Fake emails are the most common way businesses get caught out. They can look exactly like a message from a supplier, your bank or Microsoft, and they often arrive at the worst possible time, just before a payment run or when someone is rushing to clear their inbox.

This guide covers the quick checks anyone can do in a few seconds, and the more reliable check: reading the email’s headers with our free email header analyser.

Quick checks before you click anything

  • Look at the real address, not the name. The name shown can say anything, such as “Microsoft 365” or the name of your boss. Hover over it, or tap it on a phone, to see the actual email address.
  • Check the domain carefully. Scammers register lookalikes, such as posi1an.com with a number 1, or posilan-support.com. One wrong character is enough.
  • Hover over links before clicking. The address that appears should match where the email says it goes. Be wary of shortened links, or links to file-sharing sites you don’t normally use.
  • Be suspicious of pressure. “Your account will be closed today”, “invoice overdue” and “urgent, I’m in a meeting” are all designed to stop you thinking.
  • Treat any change of bank details as fake until proven otherwise. This is the most expensive scam we see. Always confirm by phone, using a number you already have, not one from the email.
  • Don’t open unexpected attachments, especially zip files, or documents that ask you to “enable content” or sign in to view them.

The reliable check: read the headers

Every email carries hidden headers: a record of where it came from, which servers handled it, and whether it passed the security checks that prove the sender is who they say they are. Headers are much harder to fake than the parts of an email you can see.

1. Copy the headers

  • Outlook (classic, on Windows): open the email in its own window, choose File, then Properties, and copy everything in the Internet headers box.
  • New Outlook and Outlook on the web: open the email, select the three dots (More actions), then View, then View message source.
  • Gmail: open the email, select the three dots, then Show original.
  • Apple Mail: open the email, then choose View, Message, Raw Source.

2. Paste them into the analyser

Paste the headers into our email header analyser and select Analyse headers. It runs entirely in your browser, so nothing you paste is uploaded or stored.

3. Read the results

The analyser picks out the warning signs for you. The most important results are the three authentication checks:

  • SPF: was the server that sent the email allowed to send for that domain?
  • DKIM: was the email digitally signed by the domain, and is it unchanged since?
  • DMARC: does the email pass the sending domain’s own anti-spoofing policy? A DMARC fail on an email claiming to be from your bank or a supplier is a strong sign it’s fake.

It also flags replies that would go to a different domain from the sender, a common trick in invoice fraud, and shows the IP address the email came from, with links to check who owns it and whether it’s on a spam blacklist.

What headers can’t tell you

A clean result doesn’t prove an email is safe. If a supplier’s real mailbox has been hacked, emails sent from it pass every check, because they genuinely come from that supplier. Lookalike domains can pass too, because the scammer controls them and sets up their own records.

So use the headers alongside common sense. If an email asks for money, passwords or new bank details, confirm it by phone with someone you know, using a number you already have.

If you think an email is fake

  • Don’t click links, open attachments or reply.
  • Report it. In Outlook, use the Report button, which also helps Microsoft block it for others. You can forward suspicious emails to the National Cyber Security Centre at report@phishing.gov.uk.
  • If you’ve already clicked a link or entered a password, change that password straight away, and tell your IT support so they can check the account for unusual sign-ins or mail forwarding rules.

Posilan clients can forward any suspicious email to support@posilan.com, or send a screenshot on WhatsApp, and we’ll take a look.

Stop scammers pretending to be you

The same checks protect your own business. If your domain doesn’t have SPF, DKIM and DMARC set up, anyone can send email that appears to come from you, to your clients, your suppliers or your own staff. It also makes your genuine email more likely to land in junk.

Use our email health check to see where your domain stands, and the SPF and DMARC generator to create the records you’re missing.

Would you rather we set it all up and took you safely to full DMARC protection? Get in touch or call us on 0161 660 7471.