check a link safely, and report it to your carrier in under a minute.

    • scam recognition
    • phishing
    • text scams
    • prevention
  • 5 min read

    Caller ID Is Not Evidence: How Phone Scams Actually Work

    Caller ID can be forged, voices can be cloned, and a familiar number proves nothing. How phone scams are built, and the callback rule that defeats all of them.

    • scam recognition
    • phone scams
    • prevention
    • fundamentals