HomeGuides › How to Spot a Phishing Email

How to Spot a Phishing Email: 8 Red Flags

Urgency “act now or else” Odd sender name ≠ address Hidden link hover to check Wants secrets password or card
Four classic phishing red flags — a false sense of urgency, a sender whose name doesn't match its address, a link that hides where it really goes, and a request for your password or card. Spot one and slow down.

Phishing works best when a message makes you act before you inspect it. The design may be polished and the wording may be clean, so do not wait for an obvious spelling mistake. Check who sent it, where the link goes and what the message is asking you to do.

Eight tells of a phishing email

What to do instead of clicking

If a message might be real, leave its links alone. Open a new tab and type the company's address yourself, or use its official app. You can then check the account without letting the email choose your destination.

Work through a suspicious delivery message

Synthetic example: the following message is written for this guide. The brand and .example domains are fictional, the links are inert text, and this is not an email received from a real company.

Example A: a small fee with a large request

Display name: Parcel Desk
From: notice@parcel-check.example
Subject: Delivery paused: address confirmation needed
Message: “Your parcel is waiting. Pay the small redelivery fee today.”
Button label: View delivery
Destination: https://parcel.example.account-check.example/pay

What to inspectWhat this example tells usWhat to do with that clue
The friendly name“Parcel Desk” is text the sender can choose.Expand sender details; do not use the name or logo as authentication.
The destination hostIn this fictional host, parcel.example is a prefix of account-check.example, not the destination company.Find the hostname between https:// and the next slash. A familiar word elsewhere is not enough.
The requested actionA delivery notice is asking for a payment, creating a reason to collect card details.Check the order in the retailer's app and follow its established tracking path.
The deadlineThe message asks you to decide before checking.Pause. A real deadline can be checked through the company's known contact channel.

This is a reason to avoid the supplied link, not a mathematical phishing score. Real organisations may use separate delivery or marketing domains; real attackers may compromise an otherwise legitimate sender. The reliable next action is independent verification. The FTC's phishing guidance likewise directs readers to contact the organisation using a website or number they already trust.

A plausible security alert needs a different decision

Synthetic example B: you receive “New sign-in detected” from security@notes.example, with no attachment and a destination beginning https://notes.example/security/. You do use that fictional service. Nothing in this short description proves fraud, and ignoring a real alert would be a mistake.

Open the service through your existing bookmark or app, inspect recent sign-ins and use its official help channel if the message remains unexplained. A lack of visible alerts does not establish that the email is fake: alerts can be delayed, stored elsewhere or sent for an event the account page does not display. If it concerns a Google Account specifically, Google's phishing instructions point to the account's recent security activity and explain the Gmail reporting action.

Sender authentication adds evidence, but it does not certify the content. Gmail's authentication guide explains the “Mailed by” and “Signed by” details. An attacker can authenticate mail from a domain they own, while legitimate forwarded mail can have authentication complications. Keep checking the request and the actual organisation.

Remember

A disposable inbox changes the recipient address, not the destination behind a link. Apply the same caution you would in your primary inbox. See are temporary emails safe.

Reduce how much phishing you get

Reducing public exposure gives attackers fewer easy ways to connect a message to your main identity. Keep a personal address off public pages, use a disposable inbox only for permitted low-stakes signups, and report phishing through your provider. More on shrinking your footprint appears in 12 email privacy tips.

If you already clicked

Close the page and distinguish what happened. Opening a page without submitting data is different from entering a password, approving a login or installing a file. A click alone does not establish account compromise. If you entered credentials, approved access or see suspicious activity, start the account steps below. If a file or app was downloaded, use your device's trusted security tools and the provider's recovery guidance too.

  1. Stop and enter nothing more. Close the tab. Don't finish the form or "verify" again — every extra field is a gift to the scammer.
  2. Replace credentials you exposed, using a trusted device. Go to the affected account directly and set a new, unique password. Replace the old password anywhere else you reused it. If you only opened a page and entered nothing, assess downloads and account activity rather than assuming every password was stolen.
  3. Turn on two-factor authentication. A second factor limits what a stolen password can do. An authenticator app avoids SIM-swap risk, while a passkey or security key is harder to phish when the service supports one; NIST's current authenticator guidance explains that difference.
  4. Hunt for what they left behind. Attackers often add a hidden forwarding rule, a filter that buries security alerts, or a logged-in session to keep access after the reset. Check your forwarding, filters, and active-sessions pages and remove anything you don't recognise.
  5. Watch and report. Keep an eye on statements, and report it to the real company — or your bank, if a card was involved — using a number you look up yourself, never one from the message.
Check what the reset actually revokes

A password reset may revoke some sessions, depending on the provider. It does not necessarily remove forwarding rules, connected apps or every existing session. Review those separately using the provider's recovery instructions.

How to verify a suspicious message safely

Most messages aren't worth a clean-up at all if you check them before you act. The trick is to never let the email steer you:

Address separation can reduce how often low-value signups lead back to your main inbox, but it cannot make a suspicious message safe. The sender, destination and request still need the same scrutiny.

Quick FAQ

Is it safe to open a suspicious email? Reading a message in an updated mail client is generally lower risk than clicking a link or opening an attachment, but it is not completely private: remote images can report that the message was opened. Disable remote content if your client offers that option, and do not interact with the message.

What if I replied with information? Treat whatever you sent as compromised. If it was a password, change it everywhere you reused it and follow the steps above; if it was card or identity details, contact your bank. A reply also confirms your address is live, so expect more attempts.

Does receiving it in a temporary inbox make the links safe? No. A disposable address limits what a leak of that address exposes, but it does not inspect or endorse the link's destination. More on what these inboxes do and don't protect: are temporary emails safe and protecting your email from data breaches.

Try it in one clickOpen a free temporary inbox right now — no signup, no password, auto-expiring.
Open Temp Mail