Is this request genuine?
Somebody has asked you to send them something — a paragraph, a photo, a file — through a link. Here is how to check that the request really comes from the organization it names, without taking our word for it.
The short answer: the email names the organization’s own verified email address, near the bottom. If you know that organization, write to that address and ask whether they sent it. That check does not depend on trusting this page, the email, or us.
What a genuine request looks like
SendGather sends these on behalf of an organization — a school, an agency, a foundation, a business — that has proved it controls its own email domain. A real one carries all of this:
- A name you recognise on the From line, followed by (via SendGather). The address itself is ours, not theirs. That disclosure is deliberate: without it, a message carrying their name from our servers would be indistinguishable from somebody pretending to be them.
- The organization’s own verified address, written out in the footer — something like
office@theirdomain.org. We only print that once the organization has proved it receives mail there. - A link that goes to sendgather.com and nowhere else. Hover it, or long-press it on a phone, and read the address before you tap.
- Your own name, and a specific thing being asked for. These are requests to named people, not mailing lists.
What should make you stop
- You have no connection to the organization named. These go to people an organization already knows. If you have never heard of them, that is reason enough not to fill anything in.
- The link does not go to sendgather.com. Anyone can copy the look of an email. Nobody else can send you a link on our domain.
- You are asked for a password, a payment, or a government ID number. SendGather has no passwords at all, takes no payments from contributors, and no genuine request will ask you to sign in to anything. Signing a document is a different thing, and it never needs an account either — see below.
- It is urgent, and the urgency is the point. A request can have a deadline. It will not threaten you with one.
How to check for certain
Do not reply to the email, and do not use a phone number or address printed inside it — a forgery controls everything in its own message. Instead:
- Find the organization’s contact details independently — their website, a newsletter you already had, a number you already have.
- Ask whether somebody there is collecting what the email describes.
If the address in the footer matches the domain of the organization you know, writing to it is the same check with fewer steps.
If you are being asked to sign something
Some requests ask you to sign a document electronically. That is a real signature, so it is worth more care than sending a photo — and the check above is the same one, just more worth doing.
A genuine signing request always does all of this:
- It shows you the document before you sign it. You can open it, read it, and close the page. Nothing is recorded until you press Sign.
- It tells you what is kept — the document as it was at that moment, the name you type, the address it was sent to, the date and time, and technical details of the signing — before you agree to anything.
- It offers you paper instead. You can ask the organization to let you sign on paper, and you do not have to give a reason.
- It emails you your own copy the moment you sign, with the document attached. Keep it.
To be sure the person signing is you, we email a short code to the address the request was sent to, and you type it in on the signing page.
- Nobody will ever ring you, message you, or email you asking for that code. It is only ever typed into the signing page you already have open. Anyone who asks you to read it out is not us and is not the organization.
- Nobody genuine will hurry you into signing. A document can have a deadline. If somebody is pressing you to sign now, stop and use the check above — the organization will still be there tomorrow.
What we can see, and what the organization can see
Whatever you send goes to the organization that asked — the coordinators there can read it, download it, and keep it. Files are stored privately and are not published anywhere or reachable by guessing an address.
You do not have an account here and never will. Your link is yours alone: you can go back to it and change what you sent for as long as the request is open. The one exception is a document you have signed — a signature is a record of something you did, so it is fixed once you press Sign, and changing it means asking the organization.
If a request is not genuine
Every request page has a Report this request link at the bottom. It reaches SendGather directly — not the organization that sent it, which matters if the organization is the problem. You do not need an account to use it.
If you would rather not open the link at all, that is a reasonable thing to do. Contact the organization the way you normally would and ask them.