Why Retailers Are a Favored Phishing Target

Retail-themed phishing works because shopping emails are genuinely high-volume and expected. Most online shoppers receive multiple order confirmations, shipping updates, and promotional messages each week, which means a convincing fake blends naturally into an already busy inbox.

Attackers also exploit timing. During peak shopping periods, consumers are more likely to have recent orders they're tracking, making a fraudulent "Your shipment is delayed" message feel plausible. The goal is almost always one of three things: harvesting login credentials, capturing payment information, or installing malware on the recipient's device.

Understanding how these attacks are constructed is the first step toward resisting them. Our broader guide on how online shopping scams are structured covers the wider ecosystem these phishing attempts feed into.

What you will need

Access to the email account where retail communications are received
Basic familiarity with opening and reading emails on a desktop or mobile device
Knowledge of which retailers you have active accounts or recent orders with

How to Spot a Phishing Email Step by Step

The six steps below walk you through a systematic check you can run on any suspicious retail email. You do not need technical expertise — each check requires only the tools already built into your email client and browser.

Required

Email client with header inspection

Lets you view the full sender address and raw message headers to verify the true origin of an email.

Required

Retailer's official website (typed directly into browser)

Used to cross-check order status, account activity, and promotions without relying on email links.

Optional

Password manager

Autofills credentials only on legitimate domains, providing a practical safety net against spoofed login pages.

1

Inspect the actual sender address — not just the display name

Open the email and expand the sender field to reveal the full address. A legitimate email from a major retailer will use that retailer's own domain (e.g., @amazon.com or @target.com). Watch for subtle misspellings such as @amazon-support.net or extra subdomains like @mail.amazon.orders-help.com — the rightmost part of the domain before the first slash is what matters.

Tip: On mobile, tap the sender name to expand it — most apps show only the display name by default until you do.
2

Hover over links before clicking anything

Move your cursor over any link in the email without clicking. Your browser or email client will display the destination URL in a status bar or tooltip. Confirm the domain matches the retailer's known web address exactly. Any redirect through a URL shortener or an unrelated domain is a strong signal the email is fraudulent.

Tip: On mobile, press and hold a link to see the destination URL appear in a preview popup before committing to open it.
3

Check the email for generic or pressuring language

Phishing messages frequently use vague greetings like "Dear Customer" instead of your name, and they often inject urgency — "Your account will be suspended in 24 hours" or "Claim your reward before it expires." Authentic transactional emails from retailers typically include your name, a specific order number, and itemized details you would recognize from an actual purchase.

Warning: Urgency is a deliberate tactic. A message designed to make you act immediately without thinking is designed that way on purpose — slow down before clicking anything.
4

Verify the order or promotion directly on the retailer's site

Open a new browser tab and type the retailer's web address manually — do not copy-paste from the email. Navigate to your order history or account dashboard and check whether the order, shipment update, or offer actually appears there. If it does not, the email is almost certainly not from the retailer.

Tip: Bookmark the account pages for retailers you use frequently so you can get there quickly without any risk of mistyping.
5

Examine attachments and embedded images critically

Legitimate order confirmations rarely require you to open an attachment. Be especially cautious with PDFs or Word documents claiming to be invoices or receipts — these are a common delivery mechanism for malware. Embedded images that fail to load may indicate the email was sent from an unauthorized server that the retailer's image-hosting infrastructure rejected.

Warning: If your email client asks whether to download remote images from an unfamiliar sender, decline. Loading external images can confirm to attackers that your address is active.
6

Report and delete confirmed phishing attempts

Most email clients include a "Report phishing" or "Mark as spam" option. Reporting phishing emails helps your provider improve filters that protect other users. Delete the email after reporting rather than leaving it in your inbox, and do not forward it to friends or family without removing any live links first.

Tip: The Federal Trade Commission (FTC) maintains a reporting channel at reportfraud.ftc.gov where you can also flag phishing attempts targeting U.S. consumers.

Use Your Account Dashboard as Ground Truth

Every major retailer maintains an order history page within your account. If you receive an order or shipping email and feel uncertain, log in directly through your browser and check the dashboard. If the order doesn't appear there, the email almost certainly didn't come from the retailer.

Never Enter Credentials Through an Email Link

If an email prompts you to log in, reset a password, or confirm payment information, go directly to the retailer's website by typing the address into your browser instead. Phishing pages are engineered to look identical to real login screens. Entering credentials on one can hand criminals full access to your account — and any saved payment methods attached to it.

What Happens After Credentials Are Stolen

If a phishing email successfully captures your login details, the consequences extend beyond a single compromised session. Attackers frequently use stolen credentials to attempt access across multiple platforms — a practice called credential stuffing — because many people reuse passwords. Saved payment methods, stored addresses, and loyalty point balances are all at risk.

Taking steps to lock down your retail accounts after any suspected phishing exposure is critical. Our guide on protecting your online shopping accounts from takeover covers practical measures to reduce that exposure.

Similarly, if an email link leads you to a site that looks like a retailer's checkout page, the page itself may be a clone. Familiar-looking websites can still be fraudulent — knowing the subtle tells that separate real storefronts from imitations adds another layer of protection.

Display Names Are Easy to Fake

An email can show "Amazon Customer Service" or "Target Orders" as the sender name while the actual sending address is a completely unrelated domain. Always expand the sender field to inspect the full email address, not just the friendly display name. This is one of the most commonly overlooked phishing tells.