7 Tips for Recognizing Scam Emails Before You Open Them

[Signup for our free weekly newsletter to learn about the latest scams and tips to stay safe!]

We can significantly reduce our risks from email threats if we learn a few easy clues that reveal that an email is a fraud or highly suspicious. However, once we open a malicious email, for example, our risks increase significantly and we must be very careful. Did you know that if you hold your mouse over the sender’s email name in your inbox, BUT DO NOT CLICK IT, in a few seconds your email program will likely produce a popup showing your more detail about the the sender’s email address! Below are several more valuable tips and tricks you can do to more easily identify and delete malicious emails and spam before you open them!

1. Is the Sender’s email address or the domain used in it an odd string of characters? (The domain name in an email always appears after the @ symbol)

Spammers and scammers often use software to generate thousands of emails at a time.  These programs sometimes dump in random strings of characters when they create the fake sender’s address. Check out this string of email addresses that hit an email server in just a few minutes:

Or how about this very brief email from “Robot Puppy” about a robot puppy toy?   The domain name that sent this email “toubskl[.]info” is very odd, but the name infront of the “@” symbol is really bizarre!  a.6eipm5 and should make everyone suspicious!

2.    Sender’s email address has a name before it that doesn’t match the name in the email address

Email programs very typically display the owner’s full name in front of the owner’s email address. Here are two legitimate examples:

“Joe Turnip <joeseph.turnip@yahoo.com>”
“Janey Smith <jsmith@mycompany.com>”

Spammers/Scammers often mismatch names. Sometimes they do this because they are misusing a hacked email account, or are trying to trick you by putting something into the text field that appears before the email address.  In this first example, notice that the sender’s namne in the text field says “Camie Bauer,” but the email address that follows it shows a different name and string of numbers: ferlandchahst778268! Also, this supposed Paypal invoice was sent from a free Gmail account!

In this second example, the name in front of the email address is “Joshua (blurred last name).” But the name in front of the actual email “@” symbol is bongik. Trust us, this is NOT Joshua’s last name!

3. Sender’s email address contains a 2-letter country code!

We have an excellent short video that explains 2-letter country codes in detail and the importance of recognizing them. If you see an email address that ends in a period followed by 2 letters, these 2 letters refer to a country where the email originated. Some are easy to figure out such as br (Brazil), hu (Hungary) or in (India) while others are not so straight forward… es (Spain = España), de (Germany = Deutschland) or hr (Croatia) For a detailed list of country codes, visit this Wikipedia article.

Now look at the email screenshot just above from Joshua. If you look find the  “@” symbol and then look all the way to the right end of it, you’ll see the 2 letters “za.”  (Not “co” because “co” is not at the very end of the email!)  DOT-za is the 2-letter country code for South Africa! If you get an email from a country and you don’t expect it to come from that country, or have no connection to, or no interest to that country, you can make a decision to delete it before you open it!

4. The email seems to have been sent from you to you!

This may sound a bit strange but it is actually a very common trick used by cybercriminals. They will often put YOUR NAME into the text field that appears in front of an email address! So if you see an email that looks like it came from you to you, and you know you didn’t send it to yourself, then delete it!

5. Sender’s email address contains a variation of your name

Another common trick used by spammers and scammers is to create a “From” address that actually uses variations of your own name. Again, the idea is to raise your curiosity enough to get you to open the email. Check out these examples of my username…
(Also, notice the 3 different country codes in some of those emails in the screenshot below! UK = United Kingdom, AR=Argentina RO=Romania)

6.  Sender’s email doesn’t match the expected source of the email

The final tip we can offer is actually a little common sense when you think about it. If you receive an email, for example, that says it is from “Social Security” you would expect to see the actual address within the < > brackets ending in the domain ssa.gov, NOT “godsellcc[.]com”

 

7. There is no visible “From” email address

If the sender’s email address is completely missing in the “From” section then it was hidden on purpose. Just delete it!

Finally, as long as you don’t click a link or attachment, don’t be afraid to open an email if you feel that you need to. But always keep a healthy does of skepticism as you read your emails!