Check a “new bank details” email before you pay

Paste the sender's address. We check how old their domain is, whether it imitates your supplier's, and how it's set up for email. Free, no signup.

Enter the sender's email address, or paste the headers below.

Lets us spot lookalike domains. Take it from an old invoice, not from the new email.

Paste the email headers (optional, more accurate)

How to copy the headers in Outlook, Gmail and Apple Mail.

We don't save the addresses or headers you enter.

Before you change any bank details

  1. Don't use the contact details in the email. Not its phone number, links or reply address.
  2. Call your supplier on a number you already had, from an old invoice or your own records, and ask them to confirm the new details.
  3. Get a second person to approve the change before any payment goes out.
  4. Write down who confirmed it, how and when. Your bank may ask for this record.

What the check looks at

Signals from public records and, if you paste them, the email's own headers.

Domain age

When the sender's domain was registered, from its registry (RDAP, with WHOIS as a fallback). Scam domains are often days old.

Lookalike domains

Compares the sender's domain with your supplier's: swapped, missing or extra letters, characters that look alike such as “rn” and “m”, added words and different endings.

Free email services

Flags Gmail, Outlook.com, Yahoo and other free mailboxes, where anyone can open an address in a minute.

Email set-up

Whether the domain can receive mail, and whether it publishes a DMARC policy that stops others faking it.

Headers optional

Your mail server's SPF, DKIM and DMARC results for the message, and whether replies would go to a different domain.

How these scams usually work

A lookalike domain

The scammer registers a domain one letter away from your supplier's, often days before, and sends “new bank details” from it.

A hacked real mailbox

The scammer gets into your supplier's email and sends the change from their real address, often inside an existing thread. Only a phone call catches this.

A different reply address

The email shows your supplier's name, but replies go to an address the scammer controls, so your questions reach them.

Nacha's fraud-monitoring rule, in plain terms

Nacha writes the rules for ACH, the US bank-transfer network.

Since June 22, 2026 (the rule date was June 19), Nacha's fraud-monitoring rule covers every business that sends ACH payments through its bank. The largest senders were covered from March 20.

  • You need a risk-based process to spot payments made under false pretenses: someone pretending to be a supplier, an employee or anyone else you pay, or lying about who owns the bank account.
  • There's no small-business exemption, and the process has to be reviewed at least once a year.
  • If a payroll or bill-pay provider sends payments for you, ask them how they handle it.

Practical steps that address the most common scam: check every bank-detail change by calling a number you already have, have a second person approve it, and keep a record of who checked, how and when.

Plain summary, not legal advice; ask your bank what it expects. Source: Nacha, Fraud Monitoring Phase 2.

How to copy the headers

Headers show what your mail server found when the email arrived. Paste all of them into the box above.

Outlook (new and web)

Open the email, select More actions (…) > View > View message details, then copy all the text.

Outlook (classic desktop)

Open the email in its own window, then File > Properties. Copy everything in the Internet headers box.

Gmail

Open the email, select More (⋮) > Show original, then Copy to clipboard.

Apple Mail

Open the email, then View > Message > All Headers, and copy the header lines at the top.

Get this inside Outlook and Gmail

We're building an add-in that runs these checks on supplier emails as they arrive and keeps a record of how each bank change was verified, ready for your bank or insurer.

Join the waitlist and we'll email you once when it's ready to try.

A confirmation email now, then one email when it's ready.

Frequently asked questions

Is the check free?

Yes. There's no signup. You can run up to 30 checks a day from one network.

Do you store the email I paste?

No. We use the addresses and headers you enter to look up the domains and show you the result, then discard them. The domains themselves are handled like any other lookup on this site: public results such as registration dates and DNS records are cached for up to an hour.

If it says "No warning signs found", is the email safe?

Not necessarily. If your supplier's real mailbox was hacked, the email comes from their real domain and passes every check here. Always confirm a bank change by calling your supplier on a number you already have.

What is a lookalike domain?

A domain made to look like your supplier's at a glance: an extra or missing letter, two letters swapped, "rn" in place of "m", an added word such as "-billing", or a different ending such as .co instead of .com.

Why does the age of the domain matter?

Scammers usually register a lookalike domain shortly before they use it. A domain registered days ago that claims to belong to a supplier you've paid for years is a strong warning sign.

What are SPF, DKIM and DMARC?

Checks that let mail servers confirm an email really came from the domain it shows. If the headers show the email failed DMARC, it did not come from the domain it claims. Paste the headers to see these results.

Does the Nacha fraud-monitoring rule apply to my business?

If your business sends ACH payments through its bank, it does: there is no small-business exemption. If a payroll or bill-pay provider sends the payments for you, ask that provider how it complies. This is a plain summary, not legal advice; your bank can tell you what it expects.

What will the add-in do?

It will run these checks on supplier emails inside Outlook and Gmail and keep a record of how each bank change was verified. It isn't available yet. Join the waitlist and we'll email you once when it's ready to try.