TELLDATA BLOG

Email Fraud Warning Signs You Shouldn’t Ignore

Email Fraud Warning Signs You Shouldn't Ignore

A fake email does not have to look fake anymore. The old scams had bad spelling, strange fonts, and a prince offering you money. Now, a scammer may copy your vendor’s logo, use the name of your bookkeeper, and send an invoice that looks almost right.

That is why email fraud warning signs matter. One rushed reply can send a deposit to the wrong account, hand over a password, or give a stranger enough details to keep the scam going. For a small business, the loss is rarely just the dollar amount. It can mean a missed payroll, an angry customer, or a week spent cleaning up a mess.

The email can look familiar and still be wrong

Most email fraud works because it borrows trust you already have. A scammer does not need to convince you they are a stranger. They want you to think they are your supplier, customer, bank, office manager, or regular subcontractor.

Start with the sender address, not just the display name. An email from “Mike at Summit Electric” can appear normal in your inbox, while the real address is mike.summitelectric@outlook.com instead of mike@summitelectric.com. A single changed letter matters too. “rn” can look like an “m.” A domain like paypaI.com, using a capital I in place of a lowercase L, can slip past a quick glance.

The same thing happens with reply addresses. You may receive a message from a known contact, hit Reply, and find that the reply goes somewhere else. Before you answer a payment request or share private details, look at the full address. On a phone, you may need to tap the sender name to see it.

A real-looking name is not proof of a real person. Treat it as a starting point.

Email fraud warning signs that deserve a pause

No one sign proves fraud. A real vendor can make a typo. A customer may send an invoice from a personal account because their work email is down. The problem is when small things pile up and the email asks you to act fast.

Here are the signs that should make you slow down:

  • A request to change bank details, payment instructions, mailing information, or account contacts.
  • Pressure to act now, often with threats such as a late fee, canceled service, locked account, or missed shipment.
  • An attachment you were not expecting, especially a file that asks you to enable editing, content, or macros.
  • A link that wants you to sign in, confirm a password, enter a code, or view a shared document.
  • A message that sounds unlike the person who supposedly sent it. Maybe they normally write two clear sentences, but this email is stiff, vague, or overly urgent.
  • A request to keep the matter private from your partner, bookkeeper, manager, or regular contact.

That last one is a big tell. Scammers like isolation. They want the person reading the email to feel that checking with someone else will cause trouble or take too long.

A landscaping company owner in Dallas got an email that appeared to come from a material supplier. It said the supplier had changed banks and included a new routing number for future payments. The logo matched. The account manager’s name matched. But the message came from a free email address and used a phrase the account manager never used: “kindly remit.”

The owner called the number already saved in his phone, not the number in the email. The supplier had not changed anything. That two-minute call prevented a $4,800 payment from going to a scammer.

The link is often the real trap

Some scams do not want money right away. They want access.

A message may say your Microsoft account, shipping portal, payroll system, or cloud storage is about to expire. The button looks normal. The login page may look normal too. But the page is controlled by the scammer. When you type your password, they have it.

Before opening a link, press and hold it on a phone or hover over it on a computer. Look at where it leads. If the address is unfamiliar, misspelled, or filled with random words and numbers, do not open it. Go to the company site the way you normally do, or use a saved bookmark.

Be careful with shared-file notices as well. “You have a new document to review” is common bait. If you were not waiting for a file, confirm it through another channel first. Call, text, or start a fresh email to the person using contact details you already trust.

And never send a one-time login code to someone who asks for it by email, text, or phone. That code is often the last thing a criminal needs to get into your account.

A payment change needs a second path

Fraudsters know that invoices and payment changes are normal parts of business. That is why they target them.

Make one simple rule: never confirm a change to payment instructions by replying to the email that requested it. Use a second path. Call a known number. Send a new message to an address already in your contacts. If you deal with the person face to face, ask them directly.

Do this even when the email chain looks real. Sometimes a criminal gets into a real mailbox and waits quietly. They read old conversations, learn how people speak, and step in when a payment is due. In that case, the email address may be genuine. The request is still not.

It may feel awkward to call and ask, “Did you send this?” Good. A real business contact will understand. People who handle money should expect verification.

Look for identity mismatches outside the inbox

Email is only one piece of the picture. If a new customer, seller, contractor, or private party wants money, keys, equipment, or access to a property, compare the details they give you.

Does the name on the ID match the name tied to the phone number and email? Does the address make sense with the story? Is the email connected to a public business presence, or was it created yesterday and used only for this one deal? These checks do not prove someone is safe or unsafe. They can show a mismatch worth clearing up before anything changes hands.

For a fast identity check, TellData can combine identity and SSN trace data, address history, phone and email consistency checks, court and criminal record signals, watchlist screening, and public web presence into a plain-English report. A single report is $29.99 and is designed for situations where you need to know whether the person in front of you lines up with the details they gave you.

A report will not tell you why every mismatch exists. People move. They use nicknames. A phone may belong to a spouse or a small office. Public records can be incomplete or out of date. But a mismatch gives you a reason to stop guessing and ask for a clear explanation.

Build a habit your team can follow

You do not need a long policy binder. You need a few repeatable habits that still work when the shop is busy.

Keep vendor contact details in one place and update them when you speak to the vendor directly. Turn on multi-factor authentication for email and financial accounts. Use different passwords for different systems. If two people handle payments, have one person request a change and another verify it outside the email thread.

Also make it easy for staff to raise a concern. Nobody should feel foolish for asking about a weird invoice or a suspicious shared file. The expensive mistakes happen when someone worries they will look slow, then clicks anyway.

If you think you clicked a bad link, act fast. Change the password from a clean device, sign out of other sessions if the account allows it, and tell the people who need to know. If money was sent, contact your bank right away. Save the email, headers, invoice, and any chat records. A file called “April reciept.pdf” may look harmless later, but it can help explain what happened.

The best defense is not being suspicious of everyone. It is being careful when an email asks you to move money, share access, or trust a new identity without a second look. Stop for a minute. Use a known contact method. Make the person and the details line up before you act.

Know who you are dealing with.

Run a full person report in minutes — identity, records, watchlists and digital footprint in one clear PDF.