Understand Your EFA Warning

Email fraud can hide in the sender, the domain, the links, the routing, the authentication, or the request itself. EFA checks for these warning signs when you open an email and tells you what it found before you decide what to do.

A warning does not automatically mean an email is fraudulent. It means EFA found something worth checking before you trust or act on the message.

Want to learn more about your warning? Click the warning you saw below.

Skip the warning list and go to the explanations

Scam Warnings

Credential Harvesting Attempt

This email offers you a document or an account notice, but the links go to a website that has nothing to do with the sender. The page it opens is built to look like a real sign-in screen so you will type your password into it.

What to do: Don't use the links in this email. If you need to check the account, type the company's address into your browser yourself or use a bookmark you already had.

HTML Attachment Phishing Trap

This email has a web-page file attached. Opening it launches a page in your browser that is stored on your own computer, which is a way to show you a convincing fake sign-in screen without a suspicious web address to notice.

What to do: Don't open the attachment. If you were expecting a document from this sender, ask them to resend it another way, using contact details you already have.

Suspicious Protected Attachment

The email includes a password-protected attachment and gives you the password to open it. Locking a file this way stops security software from checking what is inside, so it is sometimes used to slip a harmful file past scanning.

What to do: Don't open the file or use the password until you've confirmed with the sender through a phone number or address you already have.

This can be legitimate — some firms genuinely send encrypted documents. Confirming first costs very little.

Payment Redirect / Business Email Compromise

This email asks you to change payment or banking details, the sender's identity doesn't hold up, and the message discourages you from calling to check. Discouraging a phone call is the part that matters: it is there to stop you from discovering the change is fake.

What to do: Do not process any payment or account change from this email. Call the company at a number you already have on file — never one printed in this message — and confirm before anything moves.

Social Engineering — False Familiarity Attack

The message is written to feel like it comes from someone you already know or an organization you already deal with, and it leans on that familiarity instead of proving who it is. Sounding familiar is easy to fake and is often the whole of the approach.

What to do: Don't click links or send any information. Check the offer or request directly with the organization, using their official website or a number you look up yourself.

Voicemail Lure Phishing

This email says you have a voicemail or a missed call waiting. The notice creates a reason to click quickly, and the link or attachment usually leads to a fake sign-in page or a harmful file dressed up as an audio recording.

What to do: Don't click the link or open the attachment. If you might have a real voicemail, check your phone directly or sign in to your voicemail provider the way you normally do.

ClickFix — Command Injection Lure

This email tells you to copy something and paste it into your computer's Run box, terminal, or browser address bar, usually framed as a quick fix. No legitimate email ever asks for this. Following the steps runs the sender's instructions on your machine.

What to do: Don't paste or run anything from this email. Delete it. If it arrived at a work address, let your IT or security team know.

ClickFix — Fake Browser Verification

This email asks you to complete a browser check or a CAPTCHA to continue. Real websites don't email you to verify your browser. These fake verification pages exist to deliver harmful software or capture a password.

What to do: Don't follow the verification steps. If you need the site, go to it directly using a bookmark or by typing the address yourself.

TOAD — Telephone-Oriented Attack Delivery

This email pairs a phone number with billing or charge language, often with an attached invoice. The aim is to get you to call. On the phone, a person will try to collect payment details or talk you into installing software that gives them access to your computer.

What to do: Don't call the number in the email. If you're concerned about a real charge, use the number on your account statement or the company's official website.

Real Estate Wire Fraud — Cash-to-Close

This email carries closing or cash-to-close wiring instructions. Property closings are the most targeted moment in email fraud, because the amounts are large, the timing is known, and a redirected wire is very hard to recover.

What to do: Do not wire funds based on this email. Call your escrow officer or title company at a number from your original contract or one you have verified independently — not a number from this message.

Suspicious Document Signing Request

This email attaches a document and asks you to sign it and send it back by email or fax. Real e-signature services almost always keep signing inside their own system, so an attachment with return-by-email instructions is unusual.

What to do: Before signing or returning anything, confirm the request with the sender using contact details you find yourself. If the document involves banking, ACH, or wire details, treat that confirmation as essential.

Potential Secure Delivery Scam

This email says a secure or protected document is waiting and that you need to sign in to read it. That wrapper is convincing because real services do send messages like it, and it gives a reason to ask for your password.

What to do: If you were expecting a document, confirm with the sender at a number you already have before clicking. Don't use any contact details from the email itself.

Multiple Phishing Indicators Detected

EFA matched more than one known scam pattern in the same email. Any one of them alone might be explainable; several appearing together is much harder to explain innocently, so the warning names the group rather than a single pattern.

What to do: Treat this as one of the strongest warnings EFA gives. Don't click, reply, sign in, or send anything. If the message claims to come from someone you know, contact them another way to check.

Sender & Identity

Sender Impersonating You

The sender has set your own name as their display name, so the email appears in your inbox looking as though it came from you. This is done to make a message feel internal and trustworthy, and it is sometimes used to claim your account was hacked.

What to do: Don't reply and don't act on anything it asks. Receiving this does not mean your account was accessed — anyone can type your name as their display name.

Display Name Impersonation

The name shown in your inbox says one thing, but the actual email address behind it belongs to someone else. Most email apps show only the name until you look closer, which is what makes this worth pointing out.

What to do: Open the sender's full email address and read it carefully. If the request involves money, passwords, or personal details, confirm with the real person at a number you already have.

Impersonating Your Organization

The sender is presenting themselves as your own company or organization, but the message came from outside it. Mail that appears to come from your own IT team, HR, or leadership is a common way to ask for a password without raising suspicion.

What to do: Don't sign in through any link in this email. Check with your IT team or the colleague named, using your normal internal contact method.

Your Organization Referenced by External Sender

This email mentions your organization by name but was sent from a domain that isn't yours. That is often perfectly ordinary — vendors, clients, and applicants all mention the companies they write to.

What to do: Mostly informational. Take it seriously only if the message also asks you to sign in, pay something, or change account details — in that case verify before acting.

Brand Impersonation Suspected

This email speaks in the voice of a company you recognize, but it wasn't sent from an address that company is known to use. Well-known brands are impersonated constantly because their name alone earns a moment of trust.

What to do: Don't use the links in the email. If it concerns your account, open the company's website or app directly and check there.

When the brand is named in the message body rather than the sender details, this appears as Brand Impersonation Suspected (Body). This can be legitimate when a company sends mail through a marketing or support service on its own behalf.

Organization Impersonation

The email claims to come from a named organization — such as a bank, agency, or service provider — but the sending address doesn't belong to that organization. Agencies and institutions are impersonated because the name carries authority.

What to do: Don't respond or click. Contact the organization through a number or website you look up independently, not one supplied in the message.

Suspicious Display Name

The sender's display name is built to influence how you read the message — for example, a name padded with an official-sounding title, a department, or a warning word — rather than simply naming a person or company.

What to do: Judge the message by the actual email address, not the name. If it asks for anything sensitive, verify through a channel you already trust.

Sender Could Not Be Verified

Gmail only

EFA could not reliably identify who sent this message, so its sender-based checks could not run. This is a statement about what EFA was able to read, not an accusation about the email — but it does mean you have less protection than usual on this message.

What to do: Read this one with extra care. If it asks for money, credentials, or personal details, confirm with the sender through a contact method you already have.

Account Email Mismatch

Outlook only

This looks like a verification or security notice, but it refers to an account that isn't yours. Genuine security emails reference your own account. Someone may have entered your address on another service, or the message may be a phishing attempt.

What to do: Don't click any links. If you didn't start this action, you can safely ignore the message. If you're concerned about a real account, sign in to it directly.

Domains & Addresses

Lookalike Email Address

This sender's address is almost identical to one already in your contacts, but not quite — often a single letter added, removed, or swapped. It is designed to survive a quick glance, which is exactly why it is one of the most effective tricks in email fraud.

What to do: Compare the address against the one you have saved, character by character. If they differ at all, don't reply — reach the real person at a number you already have.

Lookalike Domain

The part of the address after the @ closely resembles a domain you deal with, but isn't it. An extra letter, a missing one, or a slightly different ending is enough to own a convincing address that has nothing to do with the real company.

What to do: Read the domain slowly and compare it to a message you know is genuine. Don't act on payment or account instructions until you've confirmed by phone.

Invisible Character Trick

This email contains characters that look exactly like ordinary letters but are drawn from another alphabet. Used inside a name, a web address, or payment details, they make something false read as completely normal — no amount of careful looking will catch it.

What to do: Don't trust addresses, links, or account details in this message as they appear. Verify anything important through a separate, known channel.

Depending on the message and your email app, this same check appears as STOP! DISGUISED LETTERS DETECTED. The meaning and the advice are the same.

Hidden Character Obfuscation

This email uses hidden formatting characters to change how text appears on screen — for example, making a file name display backwards so a program can look like a harmless PDF. Legitimate senders have no reason to do this.

What to do: Don't open attachments or follow links from this message. Deleting it is a reasonable response.

Depending on the message and your email app, this same check appears as This Email Is Hiding Something. The meaning and the advice are the same.

Fake Domain Extension

The ending of the sender's web address — the part after the last dot — is not a real domain extension that exists on the internet. An address like this cannot belong to a genuine organization.

What to do: Don't reply, click, or act on this message.

Suspicious Domain

Something about the sender's domain follows a pattern more common in fraudulent mail than in ordinary business mail — its structure, its wording, or how it is put together.

What to do: Use this as a reason to slow down rather than a verdict. If the message asks for money, credentials, or personal details, verify through a channel you already trust.

Disposable Email Address

Outlook only

This message came from a throwaway email service — the kind that hands out a temporary inbox with no identity check. These addresses are used when someone wants to send mail that can't be traced back to them.

What to do: Be very cautious with any request in this message. Ongoing business correspondence essentially never arrives from a disposable address.

Suspicious Random Domain

The sender's domain looks machine-generated rather than chosen — a string of characters with no recognizable name behind it. Fraud campaigns register domains like this in bulk because each one is used briefly and then abandoned.

What to do: Don't act on requests from this sender without confirming who they are through another channel.

Gibberish Sender Address

The part of the address before the @ appears randomly generated rather than being a name, a role, or a recognizable word. Real people and businesses normally use addresses a human would choose.

What to do: Treat requests from this address with caution, particularly anything involving money, passwords, or personal information.

Some legitimate automated systems do send from machine-generated addresses, so weigh this alongside what the message actually asks for.

Sent from Free Hosting Platform

This message was sent through a free web-hosting or site-building service rather than from a company's own mail system. Established businesses generally send from their own domain.

What to do: If the email claims to represent a company, check that claim through the company's official website before responding or clicking.

Recently Registered Domain

Outlook only

The sender's web address was registered very recently. That is a fact about the address, not a verdict about the email — new businesses register new domains every day — but fraud campaigns rely on fresh domains because older ones get blocked.

What to do: If this message asks you to move money or change payment details, confirm by phone using a number you already have. Otherwise treat it as background context.

International Sender

The sender's address ends in a country code. On its own this means very little — plenty of legitimate mail crosses borders, and a few of these endings are used worldwide by ordinary businesses regardless of country. What makes them worth flagging is that they are also chosen to build addresses that resemble a familiar one.

What to do: Informational. It matters if the ending doesn't fit who the sender claims to be, if you don't recognize the sender, or if the message asks for payment or personal details.

Payments & Requests

Dangerous Keywords Detected

This email uses wording that appears repeatedly in wire and payment fraud — the language of transfers, account details, and urgent financial instructions. The wording alone doesn't make a message fraudulent, but it marks the kind of request worth confirming.

What to do: Before sending money or changing any payment detail, confirm the request by phone using a number you already have on file — never one from this email.

Banks, accountants, and title companies discuss these topics legitimately every day. Confirming costs a minute; a redirected payment is very hard to recover.

Payment Instructions Changed

Outlook only

This email asks you to change payment or wire instructions. This single request is the most common method in wire fraud, and it works even when the sender's address looks entirely legitimate, because accounts can be compromised.

What to do: Always verify a payment change by phone, using a number you already have on file. Do not use a number, link, or reply address from this email — including one that looks familiar.

Verify Payment Instructions

Outlook only

This message contains payment or banking details. This notice is a routine reminder rather than a sign of anything wrong — it appears because money is involved and this is the moment when confirming is cheapest.

What to do: Confirm the account details by phone before sending anything, using a number you already have.

Potential Real Estate BEC Attack

This email asks for the contact details of other people involved in an upcoming closing. Gathering who's who is how a criminal learns enough to impersonate the right person later and redirect a wire at the moment funds move.

What to do: If you weren't expecting the request, confirm it with the sender by phone before sharing anyone's contact details. Never share transaction party contacts based on email alone.

On lower-risk messages this appears as Contact Request in a Closing Context, because the same request is often routine coordination. The check is the same either way.

New Sender — Verify Before Processing

Someone you haven't corresponded with before has sent a financial document to a mailbox that handles payments. First contact plus an invoice or banking document is the shape vendor impersonation usually takes.

What to do: If this involves payment, banking, invoicing, or a vendor change, verify by phone before processing it. If it has nothing to do with money, proceed normally.

Depending on the message, this may appear as Vendor Impersonation Risk — First-Time Sender to Financial Mailbox or First-Time Sender — Document to Financial Mailbox.

Tech Support Billing Scam

Outlook only

The subject line pairs a phone number with a charge amount — the signature of tech support billing scams. The message is built to alarm you about a payment you don't recognize so that you call the number instead of checking your account.

What to do: Don't call the number in this email. If you want to check a charge, sign in to the company's official website or use the number on your statement.

Links, QR Codes & Sign-In

QR Code Contains Suspicious Link

This email contains a QR code that leads somewhere suspicious. Codes are used instead of links because you can't read a destination before you scan it, and scanning usually moves you to your phone, where a fake page is harder to spot.

What to do: Don't scan the code. If you need to reach the service it claims to be for, open it directly on your own device.

Sign-In Code Request

This email asks you to approve a sign-in or enter a verification code. Genuine sign-in codes appear on the device you are signing in from — they are not sent to you to enter on someone else's request. Approving one can hand over access to your account without your password ever being taken.

What to do: If you didn't just start a sign-in yourself, don't approve it and don't enter the code anywhere.
See how device-code scams work →

Document-Share Impersonation Detected

This email is built like a document-sharing or e-signature notice: a branded header, a document icon, one large button, and very little text. That layout is copied closely because it gets people to click the button without reading.

What to do: Don't use the button. If you are expecting a document, sign in to the sharing or signing service directly and look for it there.

Attachments & Message Content

Risky Attachment Type

This email has an attachment of a type that can carry a program inside it, even though it looks like an ordinary picture file. Most image files are perfectly safe; this particular kind is the exception, and scammers use it to send people to fake websites.

What to do: If you weren't expecting a logo or design file from this sender, don't open it. If you were, confirm with them first.

Image-Only Email Body

Almost everything in this email is a picture rather than text. Putting the message inside an image hides its wording from security tools that read text, while still showing you something that looks completely normal.

What to do: Be careful with any link, phone number, or instruction that appears inside the image — none of it was checked the way ordinary text would be.

Marketing newsletters are sometimes built this way too, so weigh it against what the message is asking you to do.

Missing Subject Line

Outlook only

This email arrived with no subject line. Business correspondence almost always has one, and blank subjects are common in bulk phishing that was sent from a template.

What to do: Mostly informational, and often just an oversight by the sender. Give it more weight if the message also asks you to click, pay, or sign in.

Phishing Language Detected

The wording of this email uses pressure of the kind found in phishing — deadlines, threats of suspension, or warnings that something bad happens if you don't act immediately. The purpose of that pressure is to get you moving before you check.

What to do: Let the urgency be the reason you slow down. If the claim might be real, check the account directly rather than through this email.

Genuine notices can sound urgent too. The test is whether you can confirm it somewhere other than the message itself.

Delivery & Routing

Reply-To Mismatch

The address your reply would go to is different from the address that sent the message. That can be entirely legitimate, but it is also how a scammer quietly moves your response — and anything you put in it — to an inbox they control.

What to do: Before replying with anything sensitive, check where the reply is actually addressed. If it doesn't match the sender, start a new email to the address you already have.

On some messages this appears as Suspicious Reply Destination. Shared mailboxes, support desks, and mailing services legitimately do this.

Sent On Behalf Of Another Domain

Outlook only

This email was sent by one domain on behalf of a different one. Plenty of legitimate services do this — payroll, scheduling, and marketing platforms all send for their customers — but it can also disguise where a message really came from.

What to do: Check whether the sending service makes sense for the company it claims to represent. If the message involves payment or sign-in, verify directly with that company.

Suspicious Routing Detected

On its way to you, this email passed through a relay server with a randomly generated name. Established businesses send through recognizable mail systems, so an anonymous hop in the path is unusual.

What to do: Take extra care with links and requests in this message, especially anything involving money or credentials.

In Gmail this appears as Suspicious Third-Party Routing.

Flagged by Gmail / Flagged by Outlook

Your email provider marked this message as suspicious before EFA looked at it, and EFA is passing that on so it isn't missed. Two independent systems raising a concern about the same message is worth noticing.

What to do: Be especially careful with any links or buttons. If you don't recognize the sender, there is rarely a reason to engage at all.

Mass-Distributed Email

This message went to a large group of recipients. Newsletters and announcements do that routinely — but genuine invoices, payment confirmations, and account alerts are sent to one person, so seeing one of those in a mass send is odd.

What to do: Be suspicious of any request for payment or personal action in a message that was sent to a crowd.

You Were BCC'd

You weren't addressed directly — your copy arrived as a blind carbon copy. This is normal for mass emails and newsletters, and it can also be used to hide who else received the message.

What to do: Mostly informational. If a BCC'd message asks you personally to act, verify the sender before you do.
↑ Back to Warning List

Protection may vary by email platform as EFA continues to expand capabilities across supported services.