How to verify a suspicious e-mail step by step

Photo: Brett Jordan · Unsplash
You do not have to guess about a suspicious e-mail. Most scams can be uncovered in a few minutes if you know where to look. In this guide we go step by step through how to check an e-mail: from the sender through the hidden headers to the links and attachments. And at the end we show how our free phishing e-mail checker, which runs right in your browser, speeds the whole check up.
1. Do not start with a click
The first rule is also the most important: do not click anything in a suspicious message yet. Not a link, not an attachment, not the Unsubscribe button. Check the message first and only then decide. An attack lives or dies on you acting before you start thinking, so give yourself that moment.
2. Look at the real sender
The display name is easy to fake. Type “Post Office” as the name and most people will not check the address. So always look at the real e-mail address behind the name:
- Does the domain after the @ match who claims to be writing? A bank does not write from an address like
@mail-sk-info.com. - Is the reply address (Reply-To) different from the sender? That means replies go to someone else.
- Watch for tiny domain swaps, for example
slsp-sk.cominstead ofslsp.sk.
3. Open the headers: Show original
This is a step most people do not know, yet it reveals the most. Every e-mail carries headers, a hidden part with technical data including the results of origin verification:
- In Gmail, click the three dots by the message and choose Show original.
- In Outlook, open the message and via the menu choose View message source.
In the source, look for the Authentication-Results line and within it SPF, DKIM and DMARC. If you see spf=fail or dkim=fail, the message probably did not come from the domain it claims. That is one of the strongest pieces of evidence of a scam, even if the e-mail looks trustworthy on the surface.
4. Check links before you click them
A link is the most common trap. The link text may show www.slsp.sk but lead somewhere completely different. How to spot it:
- Hover over the link (on a touch device, press and hold) and the real destination appears at the bottom. Compare it with what the link shows.
- Watch for shorteners (bit.ly and the like) that hide the real destination.
- Watch for addresses with an IP number instead of a name (
http://185.20.x.x/...) and for spoofed domains, where the brand appears only as part of another address (slsp.sk.login-xy.ru).
5. Watch the language and attachments
The content of the message tells you a lot too:
- Pressure and urgency (“within 24 hours”, “your account will be closed”) are meant to switch off your common sense.
- A request for a password, PIN or code is almost always a scam. A reputable service does not ask for them by e-mail.
- Unexpected attachments, especially executable files (
.exe,.scr) or double extensions (invoice.pdf.exe), should not be opened.
6. Let a tool do the checking
Our phishing e-mail checker does all these steps in seconds. You paste in the e-mail text, or better its full source (Show original), and the tool evaluates the sender, the SPF/DKIM headers, hidden and spoofed links, pressure language and risky attachments. You get a risk score and a clear list of exactly what is suspicious. It all runs in your browser, so the e-mail content never leaves your device. Treat it as a helper and awareness aid, not a guarantee: when in doubt, do not click anything.
What if you already clicked
It happens even to careful people. If you entered any details, act fast: change your password immediately, contact your bank for payment details, and wherever possible enable two-factor authentication. We also go into it in more detail in how to spot phishing and scam messages.
Not sure? We will look at it with you
If something suspicious arrived or you already clicked a link, get in touch. We will assess the message, help secure your accounts and device, and can train your people to recognise scams. For businesses and homes in the Liptov region.
Help me with a suspicious e-mailSummary
Anyone can verify a suspicious e-mail in a few minutes: do not click right away, look at the real sender address, open the headers and check SPF/DKIM, verify where the links really lead, and watch for pressure and attachments. And if you want it even faster, our phishing e-mail checker evaluates it for you right in your browser. A few seconds of caution save you from lost passwords and money.
This article is part of our Cybersecurity overview.
Frequently asked questions
How quickly can I verify a suspicious e-mail?
What are e-mail headers and how do I show them?
What does it mean when SPF or DKIM fails?
How do I spot a spoofed link?
Is it safe to paste an e-mail into your checker?
What should I do if I already clicked the link?
Need help with IT?
We will take care of your computers, networks and security - for businesses and households in the Liptov region.
Contact us