
Like most authors these days, I’m getting constantly inundated with author scam messages. As someone familiar with the underlying technology, these are pretty easy for me to recognize, but I realized it might be worth documenting the kinds of features I use to identify them. Some of these are pretty obvious, while others are more subtle.
A great source of information is SFWA’s Writer Beware. Victoria Strauss has been writing about these scams as they’ve developed over the past couple of years. This impersonation scam has already been documented by Victoria — including the particular person being impersonated —which I’ll use here for my demonstration.
This message purports to be from an agent at a literary agent that would like to solicit the manuscript I’m currently querying with. In this case, the agent and agency are both real but this particular message is fake.

A couple of things to note first. One is that I’m using a desktop computer application to check my messages. If you use phone email clients, they often make it difficult to see the email address a message came from — or to consult the full headers. Second, is that my email client is configured to not load remote “content”. I recommend never, ever loading the remote content in email. It’s almost always web-bugged, meaning it uses a filename or server path that communicates to the sender that you’ve looked at the message. You really don’t want to ever do that. It does mean that messages sometimes look broken. But the “design” of email is easy to copy and so you shouldn’t ever let yourself be fooled by a message because it “looks” genuine.
One of the first things I do when I get one of these messages is to determine whether the person referenced actually exists. A quick web search will confirm that Amelia Atlas is an actual agent and that she does, in fact, work with the Creative Artists Agency. But a little more digging will show some discrepancies. First, the email address the message was apparently sent from (amelia.agent.caa@gmail.com) is different than the email address shown in the footer (amelia@caa.com) and both of these are different from her actual email address (which you can find at her agency website).
Note that you can’t fully trust the email address shown in the “From:” line of a email message. Those are possible to forge, so you really need to look at the raw message source and confirm that the email was actually sent through gmail. The mail headers are long and mostly impenetrable, but there’s the relevant piece that shows where my mail server received the message from Google.

Unfortunately, Google does not show us the actual IP address the scammer connected from — just the address of the server they used (74.125.227.130). Otherwise, we might be able to deduce where they are located in the world. But this shows pretty clearly the email address they used and that it did come from Google.
Since agency email addresses are clearly @caa.com and this came from @gmail.com, we can be pretty sure this message is fake. The fact the footer shows an incorrect address — and is in fact not even linked to a mailto: link, but instead to the agent’s page at caa.com is also a giveaway. It’s gotten so that just the fact that it’s sent from gmail.com is, in itself, suspicious.
Note that this a lesson for authors as well: you really should get a domain name of your own and send all of your email from that if you want to appear legitimate. And you should also maintain a web-presence at your domain name with information people can cross-check to confirm that messages from you are not forged.
One other pitfall to be aware of is that scammers sometimes will register domain names that use non-ASCII letters to impersonate valid websites. For example, I could register “𝖼𝖺𝖺.com” (which uses mathematical characters that look like “caa”, but are different unicode characters: U+1D5BCU+1D5BAU+1D5BA instead of U+0063U+0061U+0061U). This is why you should never trust a link sent in email. Go find the server yourself and navigate starting from there. You can type the domain name yourself, or start with a search engine — they mostly won’t be confused.
Double checking information “out of band” is a useful strategy also in other contexts. One time I got a voicemail from someone who introduced themselves as an FBI agent from Boston and left a phone number. I didn’t call that phone number but, instead, looked up the Boston FBI office, called the number, and asked for the agent by name. It really was a valid message. But you should always be skeptical of information provided by a potentially unreliable source.
Finally, the content of the message is also suspicious. Anyone who knows anything about querying knows that agents basically never solicit manuscripts. If anything, they want a well-structured query and would probably want to look at an excerpt before considering the full manuscript. This particular agent’s webpage specifies what she’s looking for:
For fiction submissions, please include your query letter, bio, and the first 10 pages of your manuscript in the body of your email. For nonfiction submissions, please include your query letter and bio and proposal if available.
Most agents use the nagware website Query Tracker to manage queries. A few do in fact use email, and I expect they are among those most commonly impersonated.
One thing I found creepy about this particular scam was that it seems to be that the scammer has been reading my blog, so they appear to know I’m currently querying. I got an earlier scam solicitation that pretended to be a different agent at a different agency that was similar, but I wasn’t yet querying at that time.
One other particular giveaway in this instance for me was that I have in fact queried a different agent at Creative Artists. So I wouldn’t query a second agent at the same agency — and would certainly not expect a different agent to contact me.
Good luck out there. It’s a dangerous world.
