Your inbox shows a sender named "Official Sweepstakes Team" with a trophy emoji, and for a second your heart jumps. But that bold name at the top of the message is just a display name — a label the sender typed in themselves, free to say anything. The part that actually tells you who sent the email is the address hiding behind it, and scammers count on you never looking. Here's how to pull back the curtain in about ten seconds. 🕵️
Expand the display name and read the real address
On a phone, the From line usually collapses to just the friendly name. Tap it (or tap the sender's name/avatar) and the app expands to show the true address in <angle brackets>, like noreply@ford-winners-claim.info. On desktop Gmail, click the little down-arrow beneath the sender's name to open the details panel; in Outlook, hover the name or open the message header. The friendly label can read "PCH Prize Patrol" all day long — the address in the brackets is the fact that matters.
Now read the domain only, meaning the part right before the first single slash or the end: everything after the @ and up to the top-level ending like .com. A real Publishers Clearing House email comes from @pch.com; a real Amazon one from @amazon.com. Scam domains pile on extra words to look official — @pch-rewards-center.com, @amazon.prize-verify.net, or a random string like @mail3722.win. If the brand's actual name isn't sitting immediately to the left of that .com, treat it as fake. Big free domains are another tell: legitimate national sweepstakes do not notify winners from @gmail.com or @outlook.com.
Check where a reply would actually go
A sender can spoof the display name and even fake the visible From address, so do one more move: check the Reply-To. Start a reply (don't send it) and look at the address your app auto-fills in the To field, or open the full header and find the Reply-To: line. Scammers often let the From show a clean-looking brand address but quietly route replies to a throwaway inbox like claims.dept99@gmail.com. A mismatch between the From domain and the Reply-To domain is a screaming red flag. 🚩
For the technically curious, open the raw header ("Show original" in Gmail, "View message source" in Outlook) and scan for SPF, DKIM, and DMARC results. You want to see pass next to each. A fail or softfail on SPF or DMARC means the message wasn't actually authorized by the domain it claims to come from — the digital equivalent of a forged return address. You don't need to understand the cryptography; you just need to see the word "pass."
Why a name–domain mismatch equals fraud
Here's the core principle: a friendly name and an email domain that don't match is not sloppiness, it's deception by design. No real sweepstakes administrator sends a "you won $50,000" notice from an address that has nothing to do with their company. The FTC has said it plainly — legitimate sweepstakes never ask winners to pay and never hide behind unrelated addresses. The mismatch itself is the confession.
Once you've confirmed a mismatch, don't reply, don't click, and don't download the attachment. Report it: forward the message to reportfraud.ftc.gov and to the real brand's abuse address if they list one, then delete it. Sixty seconds of reading an address beats months of chasing a "prize" that was never real.
Before you celebrate any win, expand the sender and read the domain — if the name and the address don't match, it's a scam.