No single detail proves an email is fraudulent. Most convincing scams get one or two things exactly right and one or two things slightly wrong. The goal isn't to spot every fake email on sight. It's to build a habit of pausing on the handful of checks that catch most of what actually gets through.
1. The sender address, not just the display name
Email clients show a display name by default, which is trivial to fake. A message can say "Jordan Ellis, CFO" while the underlying address is something unrelated. Before acting on a financial or urgent request, look at the full sender address, not just the name attached to it.
2. A domain that's close, but not quite right
Look-alike domains are a common tactic: swapping a letter, adding a hyphen, or using a different top-level domain than the real organization uses. These are easy to miss at a glance, especially on a phone screen. If a request involves money or credentials, it's worth a second look at the exact domain.
3. Urgency paired with a request to skip the normal process
Legitimate requests can be urgent too, so urgency alone isn't the signal. The combination that matters is urgency plus pressure to bypass a normal step: "don't call to confirm, I'm in a meeting," "handle this today before you check with anyone else," or "keep this between us for now." That combination shows up repeatedly in business email compromise attempts.
4. A payment detail that changed
A vendor's bank account number changing, a new "updated" invoice showing up with different payment instructions, or a request to redirect an existing payment somewhere new are all worth stopping on. The standard response should be the same every time: confirm the change through a phone number or contact method you already had on file, not one included in the email itself.
5. A request that doesn't match how your organization actually works
This is the broadest and often the most useful check. Does this fit your normal process? If a request asks you to buy gift cards, wire money without a second approval, or share credentials over email, and that's not how your organization normally does things, that mismatch is itself a signal worth acting on, regardless of how convincing the message looks.
Putting this into practice
These five checks won't catch everything, and no list can promise that. But they cover the pattern behind a large share of email-based fraud attempts: a plausible sender, a small technical inconsistency, artificial urgency, a financial change, and a break from normal process. Building the habit of pausing on these points, even briefly, is one of the more practical steps an organization can take.
For a more complete self-assessment covering account access, payment verification, technical controls, and reporting, see the full Email Fraud Readiness Checklist.
Want this built into an ongoing program for your team? A Human Risk Readiness Review is a no-cost conversation about what that could look like.
Book a Human Risk Readiness Review