From (Sender)
The From field shows the address that apparently sends the email. It is one of the easiest elements to forge. An attacker can use a similar domain, a visually identical name, or even a completely fabricated address.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
- It should match the official domain of the legitimate sender.
- It may show a "friendly name" different from the actual address.
- It is common to find spoofing through look-alike domains.
To (Recipient)
The To field indicates who receives the message. Although it is usually correct, it can also reveal if the email has been sent in bulk or if an unexpected distribution list has been used.- It can show multiple visible recipients.
- In targeted attacks, usually only one address appears.
- In bulk campaigns, it may appear empty or generic.
Subject
The Subject is the title of the message. Attackers often use urgency, alarms, or emotional messages to force a quick reaction.- Subjects with unjustified urgency.
- Spelling errors or poor translations.
- Promises, threats, or unexpected requests.
Date (Declared Date)
The Date field shows the date and time declared by the sending server. It does not always coincide with the real time.- Dates inconsistent with the sender's local time.
- Emails sent "in the future."
- Mismatches that may indicate manipulation.
Reply-To (Reply Address)
The Reply-To field indicates which address the response will be sent to. It is one of the most commonly used elements in fraud.- It may differ from the actual sender.
- It is used to redirect replies to accounts controlled by attackers.
- It should always be checked in suspicious emails.
Message-ID (Unique Identifier)
The Message-ID is a unique identifier generated by the sending server. It is very difficult to forge correctly.- It should contain a domain consistent with the sender.
- IDs without a domain or with strange domains are suspicious.
- It allows for tracking the technical origin of the message.
Return-Path (Technical Return Address)
The Return-Path is used by servers to manage bounces. It does not always match the visible sender.- It can reveal the actual server that sent the message.
- If it differs from the sender's domain, it should be analyzed.
- It is one of the most useful clues for detecting spoofing.