A friend of mine got one of those nerve-wracking emails recently. It claimed that a new email address had been added to their Apple Account. They hadn’t done anything, so naturally they panicked. Was someone trying to hijack their account? Was the email even real?
Turns out it was a phishing attempt, a fake email designed to scare them into clicking a link and handing over their login credentials. Luckily, instead of clicking anything, they opened a browser, went straight to Apple’s website, and checked their account directly. Smart move. In this guide, I’ll show you exactly how to figure out whether an email is fake, spoofed, or legitimate, and what to do either way. No IT background required.
What’s the Difference Between Fake, Spoofed, and Phishing Emails?
These terms get thrown around interchangeably, but they actually mean slightly different things, and knowing the difference helps you spot them faster.
- Phishing: An email designed to trick you into handing over sensitive information such as passwords, credit card numbers, and account credentials. Usually impersonates a trusted brand like Apple, PayPal, or your bank.
– Spoofing: When a sender fakes the “From” address to make an email look like it came from a legitimate source. Think of it as caller ID fraud, but for email.
– Spam: Unsolicited bulk email, usually annoying rather than dangerous, but it can carry phishing links or malware attachments.
Modern phishing attacks in 2026 are a lot more convincing than the clunky “Nigerian prince” emails of the past. They use real company logos, match the tone of legitimate messages almost perfectly, and create a sense of urgency (“Act now or your account will be suspended!”). The good news? There are reliable ways to see through them.
Step 1: Don’t Click Anything, Check the Account Directly First
This is the single most important habit you can build. If you get an email claiming something changed on your account, such as a new email address being added, a password being reset, or suspicious activity being detected, do not click any link in that email.
Instead, open a new browser tab and go directly to the service’s website by typing the address yourself. For example:
- Apple alert? Go to appleid.apple.com or open Settings > [Your Name] on your iPhone/iPad.
– Google/Gmail alert? Go to myaccount.google.com.
– Bank alert? Type your bank’s web address directly into the browser.
– PayPal alert? Go to paypal.com, never follow a link from an email.
If the account change the email mentioned actually happened, you’ll see it there. If nothing looks different, the email was almost certainly fake. The account itself is the source of truth, not the email.
Quick Apple Account note: Apple now refers to this as your Apple Account (not “Apple ID”) in current device settings and documentation. If you’re checking for unauthorized changes, go to Settings > [Your Name] on your iPhone or visit appleid.apple.com and look under Sign-In and Security.
Step 2: Look at the Sender’s Email Address (Carefully)
The display name in an email can say anything, such as “Apple Support,” “PayPal Security Team,” or “Your Bank.” That part is trivially easy to fake. What’s harder to fake is the actual email address behind it.
Click or tap on the sender’s name to reveal the full email address. Here’s what to look for:
- Does the domain match the company? A real email from Apple should come from something like @apple.com or @id.apple.com, not @apple-support-team.net or @appleaccountalert.com.
– Watch for lookalike domains. Attackers are clever. They register domains like paypa1.com (with a number 1 instead of an L) or apple-id-verify.com. Glance twice.
– Random or unrelated domains are a red flag. If an email claims to be from your bank but comes from something like noreply@seajin.chtah.com, that’s a dead giveaway.
Step 3: Check the Email Header in Gmail
The sender address alone isn’t foolproof. A determined attacker can sometimes make the visible “From” address look legitimate. The email header is where you get the real story. Think of it as the email’s behind-the-scenes paperwork that’s much harder to fake.
If you’re using Gmail in a browser, this is easy to check.
How to View Email Details in Gmail
- Open the email in Gmail.
2. Click the small down arrow (Show details) just below the sender’s name.
3. Look for the mailed-by and signed-by fields.
Here’s what those fields mean in plain English:
- mailed-by: Shows the domain that actually sent the email (SPF authentication). For a real Google email, this should say google.com.
– signed-by: Shows the domain that digitally signed the email (DKIM authentication). Again, should match the company’s real domain.
– Encryption: Legitimate emails from major companies are almost always encrypted. No encryption on a “bank security alert” is suspicious.
The general rule: for most consumer-facing emails from big companies, both fields match the company’s actual domain. If you get an email claiming to be from PayPal but mailed-by shows randomdomain.ru, treat that as a strong red flag. One exception: some legitimate companies send through trusted third-party platforms (see the third-party note below), so combine this check with account activity and other authentication results rather than treating any single mismatch as automatic proof of a fake.
Some spammers have gotten smart and do sign their own emails, but they can only sign them with their domain, not the company they’re impersonating. So you might see signed-by: sketchy-domain.com on an email that claims to be from your bank. That’s still a red flag.
Step 4: Check the Full Email Header (Non-Gmail Clients)
Not using Gmail? No problem. Every email client has a way to view the full raw email header. It’s just buried in different menus depending on which app you’re using.
Just search Google for your email app name plus “view email header”, for example “Outlook view email header” or “Apple Mail view email header”, and you’ll find the exact steps.
Once you’re looking at the raw header, search for the section labeled Authentication-Results. You’re looking for these two lines:
spf=pass
dkim=pass
- spf=pass means the email came from a server authorized to send on behalf of that domain (same as mailed-by in Gmail).
– dkim=pass means the email was digitally signed and the signature checks out (same as signed-by in Gmail).
Same rule applies here: both need to pass and the domain listed next to them needs to be the actual company’s domain. If you see spf=pass (domain: sketchy123.com) on an email claiming to be from Apple, that’s a fake.
Step 5: Watch for Gmail’s Built-In Warnings
If you’re using Gmail, it does a lot of the heavy lifting for you. When Gmail detects something suspicious about an email’s authentication or sender, it’ll show you a warning banner right inside the message.
If you see one of these banners, treat the email as dangerous until proven otherwise. Don’t click any links, don’t download any attachments, and definitely don’t enter any login credentials anywhere the email directs you.
Step 6: Spot the Classic Phishing Red Flags
Beyond the technical checks, phishing emails tend to follow predictable patterns. Once you know what to look for, they’re surprisingly easy to spot.
- Urgency and panic: “Your account will be suspended in 24 hours!” or “Unauthorized access detected, act immediately!” Legitimate companies don’t usually threaten you like this.
– Requests to sign in via a link: Real security alerts from Apple, Google, or your bank will tell you to go to their website. They won’t ask you to click a link and enter your password.
– Mismatched or weird URLs: Hover over any link before clicking it (on desktop, just move your mouse over the link without clicking). The URL that appears in the bottom of your browser should match the company’s real domain. apple-security-alert.com is not Apple.
– Generic greetings: “Dear Customer” or “Dear User” instead of your actual name. Not always a red flag on its own, but combined with other signs, it’s suspicious.
– Unexpected attachments: If you weren’t expecting a file, don’t open it, even if it looks like a PDF invoice or a Word document.
– Slightly off branding: Logos that look slightly wrong, odd fonts, or formatting that seems a bit “off” compared to emails you’ve received from that company before.
What to Do If You Think an Email Is Fake
If your gut says something’s off, trust it. Here’s the action plan:
- Don’t click any links or open any attachments.
2. Go directly to the service’s website by typing the address in your browser and check your account from there.
3. Report the email as phishing in your email client. In Gmail, click the three-dot menu next to the reply button and select Report phishing. In Outlook, use the Report button in the toolbar.
4. Delete the email after reporting it.
5. If you already clicked a link and entered your credentials: Change your password immediately, review your active sessions and trusted devices in your account security settings, and watch for any unauthorized changes like new email addresses or forwarding rules being added.
Tips and Troubleshooting
Common Questions
Can spam filters catch all phishing emails?
Not reliably on their own. Modern anti-phishing tools inspect links, attachments, sender behavior, and impersonation signals, but no filter is perfect. That’s why knowing how to spot these yourself still matters.
The email looks completely real. How can I be sure?
Check the account directly (Step 1) and verify the email header (Steps 3–4). The account itself doesn’t lie. If the change the email describes isn’t showing up in your account settings, the email is fake.
Is spoofing the same as phishing?
Not exactly. Spoofing is the technique, faking a sender’s identity. Phishing is the goal, stealing your credentials or tricking you into doing something harmful. Most phishing emails use spoofing to look convincing, but they’re related rather than identical concepts.
What if the email is from a third-party service on behalf of a company?
Sometimes legitimate companies send email through third-party platforms like Microsoft 365 or Mailchimp. In that case, you might see something like signed-by: onmicrosoft.com or mailed-by: mcsv.net even for a real email. The test is whether that third-party service is itself a large, reputable company. If it’s a domain you’ve never heard of, be cautious.
Pro Tips
- Make direct navigation a habit: For anything involving your bank, Apple Account, Google Account, or PayPal, just type the URL yourself. Always. It takes three extra seconds and eliminates a huge category of risk.
– Enable two-factor authentication (2FA): Even if a phisher gets your password, 2FA means they still can’t get into your account without your phone or authenticator app. Turn it on everywhere that offers it.
– Check recent account activity regularly: Most major services (Google, Apple, Microsoft) have a “recent activity” or “active sessions” page in their security settings. A quick monthly check can catch anything suspicious early.
– Use a password manager: A good password manager will only autofill your credentials on the real website. It won’t fill in your PayPal password on a fake lookalike site. That’s an underrated phishing protection right there.
Wrapping Up
Phishing emails have gotten genuinely good at looking real in 2026, but the fundamentals for spotting them haven’t changed: verify in the account directly, check the sender domain, and look at the email header authentication results. If the mailed-by and signed-by fields don’t match the company supposedly sending the email — and it’s not a known, reputable third-party service the company uses — treat it as a strong red flag.
Honestly, the single best habit you can build is to never click links in security alert emails. Just go straight to the website yourself. It takes a few extra seconds and saves you a world of potential headaches. If you’ve got questions or a suspicious email you’re not sure about, drop it in the comments below!