Is this email a scam? Six checks, and a fake brand deal taken apart
Six checks that tell a real email from a phishing one in about two minutes: the real sender, the greeting, what it wants, where its links go, the pressure, and how to confirm it safely. With a fake "brand partnership" email taken apart line by line.
How to tell if an email is legit
Most scam emails are not clever. They work because they arrive when you are busy, and they look close enough to something real. You do not need special software to catch them. Six checks, done in order, take about two minutes, and each one can be done on a phone.
1. Who really sent it
Look past the name and read the address. The name can say anything, like "PayPal", "Amazon Support" or "Partnerships Team". Only the part after the @ tells you who sent the email.
- A company usually writes from its own domain. An email about your bank account should come from your bank's domain, not from a free mailbox or someone's home internet provider.
- Read the spelling letter by letter. The US Cybersecurity and Infrastructure Security Agency lists "incorrect email addresses or links, like amazan.com" as a sign of phishing (CISA).
- An agency is not automatically fake. Some companies use outside agencies for marketing or recruiting. That is fine, but it means you need to confirm it through the company itself (check 6), not through the email.
2. How it greets you
A company you have an account with knows your name. PayPal, for example, says its emails "will always address you by your first and last names or by your business name" (PayPal).
"Dear user", "Dear customer", "Hi there" or no greeting at all is not proof of a scam, but from a company you do business with, it is a warning.
3. What it wants you to do
The email itself does no harm. What it asks you to do next is where the harm happens. The FTC lists what phishing emails typically claim (FTC):
- that they noticed suspicious activity or log-in attempts
- that there is a problem with your account or payment information
- that you need to confirm personal or financial information
- an invoice you do not recognize
- a link to make a payment
- that you are eligible for a government refund
- a coupon for free stuff
If the email wants you to sign in, pay, open a file, or send personal details, stop and go to check 6 before doing any of it.
4. Where its links really go
On a computer, move your mouse over a link or button without clicking and read the address that appears. On a phone, press and hold the link to see it.
- The site is the part just before the first single slash, read from the right:
paypal.com.account-review.top/loginis a site called account-review.top. - CISA also flags "untrusted shortened URLs" (CISA): a short link hides where it goes until you open it.
If you are not sure, paste the link into our checker instead of opening it. We open it in a browser that is not yours, follow every redirect to the end, and tell you what is there: whether it asks for a password or a payment, how old the site is, and whether it is on public blocklists.
5. The pressure, or the flattery
Scam emails push in one of two directions. Some make you afraid: your account will be closed, a payment failed, you have 24 hours. Others make you feel chosen: you won something, a brand noticed you, someone wants to work with you.
Both have the same job: to get you to act before you check. A real company can wait while you look it up.
6. Confirm it through a door you already trust
This is the check that works even when the email looks perfect. The FTC's advice is to "contact the company using a phone number or website you know is real — not the information in the email" (FTC).
- Type the company's website yourself, or use its app.
- Use a phone number from the back of your card, a past statement, or the official website. Never use one from the email.
- If the email is real, whatever it asked about will be there too.
How to identify a phishing email: the short version
- The address after the @ is not the company's own, or is misspelled.
- It does not use your name, from a company that knows it.
- It wants you to sign in, pay, open a file or send details.
- A link goes somewhere other than the company's site, or is a short link.
- It is in a hurry, or it flatters you.
- The company's own website or app, opened by you, knows nothing about it.
One of these is a reason to slow down. With two or more, treat it as phishing until the company itself, reached the way check 6 describes, tells you otherwise.
A fake brand deal, taken apart
People who post online, like YouTubers, small creators and anyone with a public fitness or lifestyle page, get emails like this one. We changed the names: the brand in the real email is a well-known sports nutrition company, and it is the one being impersonated, not the sender.
Hi hi, My name is Sophie, and I'm working with the partnerships team at [a well-known nutrition brand]. I had the chance to explore your YouTube channel while reviewing fitness and lifestyle content, and I took a closer look at how you share your fitness journey. It stood out as a natural alignment for what we're currently developing. I'd be happy to share more details — no pressure, just an open conversation. Partnerships Team
Here is what the six checks find:
- Who sent it: the address was a home internet provider's mailbox in another country, not the brand's own domain. That alone means you confirm through the brand, not through this thread.
- The greeting: "Hi hi". No name and no channel name. Someone who really watched your channel knows what it is called.
- What it wants: nothing yet, and that is on purpose. The first email only has to get a reply. The request, whether it is a file to open, an account to sign in to, or a fee to pay, comes after you have answered.
- Links: none in the first email. They come later, which is why the first reply matters.
- Pressure or flattery: flattery that fits any channel ("your fitness journey", "a natural alignment") and "no pressure", which is itself a way of lowering your guard.
- Confirm it: go to the brand's official website yourself and find its partnerships or press contact. Ask them whether "Sophie" works with them. If the offer is real, they will know about it.
How to report a phishing email
- Forward it to [email protected]. That is the address the FTC gives for phishing emails (FTC).
- If it pretends to be a company you use, that company may have its own address for this. PayPal, for example, asks for fakes at [email protected].
- Use your email app's "report phishing" or "report spam" option, then delete it.
- If you lost money or gave away information, report it to the FTC at reportfraud.ftc.gov.
If you already clicked, replied or paid
- You typed a password into a page from the email: change it now, typing the site's address yourself, and change it anywhere else you use the same one. Turn on two-step verification.
- You paid: contact your bank, card issuer or payment app straight away and ask them to reverse the payment. That is the FTC's advice (FTC).
- You only replied: you have lost nothing yet. Stop answering, don't open anything they send next, and confirm through the company as in check 6.
If someone then offers to get your money back for a fee, that is a second scam: the FTC warns that recovery scams target people who have already lost money (FTC).
Check a link before you click it
Paste the link or scan the QR code. We open it for you and show the real destination, the redirects on the way, and whether anyone has reported the seller behind it.
Check a linkMore articles
- QR codes Quishing: how QR code scams work, and how to check a code before you scan it Quishing is phishing through a QR code: on a parking meter, in an email, on a flyer or a package you never ordered. How each version works, what the FTC and FBI advise, and how to see where a code goes first.
- Scams Geek Squad scam emails: the fake renewal invoice, and how to check it An email says you will be charged hundreds of dollars to renew Geek Squad and gives a number to call. Here is what happens if you call, how to check the charge safely with Best Buy, the same trick dressed as McAfee or Norton, and what to do if you already called.
- Scams How to report a phishing email in Outlook, Gmail and iPhone Mail The exact buttons to report a phishing email in Outlook, Gmail and Apple Mail, where else to forward it (APWG, the company being faked, the FTC), and what reporting does and does not do.