How to check a suspicious email, URL, or SMS sender

How to inspect a link, an email domain, or an SMS sender name before trusting it — without visiting anything directly.

By AlertaSpam Security Team. Published August 7, 2026

Emails, links, and text messages are all checked the same way at a high level: look at what actually identifies the sender or destination — the domain, not the display name or how professional the message looks — and check that against a source you didn't get from the message itself.

Checking an email

  1. Look at the full email address behind the display name, not just the name — most mail apps show it if you tap or hover over the sender.
  2. Check the domain after the '@' on the email page the same way you'd check a website's domain — does it belong to the organization it claims to be from?
  3. Be wary of a domain that's close to, but not exactly, the organization's real one (see our guide on identifying a phishing page for concrete look-alike examples).

Checking an SMS sender

  1. Search the sender name on AlertaSpam's SMS sender pages — sender IDs can be spoofed or reused by a third party, so a familiar name is not proof of who sent it.
  2. Compare it against a previous, genuine message from the same organization if you have one.
  3. Never reply to confirm — contact the organization through its official app or website instead.

What not to do

  • Don't click a shortened or unfamiliar link 'just to see' — use the link checker first, every time.
  • Don't trust a sender name or display name alone for either email or SMS — both can be spoofed.
  • Don't reply to a suspicious message asking it to 'confirm' whether it's real — a scammer will simply say yes.

Frequently asked questions

Is it safe to open a suspicious email itself, just not click links in it?

Generally yes for plain-text or standard HTML email — the real risk is almost always in a link or attachment, not in viewing the message. Avoid opening unexpected attachments regardless.

What if I don't recognize the SMS sender ID at all?

Search it on AlertaSpam and treat any link inside the message as unsolicited by default — an unrecognized sender combined with a link asking for action is one of the clearest smishing patterns.