Share
SENDER CHECK - BRAND EMAIL VERIFICATION

These sender addresses look fake. The domains are real.

People search the exact address in the From line to find out whether an email is genuine. It is the right instinct and the wrong test, and the addresses below show why.

SafeBrowz Threat Research Security Research · · 9 min read

The short answer

Every address on this page ends in a domain the company actually owns, including the one that looks least believable. That does not make an email from it safe, because the From line can be written to say anything. The address tells you what a message claims to be, never what it is. The only reliable check is to ignore the email entirely and sign in to the company yourself.

SafeBrowz judges the page a link opens, so a convincing copy of a sign-in screen never gets your password. Add to Chrome, free Get the free Android app or scan a URL now →

The addresses people are searching for

These are real addresses that people look up because something about them felt wrong. In each case the domain checks out.

  • [email protected] and [email protected] both end in amazon.com, Amazon's own domain.
  • [email protected] sits on a subdomain of chase.com. Banks route alerts through subdomains constantly.
  • [email protected] looks like a machine generated mess, and it is: trx and mail2 are routing labels on Disney's own domain.
  • [email protected] is the one that looks worst, because the domain carries no brand name at all. It is registered through MarkMonitor, the registrar large companies use to hold their own domains. It is corporate infrastructure, not something an attacker minted last week.

That last one is the useful lesson. Everyone is taught to check that the domain matches the brand. A genuine transactional domain often does not, and a convincing fake often does.

Why the From line is not evidence

Email was designed so the sender writes their own return address. Nothing in the protocol stops a machine from putting amazon.com there. Modern mail providers do check, using SPF, DKIM and DMARC records that a domain publishes to say which servers may send on its behalf, and the large brands do publish them. That is why a spoofed message often lands in spam or arrives with a warning banner.

But you cannot see the result of that check from the From line, and you are not the one running it. So the address in front of you means one of two things and you cannot tell which: either the message really came from that domain, or someone typed it there. Both look identical.

The check that actually works

Stop judging the sender. Judge the destination, and then remove the email from the process entirely.

  1. Do not click the button in the message, however routine it looks.
  2. Open the company yourself, by typing the address or using a bookmark you made earlier.
  3. Sign in and look for the same thing the email mentioned: the order, the invoice, the security alert, the payment problem.
  4. If it is genuine, it is waiting for you there. If your account shows nothing, the email was not real, whatever the From line said.

This works because it does not depend on you spotting anything. A perfect forgery and a real notice both fail or pass the same test, and the test is on ground the attacker does not control.

When the address really is the giveaway

Sometimes it is. A lookalike domain, one character off from the real one, is a genuine red flag: a hyphen inserted, a letter swapped, or the brand pushed into a subdomain of something else entirely, as in the disneyplus.com versus a disney-mail style address. Our write-up on whether [email protected] invoices are real covers the version of this that trips people most often, because there the message is sent through the brand's own system.

The trap is that this only catches the lazy attempts. Plenty of phishing now arrives from a domain that is genuinely owned by someone, just not the brand, and plenty of real mail arrives from a domain that looks like nothing at all.

Where a link checker fits

The one thing an email always carries that you can test independently is the link. Layer 1 in our engine matches the destination against a local pattern and brand list in the browser itself, before anything loads. Layer 2 checks it against reputation feeds and our blocklist. Layer 3 runs AI content analysis on what the page actually serves, which is what catches a fresh lookalike login page that no list has seen yet.

Honest scope: this tells you about the destination, not about the sender. If an email carries no link, or the attacker is playing a longer game over several messages, a URL check has nothing to work with. The sign-in-yourself habit above is still the thing that saves you.

Paste the link from an email you are unsure about, before you open it. Check a URL free → Get the free Android app
🛡 LIVE CHECK

Not sure where an email link goes?

Paste it here instead of clicking it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Is [email protected] a real Amazon address?

The domain it ends in, amazon.com, is Amazon's own. So a message that genuinely comes from that domain is genuinely from Amazon. The catch is that the From line you see is not proof of where a message came from, because it can be written to say anything. Treat the address as consistent with Amazon rather than as evidence, and confirm anything it asks you to do by signing in at amazon.com yourself.

Why does [email protected] look so strange?

Because the domain does not carry the brand name, which is the opposite of what people are taught to look for. It is registered through MarkMonitor, a registrar large companies use to hold their own domains, so it is corporate infrastructure rather than something an attacker minted. Odd looking is not the same as fake, which is exactly why the look of an address is a poor test.

So how do I actually tell a real brand email from a fake one?

Stop trying to judge the sender and judge the destination instead. Do not click the button in the email. Open the company's site yourself, sign in, and see whether the same notice, invoice or alert is waiting for you in your account. If it is real it will be there. If it is not there, the email was not real, whatever the From line said.

Can an attacker send email that really appears to come from amazon.com?

They can put amazon.com in the From line, yes. Whether it survives depends on the receiving mail provider checking SPF, DKIM and DMARC, and major brands do publish those records. This is why a spoofed message often lands in spam or carries a warning. It is also why you should never rely on the address alone: you are trusting a check you cannot see the result of.

What should I do if I already clicked the link?

Do not enter anything else. Close the page, then open the real site by typing the address yourself and change your password there. If you entered card details, call your bank. Our guide on what to do after a scam walks through the first 24 hours by payment type.

Follow on Google