Resources / Email Scam Checker

Is this email a scam?

Paste a suspicious email below. This free email scam checker reads the sender's address for spoofing tells, flags the red flags phishing emails rely on, and explains the tactic behind each one. Use it as a quick phishing email checker or scam email checker whenever you're asking "is this email legit?" — no signup, and nothing is uploaded.

🔒 Checked entirely in your browser — the email is never uploaded
Tip: paste the full sender — display name and the address in angle brackets. The mismatch between the two is often the clearest tell. Leave blank if you only have the body.
Try an example:
Paste the email first — the subject line and a few sentences is enough.

This is a pattern-based checker, not a verdict from your email provider or IT team. A clean result does not guarantee an email is safe — new phishing appears daily, and the most targeted attacks avoid common tells. When in doubt, contact the company or person directly using a website or number you already have, never one from the email. Already clicked, entered a password, or paid? Use our what-to-do-now tool.

Got a suspicious text instead? Run it through our free SMS scam checker

Want deeper checks? This free tool runs entirely in your browser, so it only sees what you paste. The email checks included with paid Family plans go further: forward any suspicious email to your ScamDrill address and our servers also expand shortened and redirected links to reveal the real destination, flag links to newly registered domains, and check the sender's SPF, DKIM, and DMARC authentication to catch a forged From line the text alone can't.

Real scam email examples (and the tell in each)

These are the patterns behind the emails most people paste into the checker. Learn the one tell in each and you’ll catch the next one without any tool.

“Microsoft 365: Your password expires today. Re-verify now to keep access to your account: micros0ft-verify.com”

🚩 Why it’s a scam: Hover the link before clicking — the domain isn’t microsoft.com (note the zero in “micros0ft”). Real password changes happen inside your account settings, never through an emailed link with a deadline.

“Re: Outstanding invoice #4471 — kindly process the wire today. Updated bank details attached.” (from accounts@yourvendor-billing.com)

🚩 Why it’s a scam: Check the sender’s domain character by character. Business email compromise uses look-alike domains (an added word like “-billing,” or “rn” for “m”) plus urgency to redirect a real payment. Verify new bank details by calling a number you already have.

“Amazon: We couldn’t ship your order because your payment was declined. Confirm your card details to release it: [link]”

🚩 Why it’s a scam: Retailers don’t ask you to re-enter card details through an email link. Go to the retailer’s site or app directly — the “declined payment” is bait to capture your card.

“I know your password is ******. I installed malware and recorded you. Send $1,900 in Bitcoin within 48 hours or I send the video to your contacts.”

🚩 Why it’s a scam: The password was leaked in an old data breach and reused to scare you — there is no video. It’s a mass-sent bluff. Don’t pay; change any password you reused and turn on two-factor authentication.

“Congratulations! You’ve been selected for a remote data-entry position at $35/hr. To onboard, send your bank details for direct deposit and a refundable $200 equipment deposit.”

🚩 Why it’s a scam: No real employer hires without an interview or asks you to pay for equipment. The “refundable deposit” and the request for bank details up front are the theft.

Next time, spot it without a checker.

ScamDrill sends safe practice emails and texts to your family so the instincts are there before the real phishing arrives. Paid plans also include forward-an-email verdicts with link expansion, new-domain detection, and sender-authentication checks built in. Free plan available — and you've just seen exactly which tactics need practice.

Start practicing free →
Protecting a team instead? ScamDrill for organizations runs phishing drills company-wide.

Get a heads-up before the next scam reaches you

Join our free newsletter — monthly scam-trend updates and practical tips to protect yourself and the people you care about. No spam, unsubscribe anytime.

We'll only use your email to send scam alerts. See our privacy policy.

Email scam questions, answered

How can I tell if an email is a scam?
Read the real sender address, not just the display name — scammers fake the name freely, but the address often gives them away (a free Gmail, a lookalike like chase-secure.info, or a Reply-To that points somewhere else). Watch for urgency, threats, account-problem pretexts, requests for passwords or codes, unexpected attachments, and links that don't go to the company's real website. The checker above scores an email against these patterns instantly. For a deeper walkthrough, see how to spot common scams.
Is it safe to paste my email into this checker?
Yes. The analysis runs entirely in your browser — nothing you paste is uploaded to a server. We still suggest removing personal information before pasting, but the email never leaves your device.
What's the difference between phishing and a scam email?
Phishing is a scam email built to steal your login or personal details, usually by sending you to a fake login page. Other scam emails want you to pay (fake invoices, subscription-renewal scams), buy gift cards (business email compromise), or hand over money (lottery, romance, inheritance). The checker flags all of these and names the likely type. The scam glossary defines the terms.
I clicked a link or entered my password — what now?
Change that password immediately from a device you trust and turn on two-factor authentication. If you entered banking or card details, call your bank. If you paid, report it. Our what-to-do-now tool gives you the exact steps for your situation.
Does a clean result mean the email is safe?
No. A clean result means none of the common scam patterns matched — but targeted attacks are written to look legitimate. Always verify any request to click, pay, open an attachment, or share information through a channel you already trust.