Blog · Dmarc

Someone Used My Email for Online Purchases. Is It a Scam?

Someone Used My Email for Online Purchases. Is It a Scam?

You open your inbox and see it: a confirmation from Amazon, a receipt from Walmart, an order update from a store you have never heard of. The email is addressed to you. Your name is there. Your email address is there. But you did not make the purchase.

This is one of the most common email-related questions people encounter, and the answer is more reassuring than most people expect.

The short version: receiving a purchase confirmation you did not authorize usually does not mean your account is compromised. It means someone typed your email address by mistake, or a scammer is testing a stolen card and needed a place to send the receipt.

This article walks through exactly what happened, why it usually is not a scam, when to worry, and what to do next.

Why You Received a Confirmation You Did Not Order

There are several plausible explanations, and most of them are harmless.

A typo in the checkout field. The most common reason. Someone is checking out on a website, types their email address incorrectly, and happens to land on yours. A transposed digit, a fat finger on a phone keyboard, someone mixing up first and last name combinations. The order is real, the purchase is real, the email is just in the wrong inbox.

A shared family email address. Multiple people in a household sometimes share an email address. A partner, a teenager, a roommate orders something and the confirmation lands in the shared inbox.

A checkout flow quirk. Some merchants send order confirmations to the email address in the billing contact field, which is separate from the account email. Someone may have used your address for a one-time guest checkout and the merchant's system stored it for future orders.

None of these scenarios involve your account being compromised. Your password is fine. Your credit card is probably fine. The email was just delivered to the wrong person.

The Scam Scenarios

There are also deliberate reasons a scammer may use your email address at checkout.

Card testing. This is the most common fraudulent use case. Someone with a stolen credit card number needs to find out if the card is still active. They go to a merchant, fill in the card details, and use a random email address to receive the confirmation. If the charge goes through, they know the card works and can use it for bigger purchases. If it fails, the failed charge goes to a stranger's inbox, not theirs.

The confirmation you received may be a byproduct of this process. The scammer does not care that the email went to a real person. They only care whether the charge succeeded.

Address verification fraud. Some scammers use your address to verify that a stolen card's billing address is correct. The package gets shipped to your address, but an intercept or porch theft is planned. The confirmation email is sent to you because the merchant's system flagged your address as the billing address on the card.

Wish-list or account spoofing. Less common, but sometimes scammers create accounts with your email address to build a fake purchase history or to hijack a loyalty account.

In all these cases, the scam is aimed at the merchant or the card issuer. You are an incidental recipient, not a target.

How to Tell if YOUR Account Was Actually Compromised

Here is the key distinction: receiving a purchase confirmation sent TO you is different from someone using your email account as a sender.

An email has two relevant address fields:

  • To: the recipient. This is your address.
  • From: the sender. This tells receivers where the message originated.

A purchase confirmation is addressed TO you. It was delivered to your inbox because the merchant sent it to your email address. Unless the email's From field shows your own domain as the sender, your account is not the source of this message.

If your actual email account were compromised, you would see:

  • Sent emails you did not write. Check your sent folder.
  • Password change notifications. From services you did not attempt to log into.
  • Login alerts. From unfamiliar locations or devices.
  • Account recovery emails. Telling you your password or phone number was changed.

If none of those are present, your email account is almost certainly safe.

What to Check Right Now

Work through this short checklist in order.

1. Look at the email headers. Does the From address show the merchant's official domain? Is the To address your email? If the From address is something odd or the email looks like phishing, do not click any links. Go directly to the merchant's website by typing the URL yourself.

2. Check your credit card statements. Look for the transaction amount shown in the email. If it is there and you did not authorize it, call your card issuer immediately and report it.

3. Check your own accounts. Log into the merchant's website directly (not from a link in the email) and look at your order history. If there is an order you did not place, report it to the merchant.

4. Check your sent folder and login history. For the email account itself, look for sent messages you did not write. For any online accounts you are worried about, check recent login activity.

5. Change passwords if you are unsure. If you have any doubt whatsoever, change the password for the email account and any account where you use the same or similar password.

What If My Email Domain Is Being Spoofed?

This is a separate concern for domain owners. If you manage a domain and you suspect it is being used as a From address in unauthenticated email, the tool you need is a DMARC aggregate report.

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication standard. When a domain publishes a DMARC policy, receiving mail servers report back on every email that claims to come from that domain, whether it passed or failed authentication.

If your domain is being spoofed, those reports will show emails with your domain in the From header that did not come from your actual mail servers. DMARCFlow aggregates those reports and displays them in a dashboard, so you can see at a glance which IPs are sending mail as your domain and whether they are passing authentication.

The practical workflow for domain owners:

1. Check your DMARC aggregate reports. Look for the failure rate on emails claiming to come from your domain. If you see failures from IP addresses you do not recognize, your domain is likely being spoofed.
2. Identify the source. The DMARC report shows the sending IP and the authentication result. Cross-reference against your own sending infrastructure.
3. Enforce p=reject. Once you have confirmed your legitimate senders are aligned, setting your DMARC policy to p=reject tells receiving mail servers to refuse any email that claims to come from your domain without proper SPF or DKIM authentication. This is the strongest protection against domain spoofing.

DMARCFlow is purpose-built for this. The aggregate report dashboard shows aligned authentication results across all major receivers (Google, Yahoo, Microsoft, Apple, and others), with failure alerts that fire when a previously passing sender starts failing. For domain owners investigating whether their domain is being misused in checkout flows or phishing campaigns, this is the fastest way to get evidence.

When to Contact the Merchant

If you received a confirmation for an order you did not place, it is worth contacting the merchant to:

  • Alert them that someone may be using a stolen card with their service
  • Confirm whether an account was created in your name
  • Request that the order be cancelled if it has not shipped

Most large merchants have a fraud department. A brief note through their official support channel can trigger a review of the account and possibly prevent the package from being shipped.

Do not use reply-to links in the suspicious email. Go directly to the merchant's website and use their contact form.

How to Reduce Future Occurrences

If you are tired of receiving other people's order confirmations:

Use a plus-addressing pattern. Many email providers support sub-addressing, where you can add a tag like yourname+amazon@example.com. Emails to that address still arrive in your inbox, but you can filter them separately and identify which service leaked or misused your address.

Use a unique email for each service. A dedicated email address for shopping, another for financial services, another for everything else. If one merchant's database is breached or shared, the exposure is contained.

If you manage a domain, enforce DMARC p=reject. This prevents anyone from sending email that appears to come from your domain without proper authentication. It reduces spoofing-related confusion and protects your recipients from phishing.

Frequently Asked Questions

Does this mean someone has my password?

No. Receiving a purchase confirmation does not mean your email password or any other password is compromised. The email was sent to you as the recipient, not sent from your account. If you want to confirm, check your sent folder and your account's recent login activity.

Should I click the unsubscribe link?

Be careful. If the email is legitimate (someone just typed the wrong address), unsubscribing affects nothing. If the email is a phishing attempt or card testing, clicking unsubscribe confirms your email address is active, which may lead to more spam. When in doubt, navigate directly to the merchant's website instead of clicking any link in the email.

Can someone use my email address to make purchases without my knowledge?

No. Making a purchase requires access to a payment method. Your email address alone is not enough. Receiving a confirmation means the charge went to someone else's payment method and the receipt was sent to your inbox. That is different from someone spending your money.

What is card testing exactly?

Card testing is when someone with a stolen card makes small purchases to verify the card is active before making larger purchases. They choose merchants, enter card details, and use a random email address to receive confirmations. The goal is to fly under the radar: small charges, anonymous inbox, no link back to the scammer.

My email was used as the sender address. Does that mean my account is compromised?

Not necessarily. The email's From field can be set to anything by the sender. This is how spoofing works. What matters is whether your actual email account shows unauthorized activity. Check your sent folder, password changes, and login history. If those are clean, your account has not been accessed.

How can I tell if my email domain is being spoofed?

Domain owners can check DMARC aggregate reports. If your domain shows up in failures from IP addresses you do not recognize, your domain is being used in the From header of unauthenticated email. DMARCFlow aggregates those reports and sends real-time alerts when your domain appears in authentication failures, which is the fastest way to catch spoofing.

What can domain owners do to prevent this?

Set your DMARC policy to p=reject. This tells receiving mail servers to refuse any email that claims to come from your domain but does not pass SPF or DKIM authentication. It is the strongest protection against domain spoofing.

The Bottom Line

Receiving a purchase confirmation you did not authorize is alarming, but in most cases it is harmless. A typo sent someone else's receipt to your inbox. The fix is to verify your accounts are clean, check your card statements, and move on.

The cases that warrant real concern are the ones where you also see unauthorized charges, password reset emails, or login notifications from accounts you do not recognize. Those are signs of actual compromise.

If you manage a domain and want to know whether your domain is being misused in email headers, DMARCFlow aggregates your DMARC reports and alerts you to authentication failures in real time. That visibility is the first step toward enforcing p=reject and stopping spoofing at the source.

DMARCFlow monitors your domain's email authentication health, including DMARC, SPF, and DKIM. Set up a free account to receive real-time alerts when your domain's email fails authentication or appears in unexpected senders' DMARC reports.