How to Spot a Phishing Email
Learn how to spot a phishing email before it tricks you. This plain-English guide covers the warning signs, common tactics, and what to do next.
Quick answer
To spot a phishing email, check the sender's real address, look for urgent or threatening language, hover over links before clicking, and be wary of unexpected attachments or requests for passwords and payment. Legitimate organisations rarely ask for sensitive details by email, so treat any such request with strong suspicion.
Knowing how to spot a phishing email is one of the most valuable everyday security skills you can have. Phishing is a type of scam where an attacker sends a fraudulent message pretending to be someone you trust, hoping to trick you into handing over passwords, money, or personal data, or into clicking a harmful link. These attacks are extremely common, and they succeed by exploiting trust, urgency, and inattention rather than any technical weakness in your device.
The good news is that most phishing emails share recognisable warning signs. Once you know what to look for, you can catch the vast majority before they cause any harm. This guide walks through the tell-tale signals, the common tactics attackers rely on, and exactly what to do when a suspicious message lands in your inbox.
What phishing is and why it works
Phishing works because it targets people, not machines. A convincing email can imitate a bank, a delivery company, an employer, or a familiar brand, complete with logos, colours, and professional-sounding wording. The attacker’s goal is to get you to act quickly, before you stop to think and notice something is wrong.
Common goals behind phishing include stealing login details, capturing payment information, installing malware through attachments, or tricking you into transferring money directly. Because the whole scheme relies on your reaction, staying calm and checking a few key details is often enough to defeat it. The attacker is essentially betting that you are busy, distracted, or worried enough to skip your usual caution.
The main warning signs
Most phishing emails give themselves away through one or more of these signals. With practice, you can learn to scan for them almost automatically.
| Warning sign | What to look for |
|---|---|
| Suspicious sender address | A display name that looks right but an odd or misspelled email domain |
| Urgency or threats | “Act now,” “account suspended,” “final warning” pressure |
| Requests for sensitive data | Asks for passwords, card numbers, or verification codes |
| Mismatched links | Link text says one thing but points somewhere else |
| Unexpected attachments | Files you did not expect, especially ones urging you to open them |
| Generic greetings | “Dear customer” instead of your name, though not always |
| Odd spelling or grammar | Awkward phrasing or errors a real organisation would catch |
No single sign proves an email is phishing on its own, but the more that appear together, the higher the risk. Treat these as a checklist you run through whenever a message feels even slightly off.
Check the sender carefully
The display name in an email is easy to fake. What actually matters is the real address behind it. On a computer, click or hover to reveal the full email address and examine the domain, the part after the @ symbol, which is much harder to fake convincingly.
Attackers often use lookalike domains, swapping letters, adding extra words, or using slightly different endings that resemble the real one at a glance. A message claiming to be from a well-known company but sent from an unrelated, misspelled, or oddly structured domain is a strong red flag. When in doubt, do not trust the email itself; contact the organisation through their official website or app that you find independently.
Inspect links before you click
Links are one of phishing’s main weapons. Before clicking, hover your mouse over a link on a desktop to see the real destination, which usually appears in a corner of the screen. On a phone, you can often press and hold to preview the address without opening it.
- Check whether the domain genuinely matches the organisation it claims to be from.
- Be wary of links that use unfamiliar domains or long, confusing strings of characters.
- Watch for slight misspellings of well-known names hidden inside the address.
- Never enter login details on a page you reached from an unexpected email.
When a message asks you to log in or verify something, it is far safer to open your browser and type the official address yourself, or use a bookmark you saved earlier. The same judgement you would use in how to tell if a website is legit applies directly to any page a link tries to send you to.
Watch the language and requests
Phishing emails often manufacture pressure. Phrases like “your account will be closed,” “unauthorised login detected,” or “immediate action required” are carefully designed to make you panic and skip your usual caution. Fear and urgency are the scammer’s most reliable tools.
Be especially suspicious of any message that asks for:
- Your password or a one-time verification code.
- Payment or bank details, or a request to move or transfer money.
- Personal information such as identity documents or your date of birth.
- Action “within minutes” to avoid a penalty, fee, or account closure.
Legitimate organisations rarely ask for sensitive details by email, and they will never ask you to share verification codes. A genuine bank or service will not pressure you to reveal a password. Treat any such request as a serious warning sign, no matter how official the message looks.
Common phishing tactics
Understanding the usual playbook makes individual attacks much easier to recognise when they arrive.
- Impersonation: Pretending to be a bank, retailer, delivery service, or your employer or colleague.
- Fake invoices or receipts: Claiming you were charged for something, hoping you click to “dispute” or “cancel” it.
- Account alerts: Warning of suspicious activity to lure you to a fake login page that captures your details.
- Prize or refund lures: Promising money or a reward to collect your personal or payment details.
- Targeted attacks: Using real details about you to seem convincing, sometimes called spear phishing.
The same techniques also appear beyond email, in text messages, phone calls, and messaging apps. The warning signs and defences are broadly the same wherever the message arrives.
What to do with a suspicious email
If you think an email is phishing, follow a simple, consistent routine so you never have to improvise under pressure.
- Do not click links or open attachments. This is the single most important step.
- Do not reply. Replying only confirms your address is active and invites more attempts.
- Verify independently. Contact the organisation through their official channels if you are unsure whether it is genuine.
- Report it. Use your email provider’s spam or phishing report tools, which also help protect others.
- Delete it once you have reported it.
If you already clicked a link or entered details, act fast: change the affected password immediately, enable two-factor authentication, and watch closely for unusual account activity. That extra login step often stops attackers even when they have captured your password, which is why it is such a valuable safety net.
Building safer habits
Beyond spotting individual emails, a few ongoing habits reduce your overall risk. Keep your software and devices updated, use strong and unique passwords for each account, and be cautious about sharing your email address widely. On untrusted public networks, a VPN adds privacy, though it does not stop phishing on its own. It also helps to understand how legitimate email works, since knowing normal, professional practice, such as the approaches covered in how to improve email open rates, makes abnormal, manipulative messages stand out much more clearly by contrast.
Above all, slow down. Phishing depends on speed and emotion. A few seconds spent checking the sender address and hovering over links defeats the overwhelming majority of attacks, and that habit quickly becomes second nature.
How phishing differs from spam and other scams
It helps to distinguish phishing from ordinary spam. Spam is unsolicited bulk email, often advertising, which is annoying but usually not directly dangerous. Phishing is more targeted in intent: its whole purpose is to deceive you into an action that harms you, such as revealing a password or making a payment. Some messages blur the line, but the key difference is that phishing actively tries to trick you, not just sell to you.
Related scams use the same psychology in other channels. “Smishing” arrives by text message, and “vishing” comes by phone call, both relying on urgency and impersonation. Recognising the shared pattern, an unexpected message pressuring you to act on sensitive information, helps you stay alert across all of them rather than only watching your email inbox.
Protecting your family and colleagues
Phishing awareness is most effective when it is shared. Attackers often target the least prepared person in a household or organisation, so talking openly about the warning signs helps everyone. Encourage family members, especially those less comfortable with technology, to pause and check with someone they trust before acting on any urgent-sounding email about money or accounts.
In a workplace, reporting suspicious emails promptly can protect many colleagues at once, since attackers frequently send the same message to many people. A simple shared rule, verify before you click or pay, prevents a large share of successful attacks. Security is a habit that grows stronger when a whole group practises it together.
The bottom line
Spotting a phishing email comes down to a handful of reliable checks: verify the sender’s real address, be wary of urgency and threats, inspect links before clicking, and never share passwords or payment details in response to an unexpected message. Report anything suspicious, and when in doubt, verify through official channels rather than the email itself. For more practical security guides, explore our technology section.
Frequently asked questions
What is a phishing email?
A phishing email is a fraudulent message designed to trick you into revealing sensitive information, clicking a malicious link, or downloading harmful files. It usually pretends to come from a trusted source, such as a bank, retailer, or colleague. The goal is to steal credentials, money, or data by exploiting your trust or urgency.
What should I do if I clicked a phishing link?
Do not enter any information on the page. Disconnect if you are worried, change the password for any account you may have exposed, and turn on two-factor authentication. Watch for unusual account activity, and if it involves a work account or payment, report it to the relevant organisation quickly.
How can I check if a link is safe without clicking it?
On a computer, hover your mouse over the link to preview the real destination, which often appears at the bottom of the window. Check whether the domain matches the organisation it claims to be from. If anything looks off, do not click; instead visit the official site directly by typing the address yourself.
Can phishing emails look completely genuine?
Yes. Convincing phishing emails can copy logos, wording, and layouts almost perfectly, and some are highly targeted using real details about you. This is why you should judge by behaviour and requests, not just appearance. Any message pressuring you to act fast or share sensitive data deserves extra caution.
Are phishing attempts only sent by email?
No. The same tactics appear in text messages, phone calls, social media, and messaging apps. The principles for spotting them are similar: check the sender, be wary of urgency, avoid unexpected links, and never share passwords or payment details in response to an unsolicited message.
Should I reply to a phishing email to tell them to stop?
No. Replying confirms your address is active and can lead to more attempts. Do not reply, click links, or open attachments. Instead, report the message using your email provider's reporting or spam tools, and delete it. If it impersonates a real organisation, you can notify them separately.
Related
What Is Two-Factor Authentication?
Two-factor authentication adds a second step to logins so a stolen password alone cannot unlock your account. Here is how two-factor authentication…
Wi-Fi 6 vs Wi-Fi 6E: What’s the Difference?
Wi-Fi 6 vs Wi-Fi 6E: what the extra E really means, when the new 6 GHz band is worth paying for, and…
How to Free Up Disk Space on Your Computer
How to free up disk space on Windows and Mac: clear temp files, uninstall unused apps, empty the trash, and find the…
