How an email scam actually works
The most damaging email fraud rarely looks like fraud. It arrives as something ordinary: a note from your boss, an invoice from a vendor, a message from someone already involved in a deal you were expecting. The sender looks right and the request makes sense, and that familiarity is the whole design. A criminal doesn't need you to believe something outrageous. They only need you to trust one email long enough to act on it. Here is how that happens, and why the moment that decides it is the one after the email reaches you.
The old warning signs no longer work
For years the advice was to watch for typos, clumsy grammar, and obviously suspicious links. That test has stopped working. Modern fraudulent emails are often written with the help of AI, which means clean grammar, polished formatting, and brand details copied down to the signature. Many carry no malware and no malicious attachment either, so security tools see nothing out of place. A convincing scam now looks exactly like the ordinary messages you get every day, which is why judging an email by how it looks is no longer enough.
Every scam that works follows the same four steps
The names change, but almost every successful email scam runs the same sequence.
First, they become someone you trust
Before you will act, you have to believe the request came from someone you know. The criminal fakes the sender with a lookalike domain or a familiar display name, or sends the message from a real account they have already compromised. Often the only difference between the real address and the fake one is a single changed character, and you were never meant to notice it.
Then they give you a reason to act
Trust gets them through the door; emotion moves you. The message adds pressure: a payment due today, an account about to be suspended, wiring instructions that just changed, a quiet request to keep it confidential. It might work through urgency, authority, fear, secrecy, or even good news like an unexpected refund. The goal is to keep you moving before anything gives you a reason to stop and check.
The request looks completely ordinary
By now the ask feels routine: click a link, scan a QR code, call a number, reply, approve a sign-in, update a payment detail, or send a wire. None of it feels dangerous, which is exactly why it works. A newer version is the request to approve a short sign-in code, where the Microsoft page you land on is genuinely real but the code was generated by the attacker, so approving it hands over your account without a password ever being stolen.
See how device-code scams workThen you cross a line you can't uncross
The moment you act, control passes to the attacker, and every bit of the damage happens after the email already reached your inbox and convinced you. Your spam filter and your gateway had their turn. The message cleared them and landed in front of a person who trusted it. The loss doesn't happen in the delivery. It happens in the reading, and in the decision that follows.
The same playbook, under different names
Once you know the four steps, the named scams stop looking like a confusing list. Each is the same sequence with different bait. Here are just some of the most common examples that EFA is designed to catch.
- Spear phishing
- uses details about a specific person, company, or deal to make one message far more believable than generic phishing.
- Business email compromise
- impersonates or takes over a trusted business identity to steer payments, invoices, or sensitive information.
- Payment and wire fraud
- waits for a real transaction already underway and quietly changes where the money goes.
- Credential phishing
- sends you to a login page that looks legitimate in order to capture your password.
- Lookalike-domain impersonation
- uses an address close enough to a real one that the difference survives a glance.
- QR-code phishing
- swaps the link for a code you scan, moving the destination to your phone where it is harder to inspect.
- Device-code scams
- talk you into approving a sign-in the attacker started, handing over access without a stolen password.
- Vendor and invoice impersonation
- mimics a supplier you already pay and changes only where the payment lands.
- Fake voicemail, document, and e-signature notices
- borrow familiar work tools as the reason to click, sign in, or open something.
Different stories, same strategy: earn trust, supply a reason, make the action feel normal, and let that action complete the fraud. These are only some of the scams EFA watches for. See the complete list of EFA warnings and what each one means →
The most important moment comes after delivery
Understanding these tactics helps, but spotting every fraudulent email by eye is unrealistic. The clearest signals often sit in the sender address, the reply path, the authentication results, and the routing, none of which an ordinary reader ever sees, and even the visible differences are easy to miss when you are already expecting the message. That is why careful, experienced people still get caught. Traditional email security does its work before and during delivery, but once a message reaches the inbox the next decision belongs to a person: read it, believe it, act on it. That gap between reading an email and acting on it is why we created Read-Time Fraud Detection (RTFD), adding one more chance to question a message at the point the decision actually matters.
Learn what Read-Time Fraud Detection is“What email? I didn't send any email.”
The real paralegal, after a lookalike address impersonated her to a homebuyer. Via ABC7 Chicago.
By the time she said it, the email had already done its job.