← All articles Compliance

How Do You Spot a Fake GSA Contracting Officer Email? A Former CO's Red-Flag List

Scammers are impersonating real GSA contracting officials to squeeze money and data out of Multiple Award Schedule (MAS) contractors. The tell is almost always the same: a look-alike domain instead of @gsa.gov, a fee or form nobody asked for, and a deadline designed to rush you. A real Contracting Officer never charges you to keep your contract active.

What did the GSA OIG scam alert actually say?

The GSA Office of Inspector General (OIG) warned that scammers are emailing MAS contractors and SAM.gov registrants while posing as named GSA officials. They copy a real official's name, title, and signature block, then send from a near-GSA domain such as e-gsa.us. Two versions have been reported so far.

You can read the full GSA OIG scam alert. The MAS Program Management Office relayed it to contractors on the MAS Interact community on August 6, 2026, and noted that GSA has blocked the reported malicious domains and is monitoring the situation.

Is this the first time scammers have posed as federal buyers?

No. GSA OIG has a separate, standing fraud alert on fake Requests for Quotations (RFQs) and fake purchase orders. That scheme targets product sellers: the scammer accepts your quote, issues a forged PO with a copied signature, and has you ship resellable goods on Net 30 terms to an address that belongs to no agency.

SchemeWhat the scammer wantsHow it shows up
Fake credentialing feePayment card dataEmail with a credit card authorization form attached
Fake compliance noticeA click, a download, or sensitive informationEmail with an attached "notice" and resolution steps
Fake RFQ and purchase orderYour inventory, shipped on creditLaptops, phones, toner, or medical equipment ordered in bulk, rush shipping, delivery to a storage unit or freight forwarder
Paid SAM.gov "registration" or "renewal"A fee for something that is freeOfficial-looking email or site demanding payment to register, renew, or fix errors

The OIG fake RFQ alert lists sample fake addresses built to look like agency mail, such as a gsa-org.com domain.

How do real GSA contract actions reach a MAS contractor?

Legitimate MAS contract actions move through GSA systems, not through email attachments with payment forms. Modifications you request go through eOffer/eMod. Mass modifications arrive through GSA's mass modification system. Agency buying opportunities come through eBuy, GSA Advantage, or SAM.gov. Email is a notification channel, never the place you pay or sign.

Contract actionWhere the real one livesWhat a fake looks like
Your modification requesteOffer/eMod, signed electronicallyAn emailed form asking you to "confirm" changes and pay a processing fee
Mass modification (Refresh)GSA mass modification system; you have 90 days to signAn emailed PDF threatening cancellation within 48 hours
Agency RFQ under your ScheduleeBuy, tied to your contract and SINsAn unsolicited email RFQ for bulk electronics from a non-.gov address
SAM.gov registration or renewalSAM.gov, signed in directly; always freeAny message asking for money to register, renew, or fix errors
Industrial Funding FeeReported and paid through GSA's sales reporting systemsAn emailed "credentialing" or "status" fee with a card form

GSA's own modification and mass modification guidance confirms both channels, and the MAS solicitation's modifications clause, GSAR 552.238-82 (Dec 2025 deviation), governs how Schedule changes are made. There is no clause anywhere in the MAS contract that creates an annual credentialing fee.

What red flags separate a real CO email from a fake one?

Check five things before you act: the actual sending domain, the Reply-To address, whether money or card data is requested, whether the request matches an action you already have pending, and whether the deadline is artificially short. If any one of them fails, stop and verify through a channel you already trust.

When I sat on the other side of the desk as a GSA Contracting Officer, my emails to contractors were boring by design. They referenced a contract number, a modification number, or a pending eMod action, and they came from a gsa.gov address. I never asked a vendor for a card number, and no Contracting Officer or Contracting Specialist I worked with at GSA, IRS, DoD, DOI, HHS, FTC, or Energy ever did either. The authority to change your contract sits with warranted officials under FAR 1.602-1, and FAR 43.102(a) is explicit that only contracting officers acting within their authority can execute contract modifications.

Red flagReal GSA COLikely scam
Sender domainEnds in @gsa.govNear-miss domains such as e-gsa.us, gsa-org.com, or anything ending in .com, .net, .org, or .us
Reply-To headerSame gsa.gov addressDifferent address from the one displayed
MoneyNever requests fees or card data by emailCredentialing fee, renewal fee, processing fee, gift cards, wire, or crypto
ContextTied to your contract number and an action you can see in eMod or the mass mod systemGeneric "your vendor status" or "your contract file" language with no mod number
AttachmentsDocuments you can also find in the systemUnsolicited forms or notices you can only get from the email
DeadlineReasonable timelines, such as 90 days for a mass modHours or days, with threats of suspension

How do you verify that a contracting officer is real?

Verify the person against records you already hold, never against the suspicious email. Your award documents and your most recent executed modification name your assigned Contracting Officer and Contracting Specialist. Call or email that person using the contact information from those records and ask whether they sent the request.

  1. Pull your award package and your latest executed modification in eMod. Note the CO and Contracting Specialist named there.
  2. Confirm your contract number and status in GSA eLibrary. If the email cites a contract number that does not match, you are done.
  3. Hover over the sender name without clicking and read the full address. Then check the Reply-To header.
  4. Contact your CO through the gsa.gov address or phone number from your own records, not from the email signature.
  5. For SAM.gov claims, sign in to SAM.gov directly and check your registration yourself. The IAE team says SAM.gov will never ask for money and will never send a link that does not end in .gov.

As a Contracting Specialist, I noticed the contractors who handled odd requests best kept a one-page contact sheet with their CO and Contracting Specialist. The part most people miss: scammers can copy a real CO's name perfectly because contract data is public. The name proves nothing. The channel proves everything.

What should you do if you already clicked, paid, or shipped?

Move fast and document everything. Call your card issuer or bank to stop the charge, change any credentials you entered, and preserve the original email with full headers. Then report to the GSA OIG hotline and the FBI's Internet Crime Complaint Center, and tell your actual CO that their identity is being spoofed.

If your team uses the self-audit checklist from our GSA fraud review post, add an inbound-email verification step to it.

Where do you report a GSA impersonation attempt?

Report suspected GSA impersonation to the GSA OIG hotline at gsaig.gov/hotline. Because these schemes chase payment and financial data, also file with the FBI's Internet Crime Complaint Center at ic3.gov. If the email impersonated a different agency, report to that agency's Inspector General as well.

WhereWhen to use it
GSA OIG HotlineAny email, call, RFQ, or PO impersonating GSA
FBI IC3Any attempt to obtain payment, banking, or login data, or goods on a fake PO
Other agency Inspectors General (listed at ignet.gov)Impersonation of a non-GSA agency official
Your assigned GSA COEvery time, through a verified contact, so they know their name is being used

What should you do now?

I spent 18 years in federal acquisition, hold FAC-C Level III certification and a Harvard Master of Liberal Arts, and have supported 70+ GSA contract awards. If you want someone who knows what a real GSA contract action looks like watching your eMod queue, mass mods, and CO correspondence, our GSA contract maintenance program keeps your Schedule current and gives you a second set of eyes on anything that claims to come from GSA.

Frequently Asked Questions

Does GSA charge an annual credentialing fee to keep a MAS contract active?

No. GSA OIG flagged the "vendor credentialing fee" email as a scam. MAS contractors pay the Industrial Funding Fee on reported sales through GSA's reporting systems, not through emailed card authorization forms.

How can I tell if an email is really from a GSA contracting officer?

Check the actual sending address, not the display name. Legitimate GSA addresses end in @gsa.gov, and the Reply-To header should match. If the email asks for money, card data, or an urgent attachment review, verify with your CO using contact details from your own award documents.

What domain did the GSA impersonation scammers use?

GSA OIG cited e-gsa.us as one look-alike domain used in reported cases. OIG also warned that fraudsters may use other near-GSA domains, so check the full domain every time rather than watching for one example.

Does SAM.gov ever charge to register or renew?

No. Registration in SAM.gov is always free, and the government will never ask you to pay to register, update, or renew. Any email or site asking for money to register or fix errors is not a government source.

How do real GSA contract modifications arrive?

Modifications you request are submitted and signed through eOffer/eMod. Mass modifications come through GSA's mass modification system, and you have 90 days to sign them. Neither process involves paying a fee by email.

What are the warning signs of a fake government RFQ or purchase order?

The fake RFQ alert from GSA OIG describes non-government sender domains, bulk orders for resellable items like laptops and toner, rush shipping, Net 30 terms, and delivery to storage units or freight forwarders. Call the named buyer at an independently sourced number before shipping.

Where do I report a GSA impersonation scam?

Report it to the GSA OIG hotline at gsaig.gov/hotline and to the FBI's Internet Crime Complaint Center at ic3.gov. Keep the original email with headers, and notify your real GSA contracting officer through a verified channel.

Work With a Former CO Who's Been There

Navigating GSA Schedule strategy doesn't have to be a guessing game. Book a free strategy call with Pedro and let's talk about where you stand.

Book a Free Consultation →