How to check a suspicious email, URL, or SMS sender
How to inspect a link, an email domain, or an SMS sender name before trusting it — without visiting anything directly.
By AlertaSpam Security Team. Published August 7, 2026
Emails, links, and text messages are all checked the same way at a high level: look at what actually identifies the sender or destination — the domain, not the display name or how professional the message looks — and check that against a source you didn't get from the message itself.
Checking a link or URL
- Don't click it yet. Paste it into the link checker instead, which looks up technical reputation signals without opening it on your device.
- If the link is shortened (bit.ly, tinyurl, or similar), treat it with extra caution when unsolicited — a shortener hides the real destination, so there's no way to judge it just by looking.
- If you can see the full URL, focus only on the domain portion — the text right after 'https://' and before the first single '/'. Watch for an '@' symbol (the real domain is the text after it, not before) or an extra subdomain designed to look like the real brand ('yourbank.login-secure.example.com' is not 'yourbank.com').
Checking an email
- Look at the full email address behind the display name, not just the name — most mail apps show it if you tap or hover over the sender.
- Check the domain after the '@' on the email page the same way you'd check a website's domain — does it belong to the organization it claims to be from?
- Be wary of a domain that's close to, but not exactly, the organization's real one (see our guide on identifying a phishing page for concrete look-alike examples).
Checking an SMS sender
- Search the sender name on AlertaSpam's SMS sender pages — sender IDs can be spoofed or reused by a third party, so a familiar name is not proof of who sent it.
- Compare it against a previous, genuine message from the same organization if you have one.
- Never reply to confirm — contact the organization through its official app or website instead.
What not to do
- Don't click a shortened or unfamiliar link 'just to see' — use the link checker first, every time.
- Don't trust a sender name or display name alone for either email or SMS — both can be spoofed.
- Don't reply to a suspicious message asking it to 'confirm' whether it's real — a scammer will simply say yes.
Frequently asked questions
Is it safe to open a suspicious email itself, just not click links in it?
Generally yes for plain-text or standard HTML email — the real risk is almost always in a link or attachment, not in viewing the message. Avoid opening unexpected attachments regardless.
What if I don't recognize the SMS sender ID at all?
Search it on AlertaSpam and treat any link inside the message as unsolicited by default — an unrecognized sender combined with a link asking for action is one of the clearest smishing patterns.
