Fake Email Hallmarks

targetfakeemailFake Email Hallmarks, or How to Recognize a Fake Email: These days our email inboxes are full of junk email – lots of which we can easily identify and delete. And some email from people we know that we’re sure is ok. But mixed in with that are emails that appear to be legit, but really aren’t. And it’s often hard to tell the difference! So here are some tips to help you figure out the good stuff from the crap.

By now you should have figured out that fake but seemingly legit emails can come from anywhere. It’s absurdly easy to fake the From: line on an email, and it’s also simple to copy images or artwork from a legitimate website so that an email can look exactly like that from someone or some company you know. Even clickable links in an email can be easily faked – they can say one thing and actually take you someplace else. Here’s two simple examples:

bing

  1. This fake web link to Google:  www.google.com – click it and it actually takes you to Bing
  2. click the fake image to Bing and it actually takes you to Google

So you’ve probably seen a ton of emails that look like they’re from your bank, from Paypal, from Sam’s Club or Amazon.com or any one of a bunch of commercial entities. In many cases it takes more than a simple glance to recognize them as fake. The bogus thank-you gift from (not!) Target is a perfect example – it looks legit until you look at the From: line – supershoulders.com is not Target!

Read on for ways to recognize fake emails.

Here’s things to watch for (click on an example image to view full-size):

  1. fakeemailzipLook for a file attachment, usually zip files, but really any file attachment
  2. fakeemail1Watch for a mis-match between the company’s Name and the From email address.
  3. fakeemaillinksLook for the From line or hyperlinks inside the email that point somewhere other than a company’s domain
  4. fakeemailamazonHover your mouse over each of the links in the email and read the pop-up for the address (if your system shows one) – the written link should match the company website address – if not, the message is almost certainly a fake.
  5. fakeemailwordingLook for uncommon or poorly-worded language, bad grammar, mis-spellings and bad punctuation. This is common in fake emails, less so in legit emails.
  6. fakeemailbillLook for a request for you to log into your account, verify account settings, view your information, or provide any personal information. Fake emails use this tactic a lot, while legit emails should never do this.
  7. fakeemaildeliveryFake delivery notifications, often with a malware-laden attachment receipt or a link to an online verification that actually takes you to a poisoned website.

I get hundreds of junk emails every day, so I’m used to just scrolling down the list and deleting without opening most of them. You start to see patterns, such as similar subject lines or identical emails sent from different From addresses. Unfortunately, there are still too many legitimate companies who haven’t figured out smart marketing, so they may use some of the same tactics that spammers use. Just my opinion, but in these days of mass credit card and identity theft, any commercial entity naive enough to still do this is really too risky to deal with – avoid them.

Advertisement

If you haven’t already read about online scams, we have a good article here. In general, if the deal looks too good to be true, it almost certainly isn’t. And another note, if you see massively deep discounts offered, first you should be wondering how the company stays in business. It’s either a scam, a bait-and-switch tactic, or some other method with the primary purpose of separating you from your money. We all want to save money and our marketing institution has trained us to look for the discounts. But giant discounts are all-too-often a sham. And another personal opinion – almost all discounting is a sham from the discounter to you. Nobody stays in business selling you something for less – regular prices are inflated so when you get a discount, you feel like you’re saving money. But you really aren’t. Modern marketing has us all fooled.

As far as personal or semi-personal emails go,

  1. Like above, watch for poor language, bad grammar, mis-spellings and bad punctuation. Hallmarks of fake emails. Same for emails that have attachments.
  2. fakeemailscamIf you’re offered something for free, claims that money is owed you, or offers to share in a money-making scheme, don’t yield to the temptation. These are all scams and some of them have been going around and around for over two decades.
  3. fakeemailstrandedEmail accounts of people you know are getting hacked constantly. An insidious fake email type is one from someone you know who is stranded somewhere, wallet/keys/money/passport stolen and they need you to wire them money. These are all fake.
  4. fakeemailnominationnominations to awards you never heard of – bogus almost always.
  5. fakeemailcrypticEmails from someone you know that just have a link to someplace are good indications your friend’s email account has been hacked. Be a good friend and let them know – but not via email!  Here’s a good article on email password protection.
  6. fakeemailthreatThreats or complaints against you or your company sent via email are almost always bogus. This includes sometimes funny FBI emails or complaints to the Better Business Bureau, but could come from anywhere.

The sad news is that the bad guys are constantly dreaming up new ways to fool us. The above examples are just that – examples of the thousands of different fake emails running around the internet. So the best way for you to deal with email is to be paranoid: first assume all email is fake. You are usually pretty good at recognizing the tone of people and friends in emails you get, but all email outside of this should be given a hard once-over before you do anything other than hit the delete key.


This website runs on a patronage model. If you find my answers of value, please consider supporting me by sending any dollar amount via Click or tap to open a new browser tab or your Venmo app and send money via Venmo to @positek (send to @PosiTek), Click or tap to open a new browser tab or your Paypal app to send money via your Paypal account to support@positek.net (send to Support@PosiTek.net), Click or tap to open a new browser tab or your Paypal app to send money using your credit card to support@positek.net (no Paypal account required) using any credit card (no Paypal account required), using Zelle, Apple Pay or Google Pay, or by mailing a check or cash to PosiTek.net LLC 1934 Old Gallows Road, Suite 350, Tysons Corner VA 22182. I am not a non-profit, but your support helps me to continue delivering advice and consumer technology support to the public. Thank you!

Go to Top of Page

4 Comments

  1. I think I got one from fake starbucks today.

  2. I have come across some phishing emails recently. Most show a real lack of sophistication, but there have been a few which have surprised me!

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.