Knowledge · Check before you click or pay · 8 minutes
How to check if an email is real: sender, headers and DMARC
Check the real sender address, the domain and its age, and the SPF, DKIM and DMARC results in the original message in Gmail and Outlook. Plus: Facebook emails.
Last updated: October 5, 2026
How can you tell if an email is real?
A real email is one sent by who it claims to be, from a domain they own. You check this on three levels: the sender address, the technical confirmation of the domain (SPF, DKIM, DMARC) and the content, meaning what the email asks you to do.
None of these levels is enough on its own. A scammer can send a perfectly authenticated email from their own freshly bought domain that looks almost like your supplier's. And a real mailbox can be taken over. So the last step is always the same: confirm any request for a transfer, password or code through another channel.
The content tells you something too. Typical signals are urgency ('within 24 hours'), threats (account suspension, a fine, a summons), a request for a password, code or card details, an unusual attachment (an .html file, a .zip archive, an 'invoice' that is really a link) and a tone that does not fit the sender. One signal alone proves nothing, but two or three together are a reason to stop.
How to check if an email address is real
1. Expand the sender name. Mail apps show a display name, such as 'Bank Payments Team', and anyone can type whatever they like there. Click or tap the name to see the full address.
2. Read the domain after the @ sign. Look for swapped letters (rn instead of m, l instead of I), add-ons ('-pl', '-invoices', '-support') and different endings (.co instead of .com). A company writing about an invoice or your account from a free mailbox, such as Gmail, is a warning sign.
3. Check the reply-to address. When you click 'Reply', see where the reply would go. An address different from the sender's is a common part of invoice fraud.
4. Check the domain itself. Its age, whether it is on the CERT Polska warning list, its similarity to known brands and whether it has SPF and DMARC set up: you can check all of that for free in domain or email mode.
SPF, DKIM and DMARC in plain language
SPF is a DNS record that says which servers may send email on behalf of a domain (the standard is RFC 7208). DKIM is a digital signature added by the sender's server that lets the recipient confirm the message was not changed on the way. DMARC is the domain owner's rule for what to do with email that fails SPF and DKIM alignment with the 'From' address: reject it, send it to spam or only report it.
DMARC got a new specification in 2026: RFC 9989 replaced the earlier RFC 7489. Existing DMARC records keep working.
Since 1 February 2024 Gmail has required SPF or DKIM from all senders, and from those sending more than 5,000 messages a day to Gmail accounts it requires both SPF and DKIM, plus DMARC and alignment with the 'From' domain. Large companies and banks usually have all three.
The key limitation: 'pass' means the email really comes from the domain you see. If that domain is a lookalike, the result will still be 'pass'. Authentication answers 'where from', not 'from someone honest'.
How to view the original message in Gmail and Outlook
Gmail on a computer: open the message, click the three dots next to 'Reply' and choose 'Show original'. A new window shows the full headers. Look for the SPF, DKIM and DMARC results (PASS or FAIL) and the 'Authentication-Results' line.
Gmail on Android: open the message, tap 'View details', then 'View security details'. The 'mailed-by' and 'signed-by' fields show the domain that passed authentication. A question mark next to the sender's name means Gmail could not confirm where the message came from. Google says not every such message is spam, but be careful with replies and attachments.
New Outlook and Outlook on the web: in the open message choose 'More actions', then 'View' and 'View message details'. Classic Outlook: open the message in its own window, choose 'File' and 'Properties', and the headers are in the 'Internet headers' box.
What to look for in the headers: whether the domain in 'From' matches the domain in the SPF and DKIM results, whether 'Return-Path' and 'Reply-To' point somewhere else, and whether DMARC shows 'pass'. A mismatch does not prove fraud (some newsletters work this way too), but together with a request for money it should stop you.
How to check if an email from Facebook is real
Meta lets you check this inside the service. Log in to Facebook yourself (not from the link in the email), go to Accounts Center, then 'Password and security' and 'Recent emails'. According to Facebook's help pages, you will see security emails from the last year and other emails sent in the last two days.
If the email is not on that list, treat it as suspicious. According to Meta, its emails only come from fb.com, facebook.com, facebookmail.com, instagram.com, meta.com and metamail.com, but the domain in the 'From' field is not enough on its own, because display names can be faked and lookalike domains registered. A threat like 'we will disable your page in 24 hours' plus a link to a password form is a typical pattern.
The same rule works for other services: your bank, a shop or a courier. Instead of clicking, open the app or a site you typed in yourself and check whether the same information appears in your account.
How to check an email domain
You check the domain in an address the same way as a website. The age of a .pl domain is shown by the NASK registry WHOIS (dns.pl/whois), other domains by ICANN Lookup. A domain registered a week ago that closely resembles your business partner's domain is a very strong signal.
Also check whether the domain has DMARC and with what rule. No DMARC does not prove fraud, but it means someone can impersonate that domain more easily. The next steps for websites are in how to check if a website is safe.
What to do with a suspicious email
Do not click links or open attachments. If you need to check a link, read how to check if a link is safe without opening it.
Report the message: in Gmail and Outlook as phishing, and in Poland to CERT Polska via the form at incydent.cert.pl or at cert@cert.pl. If the email is about a changed bank account or an invoice, read the separate piece on fake invoices and changed account numbers.
If you already clicked and entered a password, change it now and turn on two-step login. If banking details are involved, call your bank first.
In short
- The sender name is just text. What counts is the address after the @ sign and the reply-to address.
- SPF, DKIM and DMARC confirm where an email came from, not that the sender is honest. A lookalike domain can also pass.
- Open the original message in Gmail with 'Show original', and in Outlook through message details or properties.
- You can check an email from Facebook in Accounts Center, under 'Recent emails'.
- Confirm any request for money, a password or a code through a channel other than that email.
Have a website, app or email address that looks suspicious?
Frequently asked questions
How can I find out who really sent an email?
Open the original message ('Show original' in Gmail) and compare the domain in the 'From' field with the domains in the SPF and DKIM results. If they match and DMARC shows 'pass', the email came from that domain.
Can a sender address be faked?
The display name can be anything, and the 'From' address can be spoofed if the domain has no DMARC policy that rejects failures. That is why you should look at the authentication results, not just the address.
What does the question mark next to the sender mean in Gmail?
Gmail could not confirm where the message came from. Google says it is not necessarily spam, but do not reply or open attachments without checking.
How do I check if an email from Facebook is real?
Log in to Facebook yourself and in Accounts Center open 'Password and security', then 'Recent emails'. If the message is not there, treat it as suspicious.
Where can I report a fake email?
In Poland, to CERT Polska via the form at incydent.cert.pl or at cert@cert.pl. In your mail app, also mark it as phishing.
Sources
- Gmail Help: Trace an email with its full headers
- Gmail Help: Check if an email is authenticated
- Microsoft Support: View internet message headers in Outlook
- Google Workspace: Email sender guidelines (requirements from 1 February 2024)
- IETF RFC 7208: Sender Policy Framework (SPF)
- IETF RFC 9989: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- Facebook Help: Check if an email is really from Facebook
- CERT Polska: Annual report 2025 (reporting channels)
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.
See also
- Fake invoices and bank account change emails: how to check
- How to check if a link is safe before you click it
- How to spot a deepfake: fake video, cloned voice and scam ads
- How to check if a website is safe: 7 checks before you trust it
- How to check if an online shop is legit: 8 checks before you buy
- How to check if an app is safe: mobile apps and business SaaS