How can I inspect a sender, link, attachment, or QR code safely?
Safely evaluate sender addresses, destination domains, attachments, QR codes, and login pages without supplying sensitive data.
Content reviewed
Short answer
Inspect without following the message’s path: reveal the full sender, read the actual destination when your client can show it without opening it, identify the controlling domain, and verify the claimed event through an independently opened app or site.
01
What you may be seeing
Messages can hide a full email address behind a display name and a destination behind button text, shortened URLs, or QR codes.
Attachments and QR codes reduce what you can inspect at a glance. Treat an unexpected item as unverified; do not open it merely to decide whether it is safe.
02
Signals to inspect—and why they matter
Strong evidence
The controlling domain differs from the claimed organization
Read a hostname from right to left. In login.brand.example, the owner of example controls the site; the word “brand” is only a subdomain.
The login page requests a secret unrelated to the verified task
Passwords, one-time codes, recovery codes, payment details, and identity data should only be entered after independently reaching the intended service.
Contextual signals
The attachment or QR code was unexpected
Unexpected content raises uncertainty but is not proof. Verify the sender and business context through a known channel without opening the item.
The message has mistakes—or is perfectly polished
Writing quality is weak evidence in both directions. Legitimate messages can contain mistakes and malicious messages can be professionally produced.
Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.
03
Safe verification steps
Reveal the full From and Reply-To fields using your mail client’s details view.
Use the client’s built-in destination preview only if it can be viewed without navigating. Do not visit a suspicious URL to analyze it.
Find the hostname and identify the registrable domain; ignore brand words in the path, query string, or left-side subdomains.
For a QR code, do not scan it just to discover whether it is safe. Verify the claimed task independently or use an organization-approved analysis process.
For an attachment, confirm the sender and expected business process through a known contact method before opening it.
04
What to do next
Navigate independently to the claimed account or transaction.
Use the organization’s reporting control while preserving the original message when policy requires it.
If you already opened, submitted, approved, or paid, follow the action-specific response guide.