Quick answer
Treat an unexpected counterfeit-product email as an untrusted advertisement. Don't click its links, reply, open attachments, enter payment details, or pay with a gift card or cryptocurrency. Instead, open the brand's website, a known retailer, or the marketplace app yourself and look for the offer and seller there.
A fake offer may lead to a counterfeit item, a fake checkout page, a stolen-payment form, or malware. If you already paid or shared information, contact the relevant bank, card issuer, marketplace, gift card company, or cryptocurrency exchange immediately. Save the evidence, secure any exposed accounts, and report the scam. This guidance is for U.S. consumers; dispute and refund options depend on the payment method, issuer, marketplace, and transaction details.
A safe, redacted example of a counterfeit-product scam email
Use this example for recognition training. The domain is intentionally nonfunctional, and the link destination has been omitted.
Subject: Last hours: [Brand] [Product] 85% off
From: Brand Outlet - offers@[brand]-clearance.example
Dear customer,
Our exclusive stock is almost gone. Buy the genuine [product] today for
85% off the usual price. This offer expires tonight.
[Shop now - destination withheld]
To reserve your order, pay by cryptocurrency or gift card.
Shipping documents will follow after payment.
Brand Promotions Team
Red flags in the example
- An implausible price: An expensive watch, designer bag, phone, or pair of earbuds offered at a fraction of the normal price needs independent verification.
- Artificial urgency: "Last hours," "almost gone," and "expires tonight" are designed to keep you from checking the seller.
- A lookalike sender: The display name says "Brand Outlet," but the actual address uses an unrelated domain.
- Unusual payment demands: Gift cards and cryptocurrency can be difficult to recover after payment. Asking for either method to "reserve" ordinary merchandise is a major warning sign.
- A generic greeting: This doesn't prove fraud by itself, but it adds to the pattern when other warning signs are present.
- Paperwork promised later: A receipt, warranty, or shipping document sent after payment doesn't show that the item is genuine.
- Copied branding: Logos, product photos, colors, and official-sounding language can all be copied.
Some scam messages look much more polished. One may advertise a fake Rolex or designer handbag; another may pose as an AirPods warranty notice, a holiday sneaker sale, or a shipping update with an attachment. The product changes, but the pressure tactics are often similar.
How to check the email and the seller
1. Inspect the complete sender address
The name beside an email is easy to fake. Expand the sender details and check the full address. Look for misspellings, extra words, unusual subdomains, and domains that imitate a brand without belonging to it.
A domain mismatch is a strong warning sign, but a plausible-looking address isn't proof that the sender is authorized. Some legitimate retailers sell branded products from their own domains. Find the retailer through the brand's official website or a marketplace you already know instead of relying on the email.
2. Check links without opening them
On a computer, hover over a link to preview its destination. On a phone, don't tap an unfamiliar link merely to inspect it. The safer option is to open a new browser window or the official brand app and type the address yourself.
Be cautious when a link:
- Uses a domain unrelated to the advertised brand
- Contains misspellings or extra words in the domain
- Is shortened and hides the destination
- Sends you to a login page before showing the offer
- Opens a checkout form requesting information the purchase doesn't require
HTTPS or a padlock only indicates that the connection is encrypted. It doesn't prove the site's ownership, inventory, product authenticity, or refund practices.
3. Verify the offer independently
Don't search only for the exact wording in the email. Scammers can copy product descriptions and create convincing reviews. Search for the seller separately and compare the offer with the brand's official site or a known marketplace.
Check whether:
- The discount is realistic for the product and seller
- The seller has a clear return policy and reachable customer service
- A real business address and recognizable payment process are provided
- The same offer appears on the brand's official website or verified account
- The seller's terms explain what happens if the item is counterfeit, damaged, or never delivered
A seller's positive reviews, product photos, certificates, or copied brand language can be fabricated. Several warning signs together are enough reason to stop, even if you can't prove exactly how the scam works.
4. Treat unexpected attachments as unsafe
A fake invoice, warranty card, order confirmation, or shipping document may contain malware or lead to another phishing page. Don't open an unexpected attachment because it uses a familiar logo or mentions a product you recently viewed.
If you made a purchase, check the order through the retailer's official website or app. Don't use an invoice or shipping file supplied by the suspicious message.
Product-specific checks
A product check can support a decision, but no single photo, serial number, or email proves authenticity.
AirPods and other electronics
Apple's AirPods identification guide explains how to find the model number in the device settings when the AirPods are connected. Compare that information with Apple's official product details, while also considering the seller, packaging, price, condition, and purchase documentation.
A matching model number doesn't prove that the seller is authorized or that every component is genuine. When authenticity matters, use a trusted sales channel and contact the manufacturer's official support route with questions about a specific item.
Luxury watches, bags, and jewelry
Before paying, ask the brand or an authorized retailer about its authentication, warranty, and repair policies. Logos, certificates, packaging, and hallmarks can be copied or paired with a counterfeit item.
Don't let a seller rush you by claiming that another buyer is waiting. Take time to verify the item, payment terms, and return process.
Why the pressure works
These emails combine familiar sales techniques with risk:
- Price anchoring: A high "regular" price can make a large discount seem credible.
- Scarcity: Limited-stock claims encourage an impulse purchase.
- Borrowed authority: Brand names, logos, warranty language, and official-sounding titles create credibility.
- Social proof: Claims such as "thousands already ordered" make the offer appear safer.
- Fear of missing out: The message frames delay as a loss.
- Escalating requests: After you click, provide details, or pay a small fee, the sender may ask for more money.
A pause breaks that sequence. Close the message, verify the seller from an independently opened site, and ask someone you trust to review the offer if you're still tempted.
Scam email versus a safer retail message
| Signal | Common in a counterfeit scam | What a safer message allows |
|---|---|---|
| Price | Extreme discount with no credible explanation | Clear pricing and sale terms that can be checked independently |
| Sender | Lookalike domain or unrelated address | Sender and business can be verified through a known channel |
| Link | Destination differs from the advertised business | The same offer is available by visiting the official site yourself |
| Tone | Countdown, immediate action, or fear of missing out | Enough time to review the seller and terms |
| Payment | Gift card, cryptocurrency, wire, or another hard-to-recover method | A payment method and checkout process you recognize |
| Product proof | Copied photos, vague warranty, or certificate claims | Product and seller information that can be verified |
| Attachment | Unexpected invoice, shipping file, or compressed document | Order details available in the official account |
| Returns | Missing, vague, or difficult-to-find policy | Written terms available before payment |
No single row proves that an email is fraudulent. A cluster of warning signs should be enough to stop the transaction.
What to do if you clicked, paid, or received a counterfeit
If you only opened the email
Close it and don't interact with it further. Opening an email alone doesn't necessarily mean that your account or device was compromised, but don't click links, open attachments, or reply to requests for information.
If you entered a password
Use a bookmark or a typed address to reach the real service. Change the exposed password and any other account password that you reused. Turn on multifactor authentication, then review recent sign-ins and account changes.
Don't use a password-reset link from the suspicious email.
If you shared card or bank information
Call your bank or card issuer using the number on your card, official statement, or the institution's known website. Ask which protective steps and dispute process apply.
If a debit card was used without authorization, or you were tricked into making a debit-card payment, the FTC's guidance on what to do after a scam says to report it to your bank or credit union immediately.
For a credit-card purchase, describe the problem accurately. Explain whether the product was counterfeit, never arrived, or differed materially from the listing. If you made the payment yourself, don't describe it as an unauthorized transaction. A billing dispute is separate from asking the seller for a refund, and a dispute doesn't guarantee that the charge will be reversed. Follow the issuer's instructions and save the case number.
If you paid with a gift card or cryptocurrency
Contact the gift card issuer or cryptocurrency exchange immediately and ask whether any action is still possible. Keep the receipt, card number, wallet address, transaction details, and all communications.
Be wary of anyone who promises to recover the money for an upfront fee. That may be a second scam. The FTC warns that money paid to a scammer may already be gone, so speed matters, but recovery isn't guaranteed.
If the product arrived
Photograph the item, packaging, labels, listing, order confirmation, tracking record, and suspected counterfeit features. Keep the messages and payment records. Don't resell a product you believe is counterfeit.
Ask the seller for a refund through a verified contact method. If necessary, open a claim with the marketplace or payment provider. Don't send more money for a "release," "insurance," or "customs" charge unless you independently verify the request.
If you opened a suspicious attachment or installed software, stop using the device for banking. Disconnect it from the internet if practical and seek help from a trusted security professional. Report a work device to your employer's IT team.
How to report the scam
- Report the email to the FTC. The FTC's phishing guidance says to forward phishing emails to
[email protected]and report the attempt through ReportFraud.ftc.gov. Forward suspicious text messages to 7726, or SPAM. - Report an online product or payment scam to IC3. Use the IC3 complaint FAQ to file a complaint and save the confirmation. IC3 analysts review complaints and may share information with law enforcement or partner agencies, but IC3 doesn't conduct investigations or provide an investigation status.
- Report the seller to the marketplace. The Office of the Comptroller of the Currency's consumer product and retail fraud guidance recommends contacting the e-commerce platform, seller or manufacturer, and IC3 as appropriate.
- Notify the brand. Use contact information from the brand's official website, not the email. Include the fake domain, screenshots, listing, and product information.
- Keep an evidence file. Save the original message, complete sender details, headers if available, screenshots, link addresses without opening them, receipts, transaction records, tracking information, and relevant dates.
Type agency and brand addresses yourself. Don't use a reporting or recovery link sent by the scammer.
Limits to keep in mind
- A report may help a platform, brand, or agency identify a pattern, but it isn't an immediate refund request.
- Credit-card and debit-card procedures differ. Describe what happened accurately and follow the issuer's process.
- Gift-card and cryptocurrency payments can be especially difficult to recover. Contact the provider without delay.
- A genuine-looking domain, receipt, product serial number, or logo isn't conclusive proof of authenticity.
- Marketplace claim windows and issuer procedures may have deadlines. Start the process as soon as you notice the problem.
Frequently asked questions
Can a legitimate brand email come from a different domain?
It can come from an authorized retailer, marketing provider, or service partner, but the different domain doesn't make the message safe automatically. Verify the sender and offer through the brand's official website or a retailer support page that you locate independently.
Is an HTTPS checkout page safe?
HTTPS protects the connection between your browser and the site. It doesn't verify who owns the site, whether the inventory is genuine, or whether the seller will honor a refund.
Can a serial number prove that AirPods are genuine?
No single product detail should be treated as conclusive. Use Apple's official identification information to check the model, then consider the seller, documentation, condition, price, and purchase channel.
Can I get my money back from a counterfeit-product scam?
Possibly, but there is no universal guarantee. Contact the card issuer, bank, gift card company, cryptocurrency exchange, marketplace, or other payment provider immediately. The available process depends on how you paid and what happened.
If the message is still open, close it now and verify the seller only through a website or app you opened yourself.