How it works
This one splits the identity in two. The from-address is dressed to look corporate, sometimes a lookalike SoFi domain, sometimes a generic business-sounding one, so the header passes a glance. But the reply-to field is set to a personal mailbox the scammer actually controls. When you hit reply, your message silently goes to that Gmail or Outlook account instead of anywhere near SoFi, and everything after that happens in a channel the brand cannot see. Real senders have no reason to route replies away from their own domain, so a corporate-looking front paired with a personal reply-to is a spoofing pattern, not a quirk of their mail setup. Finance apps are a common skin because the money framing feels normal.
The tell-tale signals
- The from-domain and the reply-to domain disagree, and the reply-to is a personal webmail account. Check where a reply would actually go before you send one.
- The visible sender may be a lookalike, or an unrelated domain claiming to be SoFi, whose real domain is sofi.com.
- The domain may be recently registered with weak authentication.
- The pitch may add urgency or ask to move to a messenger app to close quickly.
What to do
Before replying, look at the reply-to address, not just the from-line. Most clients show it if you expand the header or start a reply and read the To field. If replies go to a personal inbox while the sender pretends to be a company, stop and do not continue the thread. Verify through sofi.com's own partnerships or affiliate contact, started from the site rather than from anything in the email. If you already replied, do not send any further details, contracts, or payment information, and treat the exchange as compromised.