Webindays

Article

Is That Email Legit? Here’s How to Tell in 30 Seconds

You open your inbox and something feels off. Here's the fast, simple way to tell if that email is legit or a scam before you click anything.

August 22, 2026 · 5 min read
Is That Email Legit? Here’s How to Tell in 30 Seconds
🕐 5 min read

You open your inbox and there it is. “Your account will be suspended in 24 hours.” Or “Dear valued customer, we noticed unusual activity.” Your stomach drops a little. Is this real? Should you click? Should you panic?

Take a breath. Most of the time, that gut feeling of “something’s off” is right. You just need to know what to look for so you can trust it.

I get asked about this a lot, not just by clients but by family too (hi, Dad). So let’s break it down the easy way, no tech degree required.

AI Doesn't search the way Google used to

The First Clue: Who's Actually Sending This?

Here’s the thing scammers count on: you looking at the name, not the actual email address. “Amazon Support” sounds official right there in your inbox. But tap or hover on it, and the real address might be something like [email protected]. See that zero instead of an “o”? That’s the trick.

Real companies send from their real domain. Every time. If PayPal is emailing you, it’s coming from @paypal.com, not @paypal-secure-alerts.com or some other lookalike. So before you do anything else, check who’s really talking to you.

Words That Should Make You Suspicious

Scam emails have a “voice” of their own, and once you know it, you’ll spot it fast. Watch for:

  • The generic greeting. “Dear Customer” or “Dear valued user” instead of your actual name. Real businesses that have your info usually know your name.
  • The panic button. Lines like “immediate action required” or “your account will be closed” are built to make you click before you think.
  • The weird phrasing. Odd grammar, random capital letters, or sentences that just sound a little… off. Real companies proofread. Scammers, often working fast and from templates, don’t always bother.
  • The ask. Any request to “confirm your password” or “verify your account” by clicking a link. Legit companies almost never ask for that over email.

If you see two or more of these in the same message, that’s your answer.

Check the Link Before You Click It

This one’s simple but it saves you every time: hover your mouse over any link (or press and hold on your phone) before you tap it. A little preview pops up showing where it actually goes. If the email says “click here to view your invoice” but the link points to some random string of letters and numbers, don’t click it. Trust the preview, not the button text.

When in Doubt, Go Around the Email

If something seems urgent, like your bank saying there’s an issue, don’t use anything in that email to check it out. Don’t call the number listed. Don’t click the “login” button. Instead, open a new tab and go directly to the company’s website, or call the number on the back of your card. Scammers love putting fake contact info right in the email so you stay trapped in their setup. Google has a good rundown on how to spot and avoid phishing scams if you want another source to double-check yourself against.

A Quick Trick for the More Curious

If you want to go a step further, you can peek at the email’s “headers,” basically the behind-the-scenes travel log of where the message actually came from. In Gmail, click the three dots near reply, then “Show original.” You’ll see technical stuff, but the main thing to look for is whether it passed authentication checks. If it failed, that’s a strong sign the sender isn’t who they claim to be. You don’t need to be techy to notice a big red “fail” next to those checks.

If You Already Clicked... Don't Panic, Just Act Fast

We’ve all been there, you click before your brain catches up. Here’s what to do, in order:

  1. Disconnect from Wi-Fi for a minute so nothing keeps talking to that server in the background.
  2. Don’t type anything if a login page popped up. Just close it.
  3. Run a quick antivirus scan on your device.
  4. Change your passwords, starting with whatever account they were pretending to be, plus your email.
  5. Turn on two-factor authentication wherever you can.
  6. Report the email as phishing in Gmail, Outlook, or whatever you use. Takes ten seconds and helps flag it for others too.

The Bottom Line

Scam emails are getting smarter (thanks, AI), but the basics still work: check the real sender address, watch for pressure tactics and generic greetings, hover before you click, and when something smells off, verify it somewhere other than the email itself. Takes 30 seconds, saves you a giant headache.

And hey, if your business gets a lot of these impersonation attempts, or customers are getting fake emails pretending to be you, that’s usually a sign your domain needs some security setup (things like SPF, DKIM, and DMARC). Worth a conversation with whoever manages your website.

FAQ

How can I tell if an email is fake fast?

Check the actual sender address (not just the display name), look for a generic greeting instead of your name, and watch for urgent language pushing you to act immediately. Any two of these together is a strong red flag.

What should I do if I already clicked a suspicious link?

Disconnect from Wi-Fi, don’t enter any info if a page pops up asking for it, run a security scan, and change your passwords right away, starting with your email account.

Can scam emails really look identical to real ones now?

Yes. Scammers are using AI to copy a company’s tone, logos, and formatting almost perfectly. That’s why checking the sender’s real domain matters more than ever, the content alone can’t be trusted.

Is it safe to just open a suspicious email?

Opening it is generally low-risk. The danger comes from clicking links, downloading attachments, or replying with personal info. Still, avoid opening anything from a sender you truly don’t recognize.