Enter the From address and, if present, the Reply-To address from an email's headers to instantly see whether they match — and if not, whether they at least share a domain, which is a quick, useful signal when assessing whether a message might be spoofed.
Every email has a From header, which is what most inboxes display prominently, and an optional Reply-To header, which — if present — silently determines where your reply actually goes when you hit Reply, regardless of what the From address shows. Legitimate systems use this all the time for good reasons: a marketing platform might send From a friendly display name while routing replies to a support inbox, or a shared team address might redirect replies to a specific person.
The problem is that this same mechanism is also a common phishing technique — an attacker can spoof a familiar-looking From address (say, one resembling your bank or employer) while quietly setting Reply-To to an address they control, so your reply, and any sensitive information in it, goes straight to them instead of the organization you thought you were writing to.
No Reply-To present, or a Reply-To that matches the From address, is the normal, expected case for the vast majority of legitimate email. A Reply-To on the same domain as the From address is usually still fine — common for internal routing at a real organization. A Reply-To pointing to a completely different, unrelated domain than the From address is the combination worth the most scrutiny, especially when paired with urgency, a request for sensitive information, or a message you weren't expecting.
You'll need to view the email's full raw headers — in Gmail, open the message, click the three-dot menu, and choose Show original; in Outlook desktop, go to File → Properties. For a full breakdown of every header field, use the Email Header Analyzer instead of pulling out just these two by hand.
No — plenty of legitimate senders (marketing platforms, shared team inboxes, customer support systems) deliberately route replies to a different address than the visible From sender. It's a signal to look more closely, not a guaranteed verdict on its own.
Don't reply directly. Instead, verify through a separate, known channel — visiting the organization's website directly rather than clicking anything in the message, or contacting them through a phone number or address you already know is legitimate.
The Header Analyzer extracts and displays every field from a full raw header block, including From and Reply-To among many others. This tool is a faster, focused comparison when you already have just those two specific addresses and want a quick verdict.
No single check can. A matching Reply-To doesn't guarantee legitimacy, and this is only one of many signals — unusual urgency, suspicious links, and unexpected attachments matter too. Use it as one part of a broader, healthy skepticism toward unexpected email.