Trade-confirmation emails look official and carry money details, which makes them a favourite template for scammers. This checklist shows how to tell a genuine broker confirmation from a spoofed one — in about ten minutes, before you click, reply or pay.
Every time an order is filled, a regulated broker sends a trade-confirmation email: a record of the instrument, the size, the price, the time and a unique order reference. It is a normal, routine message. But because these emails look official and mention your money, they are one of the most common templates that fraudsters copy. A spoofed confirmation can push you to click a look-alike link, hand over your login on a fake page, or send an "urgent fee" to release funds that were never at risk.
The good news is that impersonation almost always leaves fingerprints. The nine checks below let you confirm a confirmation email really came from your broker, without trusting the message at face value. None of them require special software — just a careful look and, in one step, logging into your account the normal way.
Two things: (1) the email genuinely came from the broker's official domain and points only to that domain, and (2) the trade it describes actually exists in your account when you check independently. If either fails, treat the email as hostile until proven otherwise.
A sender domain that does not exactly match the broker's, a request to pay any fee to "release" or "unlock" funds, links that resolve to a different domain when you hover, pressure to act within minutes, a trade you never placed, or a reply address that differs from the broker's official support address. Any one of these is a reason to stop and verify independently.
Trade-confirmation emails are effective bait for three reasons. They arrive at a predictable moment — right after you trade — so a well-timed fake feels expected. They carry authority, because they look identical to a routine, official message. And they involve money, which makes people act quickly. Fraudsters exploit all three at once: a spoofed confirmation that mirrors a real one, sent when you are likely to be watching your account, asking for a small "fee" that feels plausible in context.
That is why the strongest single defence is step four: never let the email be your source of truth. Confirm every trade by logging into the platform the normal way. If the email and your account disagree, your account is right and the email is wrong.
Choosing an EU-regulated broker gives you client-money protections — segregation, an investor-compensation backstop, negative balance protection — if the broker itself fails. It does not stop a third party from impersonating that broker by email. Regulation secures the custody of your money; this checklist secures you against being tricked into handing it over.
If you clicked a link and entered your login on a page you now doubt, change your broker password immediately and enable two-factor authentication if it is available. If you sent any payment, contact your bank or card provider to report it and ask about a chargeback. Then tell the broker through its official support channel so it can watch your account and warn other clients. Acting fast limits the damage.
Our EU shortlist covers only brokers regulated by CySEC, BaFin, the FCA or equivalent — with the regulated entity and licence set out clearly, so a genuine email is easy to confirm.
See the EU broker guide →It is the automated message a broker sends after an order is filled, confirming the instrument, size, price, time and a unique order reference. Regulated brokers send these as a record of each transaction. Because they look official and contain money details, they are a common template for phishing scams.
Check the full sender domain character by character, hover over links to see the real destination before clicking, and log in to the platform independently to confirm the trade exists. Genuine confirmations never demand an urgent extra payment or fee to release funds. When in doubt, contact the broker through the details on its official website, not the ones in the email.
Avoid it as a default. Hover to reveal the true destination first, and where possible reach your statements by logging into the platform yourself instead of clicking an emailed link. Spoofed emails hide look-alike domains behind normal-looking link text.
Do not reply, click, open attachments or send any payment. Log in to your account independently to check the real trade history, then contact the broker through the phone number or support address on its official website. If you already entered details on a linked page, change your password and tell the broker immediately.
No. Using a regulated EU broker gives you client-money protections if the broker itself fails, but scammers can still impersonate any brand by email. Regulation protects the custody of your funds; it does not stop a third party from sending you a spoofed message. The checks in this guide are how you protect yourself from impersonation.