ScamGuard

📧 Email Spoofing Checker — Detect Forged Sender Addresses

Email spoofing makes a scam look like it came from your bank, Microsoft, or even yourself. Paste the email below — ScamGuard flags forged senders, lookalike domains and broken authentication in seconds.

What ScamGuard checks for

  • Detects forged From: addresses
  • Flags Reply-To vs From mismatches
  • Spots lookalike & sub-brand domains
  • Brand-impersonation scoring
  • Header-aware when headers are pasted
  • Free, no signup

⚠️ Red flags and warning signs

  • Reply-To doesn't match From
  • Sender domain has extra dots (paypal.secure-billing.com)
  • Email from your own address asking for ransom
  • Brand normally signs mail but this one isn't signed
  • Display name shows 'PayPal' but address is random@gmail.com
  • Link domain doesn't match the brand

How to protect yourself

  • Verify the sender domain character-by-character
  • Hover every link before clicking
  • Never act on an email that pressures you to 'reply now'
  • Publish SPF / DKIM / DMARC on your own domain
  • Use a password manager — it won't autofill on spoofed login pages
  • Forward suspicious emails to ScamGuard and the impersonated brand

ScamGuard tools you can use right now

Frequently asked questions

What is email spoofing?

Email spoofing is when a scammer forges the From: address so the email looks like it came from a brand or person you trust — your bank, Microsoft, a colleague, even your own address. The technical fix exists (SPF, DKIM, DMARC) but many domains aren't fully protected, so spoofing still works.

How can I tell if an email is spoofed?

(1) Reply-To: differs from From:, (2) sender domain has hidden characters or extra subdomains (e.g. paypal.secure-billing.com), (3) email fails SPF/DKIM in the headers, (4) the brand normally signs all email but this one isn't signed. Paste the email into ScamGuard and we surface all of these for you.

Can scammers really spoof my own email address to me?

Yes — and they do, in 'sextortion' scams to make you panic that your account was hacked. Your account wasn't hacked; they just forged your address in the From: header. Don't pay. Delete.

What's the difference between spoofing and phishing?

Spoofing is the technique (forging the sender). Phishing is the goal (stealing credentials, money, data). Most phishing emails use spoofing.

How do I protect my own domain from being spoofed?

Publish SPF, DKIM and DMARC records on your domain's DNS, with DMARC set to 'p=reject' once you've verified your legitimate senders. This blocks spoofed mail from your domain at most major mailbox providers.

Is this checker free?

Yes — paste any suspicious email and we'll flag spoofing signals in seconds. No signup.

Related ScamGuard checkers

Try ScamGuard free

1 free check, no signup needed. Then create an account for unlimited investigations.

Analyze With ScamGuard