Run these four checks on that publishing email before you reply
/Debbie Nowak turns Writer Beware's scam-email roundup into four header checks a writer can actually run before hitting reply.

TL;DR: Victoria Strauss at Writer Beware, the scam-watch blog run under the Science Fiction and Fantasy Writers Association, published a catalogue of real scam addresses pulled from writer complaints: fake NPR interview requests from info.us.npr@gmail.com, a fake literary agency at therightsfactoryagency@proton.me, a lookalike Random House domain missing nothing but doubled letters, a lookalike WME domain at us-wmeagency.com standing in for the real wmeagency.com. None of it requires special tools to catch. It requires reading the header instead of the signature. Here’s the four-check version I’d actually run before I hit reply.
I’ve cleaned up after this kind of incident more times than I can count, just not in publishing. Same shape every time: something arrives looking official, someone downstream trusts the display name instead of the source, and by the time anyone checks the actual origin the damage is done. Writer Beware’s rundown of scam solicitation emails targeting authors is, underneath the publishing dressing, an incident report. So I’m reading it like one.
Strauss’s core claim: legitimate publishing professionals, agents, and film people rarely reach out to writers first, and when they do, they email from a company domain. The scams she’s cataloguing don’t. They lean on two failure modes, and both show up in the actual address, not the body of the email.
Check one: is the domain personal mail pretending to be corporate. Strauss lists addresses like info.us.npr@gmail.com claiming to be NPR, penamerica.event@gmail.com claiming to be the PEN America Literary Gala, and ballyscullionbookfest@gmail.com claiming to be a book festival. A real newsroom or a real literary org owns its own domain. If the “from” field is a free consumer host, gmail.com, aol.com, proton.me, and the signature claims a company job title, that mismatch is your first check and it clears most of the pile by itself.
Check two: is the domain a lookalike, not a match. This one takes more than a glance. Strauss found bookssubmissions@hachettebookgroup.ink standing in for the real @hbgusa.com, and dan.lazar@writershouseliterary.com standing in for the real @writershouse.com. The trick is padding, not hiding, an extra word or a swapped extension bolted onto something that reads correctly at a skim. The fix is boring and it works: load the bare domain in a browser. A real company has a real site behind it. A scam domain returns nothing, or a placeholder built to survive exactly one glance.
Check three: is it a character swap, not a padding job. The nastier version, and the one Strauss flags as genuinely hard to catch, swaps a letter instead of adding a word. A “1” for an “l,” two letters transposed, an extra “i” slipped into “publishiing” against the real @skyhorsepublishing.com. This is the same move manuscript thief Filippo Bernardini ran for years before he was caught, and it beats a skim every time. It does not beat a copy-paste into a text editor at a monospace font, where an extra character stands out because the line no longer aligns. Run that on anything that smells wrong before you click a link inside it.
Check four: does the name in the “From” line match the name in the signature. Strauss’s examples here are almost funny in hindsight: a sender named Nathan Lewis whose address belongs to a Nathan Wellis, a “Caarolyn” in the header signing off as “Carolyn” below. That’s not a typo pattern a real assistant makes twice. It’s the seam where two people, or one person and one script, stopped coordinating. It costs nothing to check and it catches things the domain check misses entirely.
None of these four checks require a security background. They require doing to your inbox what I’d do to a server log before I trust it: read the header before the body, because the body is where the con is designed to work and the header is where it’s designed not to be looked at.
One thing I’d add that Strauss doesn’t spell out as a standalone step, because it’s obvious to her the way file permissions are obvious to me: none of these checks matter if you only run them once. Strauss writes that over the past year, the Gmail addresses “almost universally used” by an aggressive wave of AI-driven marketing and impersonation scams she traces to Nigeria have become a warning sign on their own, separate from any of the four checks above. That’s a pattern shift inside a single year. The four checks above catch this month’s version. They won’t catch whatever shape it takes by the time this piece is a year old, only the habit of running them will. Writer Beware keeps a running impersonation list for exactly that reason, and it’s worth bookmarking next to whatever you use to track submissions. Run the four checks tonight on whatever’s sitting unanswered in your inbox.
Comments are open to members. Sign up free →