# How to verify a sponsorship email in 5 minutes

A sponsorship email lands. The brand is real, the number is decent, the rep sounds friendly. Before you write back, spend five minutes acting like a security analyst. That is genuinely all it takes, because fake sponsor emails fail simple checks. They rely on you not running any.

Here is the exact sequence, in the order that catches the most fakes the fastest.

Minute 1: read the sender domain letter by letter

Not the display name. The display name is free text and anyone can put "NordVPN Partnerships" there. The part that matters is the domain after the @ sign.

Read it right to left, starting from the ending. Slowly. Your brain autocompletes famous names, which is exactly what typosquats exploit. Swap the final n in a VPN brand for an m and it still reads as the brand at a glance. A .co ending reads as .com. An rn pair can pose as an m, a 1 as an l, a Cyrillic letter as a Latin one your eye cannot distinguish at all.

Then ask one question: is this the domain that brand actually mails from? If the answer takes you more than a few seconds, that is what the rest of the checks are for.

Minute 2: check how old the domain is

Real brands mail from domains that are years old. Scam campaigns register their lookalike domain days before they start blasting creators, because the domains get reported and burned quickly.

Any free WHOIS or RDAP lookup shows a registration date. Search "whois" plus the domain, or use rdap.org. If the domain claiming to be a household brand was registered three weeks ago, you are done. Nothing else needs checking.

Minute 3: look up the mail records

This one sounds technical and takes thirty seconds. Real companies publish SPF and DMARC records, which are DNS entries that stop other people from forging mail in their name. A domain with no SPF and no DMARC, claiming to be a serious brand, is not that brand.

Search any free "SPF checker" or "DMARC lookup" tool and paste the domain in. No records, or a DMARC policy of none, is a flag on its own. Combined with a young domain, it is a verdict.

Minute 4: inspect every link before you touch it

Hover, do not click. On a phone, long-press to preview. Three things to look for:

And attachments: an archive file with the password written in the email is the single most reliable scam tell there is. Encrypting the file blinds every scanner between the sender and your download folder. Real brands send briefs as shared docs and plain PDFs.

Minute 5: pressure test the offer itself

Now read the deal like a buyer would.

When it passes all five

Then it is worth a reply, and one more step protects you completely: do not verify through the email. Type the brand's real domain into your browser yourself, find their partnerships or press contact, and confirm the campaign exists. If the offer is real, the person on the other end will not mind that you checked. Genuine partners are never offended by verification. Only fakes are in a hurry.

If you would rather have the whole sequence run for you, that is what we built. Paste the email at legitsponsor.com and you get the verdict with the evidence laid out: domain age, mail records, link targets, attachment analysis, and what the deal should actually pay for a channel your size. The first check is free and needs no account.

The five minutes above catch most fakes. The habit of running them catches the rest, because the one email you skip the checks on is the one they wrote for exactly that moment.