Why do scam emails no longer have bad spelling?
The advice about poor English is now actively dangerous. What replaced it, why the old filter existed at all, and the three tests that still work when the writing is perfect.
- Difficulty
- beginner
- Time
- 7 min
- Read
- 3 min
Short answer
Because generating fluent, personalised English is now free. The old advice worked when messages were translated badly and sent in bulk; it does not work now, and using it makes people trust well-written fakes. Judge messages by structure instead: did you expect it, does it create urgency, and does it ask you to act through a channel it supplies.
For twenty years the standard advice was to look for bad spelling, odd grammar and a generic greeting. That advice trained a generation to trust anything fluent. It was never a good rule — it was a rule about the cost of writing English — and the cost of writing English has now fallen to nothing.
Step by step
- Understand why the old rule ever worked.Bulk fraud was written by people not writing in their first language and translated crudely. It was a signal about the sender's resources, not about fraud itself. Some operations deliberately kept the English poor to filter for the most credulous readers, which is a real and documented tactic.
- Understand what changed.Language generation tools produce fluent, correctly formatted, personalised text at zero cost, in any register, in any language, at any volume. Grammar carries no information about the sender any more.
- Replace it with the expectation test.Did you expect this contact? Unexpected contact about money, accounts, deliveries or documents is the entry point of nearly every fraud, however well written.
- Apply the urgency test.Deadlines, warnings, closing accounts, hours remaining. Urgency exists to prevent verification, and no legitimate organisation loses anything if you check tomorrow.
- Apply the channel test.Is it steering you to act through a route it supplies — a link, a number, an attachment, an app? Legitimate contact survives being verified independently. Fraud does not.
- Notice personalisation, and do not be reassured by it.Your name, employer, recent purchase or the name of a colleague can be assembled from breaches and public profiles, and used to write a message aimed at you specifically. Personalisation is now cheap too.
- Assume audio and video carry no proof either.A familiar voice on a call, or a face on a video, can be synthesised. Identity has to be established out of band — by ringing a number you already had, or by a word agreed in advance.
Tips
- The single most useful habit is not detection at all: never act on a link, number or attachment supplied by a message. That habit is unaffected by how good the writing is.
- Well-written fraud is often better written than the genuine notices from the same company, because the criminal has time and the company has a template.
- Business email compromise now routinely uses text lifted from earlier real messages in the same thread, matching the writing style precisely.
Common mistakes
- Teaching an older relative to look for bad English — It hands them a test that current fraud passes easily, and it makes fluent fakes feel safe.
- Trusting a message because it uses correct company branding and formatting — Both are copied from real messages in seconds. Appearance has never been evidence.
Questions people ask
Are there any writing signals left at all?
A few, weakly: mismatched sender addresses, generic greetings where the company always uses your name, and requests that no real process includes. But none of them are reliable enough to be your test.
Does this mean detection tools can spot AI-written scams?
No. Detection tools for machine-written text are unreliable and produce false results in both directions. Judge the request, not the prose.
So what actually still works?
Independent verification. Break contact, reach the organisation through a route you already had, and ask. That defeats every level of writing quality.