Etoolio

Is This Email Real? Email Scam Checker

Free email scam checker. Paste a suspicious email and it analyses the headers, sender authentication (SPF, DKIM, DMARC), lookalike domains and links to flag phishing and spoofing. All in your browser.

Your email is analysed entirely in your browser. Nothing is uploaded.

Check a suspicious email before you trust it

Phishing emails are built to look real: the right logo, an urgent message, a familiar name. But the proof of who really sent an email is in its headers, and scammers cannot easily fake those. Paste a suspicious email here and this free checker reads those hidden signals and tells you, in plain language, whether it looks genuine or like a scam. Everything happens in your browser, so your email never leaves your device.

What it checks

  • Sender authentication: did the message pass SPF, DKIM and DMARC? A DMARC pass is a strong sign the From address is genuine.
  • Brand impersonation: does a message claiming to be PayPal, a bank or a courier actually come from that company's domain, or a lookalike or free account?
  • Reply-To tricks: would your reply quietly go to a different, attacker-controlled address?
  • Dangerous links: links whose visible text does not match their real destination, links to raw IP addresses, and lookalike domains using hidden characters.
  • Scam language: the urgency, threats and requests for passwords or gift cards that define phishing.

How to get the email source

  • Gmail: open the email, click the three-dot menu, choose "Show original", and copy everything.
  • Outlook: open the message and choose "View source" or "Message details".
  • Apple Mail: View, then Message, then Raw Source.

Paste the whole thing, headers and body, or upload the saved .eml file.

What the verdict means, honestly

This is evidence-based confidence, not certainty. Authentication passing tells you the sending domain is real, not that the content is safe: a genuine account can be hacked and still send a scam. Authentication failing can occasionally happen to legitimate but misconfigured or forwarded mail. So treat the verdict as strong evidence, and whenever money or credentials are involved, confirm through a phone number or website you already trust, never one from the email itself.

Private by design

The entire analysis runs in your browser with JavaScript. Nothing you paste is uploaded or stored. This is the first of the RealCheck tools, a growing set that helps you answer one simple question in the AI era: is this real? It pairs naturally with checking suspicious links, images and messages.

Good to know

Is This Email Real? Email Scam Checker, frequently asked questions

How can I tell if an email is real or a scam?

Paste the full email, including its headers, and this checker analyses the signals scammers cannot easily fake: whether the sender passed SPF, DKIM and DMARC authentication, whether the From address matches the brand it claims to be, whether replies would go to a different domain, whether links point where their text says, and whether the wording uses classic scam pressure tactics. It gives a clear verdict, looks genuine, be cautious, or likely fake, with the evidence behind it.

What are SPF, DKIM and DMARC?

They are the three checks a receiving mail server runs to confirm an email really came from the domain it claims. SPF checks the sending server is authorised, DKIM checks the message was not altered and is signed by the domain, and DMARC ties them together and confirms alignment with the visible From address. A DMARC pass is a strong sign the sender domain is genuine; a DMARC fail means the From address may be spoofed. This tool reads these results straight from the email's headers.

How do I get the full email source to paste?

In Gmail, open the email, click the three-dot menu and choose 'Show original', then copy everything. In Outlook, open the message and choose 'View source' or 'Message details'. On Apple Mail, use View then Message then Raw Source. Paste the whole thing, headers and body, into the box, or upload the saved .eml file.

Does a passing result mean the email is definitely safe?

No, and the tool is honest about this. Authentication passing means the sending domain is genuine, but a real account can be compromised and still send scams, and a genuine domain can be used for a low-quality but real marketing email. It is evidence-based confidence, not certainty. When money or credentials are at stake, always confirm through a phone number or website you already trust, never one taken from the email.

What are the biggest red flags of a phishing email?

A mismatch between the sender's claimed brand and its actual domain (like 'PayPal' from a random address), a Reply-To that goes to a different domain, links whose visible text does not match their real destination, links to raw IP addresses or lookalike domains using hidden characters, urgent threats to suspend your account, and requests for passwords, OTPs or gift cards. This tool checks for all of these.

Is my email uploaded or stored anywhere?

No. The entire analysis runs in your browser using JavaScript. Nothing you paste, and no part of your email, is ever sent to a server or saved. That privacy matters, because suspicious emails often contain personal information.

Is it free?

Yes, free with no signup, and unlimited. It runs entirely in your browser.