Quick answer

Treat an unexpected counterfeit-product email as an untrusted advertisement. Don't click its links, reply, open attachments, enter payment details, or pay with a gift card or cryptocurrency. Instead, open the brand's website, a known retailer, or the marketplace app yourself and look for the offer and seller there.

A fake offer may lead to a counterfeit item, a fake checkout page, a stolen-payment form, or malware. If you already paid or shared information, contact the relevant bank, card issuer, marketplace, gift card company, or cryptocurrency exchange immediately. Save the evidence, secure any exposed accounts, and report the scam. This guidance is for U.S. consumers; dispute and refund options depend on the payment method, issuer, marketplace, and transaction details.

A safe, redacted example of a counterfeit-product scam email

Use this example for recognition training. The domain is intentionally nonfunctional, and the link destination has been omitted.

Subject: Last hours: [Brand] [Product] 85% off

From: Brand Outlet - offers@[brand]-clearance.example

Dear customer,

Our exclusive stock is almost gone. Buy the genuine [product] today for
85% off the usual price. This offer expires tonight.

[Shop now - destination withheld]

To reserve your order, pay by cryptocurrency or gift card.
Shipping documents will follow after payment.

Brand Promotions Team

Red flags in the example

Some scam messages look much more polished. One may advertise a fake Rolex or designer handbag; another may pose as an AirPods warranty notice, a holiday sneaker sale, or a shipping update with an attachment. The product changes, but the pressure tactics are often similar.

How to check the email and the seller

1. Inspect the complete sender address

The name beside an email is easy to fake. Expand the sender details and check the full address. Look for misspellings, extra words, unusual subdomains, and domains that imitate a brand without belonging to it.

A domain mismatch is a strong warning sign, but a plausible-looking address isn't proof that the sender is authorized. Some legitimate retailers sell branded products from their own domains. Find the retailer through the brand's official website or a marketplace you already know instead of relying on the email.

2. Check links without opening them

On a computer, hover over a link to preview its destination. On a phone, don't tap an unfamiliar link merely to inspect it. The safer option is to open a new browser window or the official brand app and type the address yourself.

Be cautious when a link:

HTTPS or a padlock only indicates that the connection is encrypted. It doesn't prove the site's ownership, inventory, product authenticity, or refund practices.

3. Verify the offer independently

Don't search only for the exact wording in the email. Scammers can copy product descriptions and create convincing reviews. Search for the seller separately and compare the offer with the brand's official site or a known marketplace.

Check whether:

A seller's positive reviews, product photos, certificates, or copied brand language can be fabricated. Several warning signs together are enough reason to stop, even if you can't prove exactly how the scam works.

4. Treat unexpected attachments as unsafe

A fake invoice, warranty card, order confirmation, or shipping document may contain malware or lead to another phishing page. Don't open an unexpected attachment because it uses a familiar logo or mentions a product you recently viewed.

If you made a purchase, check the order through the retailer's official website or app. Don't use an invoice or shipping file supplied by the suspicious message.

Product-specific checks

A product check can support a decision, but no single photo, serial number, or email proves authenticity.

AirPods and other electronics

Apple's AirPods identification guide explains how to find the model number in the device settings when the AirPods are connected. Compare that information with Apple's official product details, while also considering the seller, packaging, price, condition, and purchase documentation.

A matching model number doesn't prove that the seller is authorized or that every component is genuine. When authenticity matters, use a trusted sales channel and contact the manufacturer's official support route with questions about a specific item.

Luxury watches, bags, and jewelry

Before paying, ask the brand or an authorized retailer about its authentication, warranty, and repair policies. Logos, certificates, packaging, and hallmarks can be copied or paired with a counterfeit item.

Don't let a seller rush you by claiming that another buyer is waiting. Take time to verify the item, payment terms, and return process.

Why the pressure works

These emails combine familiar sales techniques with risk:

A pause breaks that sequence. Close the message, verify the seller from an independently opened site, and ask someone you trust to review the offer if you're still tempted.

Scam email versus a safer retail message

Signal Common in a counterfeit scam What a safer message allows
Price Extreme discount with no credible explanation Clear pricing and sale terms that can be checked independently
Sender Lookalike domain or unrelated address Sender and business can be verified through a known channel
Link Destination differs from the advertised business The same offer is available by visiting the official site yourself
Tone Countdown, immediate action, or fear of missing out Enough time to review the seller and terms
Payment Gift card, cryptocurrency, wire, or another hard-to-recover method A payment method and checkout process you recognize
Product proof Copied photos, vague warranty, or certificate claims Product and seller information that can be verified
Attachment Unexpected invoice, shipping file, or compressed document Order details available in the official account
Returns Missing, vague, or difficult-to-find policy Written terms available before payment

No single row proves that an email is fraudulent. A cluster of warning signs should be enough to stop the transaction.

What to do if you clicked, paid, or received a counterfeit

If you only opened the email

Close it and don't interact with it further. Opening an email alone doesn't necessarily mean that your account or device was compromised, but don't click links, open attachments, or reply to requests for information.

If you entered a password

Use a bookmark or a typed address to reach the real service. Change the exposed password and any other account password that you reused. Turn on multifactor authentication, then review recent sign-ins and account changes.

Don't use a password-reset link from the suspicious email.

If you shared card or bank information

Call your bank or card issuer using the number on your card, official statement, or the institution's known website. Ask which protective steps and dispute process apply.

If a debit card was used without authorization, or you were tricked into making a debit-card payment, the FTC's guidance on what to do after a scam says to report it to your bank or credit union immediately.

For a credit-card purchase, describe the problem accurately. Explain whether the product was counterfeit, never arrived, or differed materially from the listing. If you made the payment yourself, don't describe it as an unauthorized transaction. A billing dispute is separate from asking the seller for a refund, and a dispute doesn't guarantee that the charge will be reversed. Follow the issuer's instructions and save the case number.

If you paid with a gift card or cryptocurrency

Contact the gift card issuer or cryptocurrency exchange immediately and ask whether any action is still possible. Keep the receipt, card number, wallet address, transaction details, and all communications.

Be wary of anyone who promises to recover the money for an upfront fee. That may be a second scam. The FTC warns that money paid to a scammer may already be gone, so speed matters, but recovery isn't guaranteed.

If the product arrived

Photograph the item, packaging, labels, listing, order confirmation, tracking record, and suspected counterfeit features. Keep the messages and payment records. Don't resell a product you believe is counterfeit.

Ask the seller for a refund through a verified contact method. If necessary, open a claim with the marketplace or payment provider. Don't send more money for a "release," "insurance," or "customs" charge unless you independently verify the request.

If you opened a suspicious attachment or installed software, stop using the device for banking. Disconnect it from the internet if practical and seek help from a trusted security professional. Report a work device to your employer's IT team.

How to report the scam

  1. Report the email to the FTC. The FTC's phishing guidance says to forward phishing emails to [email protected] and report the attempt through ReportFraud.ftc.gov. Forward suspicious text messages to 7726, or SPAM.
  2. Report an online product or payment scam to IC3. Use the IC3 complaint FAQ to file a complaint and save the confirmation. IC3 analysts review complaints and may share information with law enforcement or partner agencies, but IC3 doesn't conduct investigations or provide an investigation status.
  3. Report the seller to the marketplace. The Office of the Comptroller of the Currency's consumer product and retail fraud guidance recommends contacting the e-commerce platform, seller or manufacturer, and IC3 as appropriate.
  4. Notify the brand. Use contact information from the brand's official website, not the email. Include the fake domain, screenshots, listing, and product information.
  5. Keep an evidence file. Save the original message, complete sender details, headers if available, screenshots, link addresses without opening them, receipts, transaction records, tracking information, and relevant dates.

Type agency and brand addresses yourself. Don't use a reporting or recovery link sent by the scammer.

Limits to keep in mind

Frequently asked questions

Can a legitimate brand email come from a different domain?

It can come from an authorized retailer, marketing provider, or service partner, but the different domain doesn't make the message safe automatically. Verify the sender and offer through the brand's official website or a retailer support page that you locate independently.

Is an HTTPS checkout page safe?

HTTPS protects the connection between your browser and the site. It doesn't verify who owns the site, whether the inventory is genuine, or whether the seller will honor a refund.

Can a serial number prove that AirPods are genuine?

No single product detail should be treated as conclusive. Use Apple's official identification information to check the model, then consider the seller, documentation, condition, price, and purchase channel.

Can I get my money back from a counterfeit-product scam?

Possibly, but there is no universal guarantee. Contact the card issuer, bank, gift card company, cryptocurrency exchange, marketplace, or other payment provider immediately. The available process depends on how you paid and what happened.

If the message is still open, close it now and verify the seller only through a website or app you opened yourself.