How to Spot a Phishing Email: 8 Red Flags
Phishing works best when a message makes you act before you inspect it. The design may be polished and the wording may be clean, so do not wait for an obvious spelling mistake. Check who sent it, where the link goes and what the message is asking you to do.
Eight tells of a phishing email
- 1. Urgency or fear. “Your account will be closed in 24 hours.” Pressure is the scammer's main tool.
- 2. A mismatched sender. The display name says “Your Bank” but the actual address is a random domain. Always check the real address.
- 3. Links that don't match. Hover over a link — if the destination isn't the official domain, don't click.
- 4. A greeting or detail that does not fit. “Dear customer” can be a clue, but personalised names can be copied too. Treat context as evidence, not proof.
- 5. Unexpected attachments. Invoices or “documents” you didn't request can carry malware.
- 6. Requests for credentials. A legitimate service should not ask you to reply with a password or enter full card details through an emailed form.
- 7. Subtle misspellings. A digit substituted for a letter or an extra word in a familiar-looking domain can change its owner. Read the whole host rather than recognising part of the name.
- 8. Too good to be true. Refunds, prizes, and inheritances you never expected.
What to do instead of clicking
If a message might be real, leave its links alone. Open a new tab and type the company's address yourself, or use its official app. You can then check the account without letting the email choose your destination.
Work through a suspicious delivery message
Synthetic example: the following message is written for this guide. The brand and .example domains are fictional, the links are inert text, and this is not an email received from a real company.
Display name: Parcel Desk
From: notice@parcel-check.example
Subject: Delivery paused: address confirmation needed
Message: “Your parcel is waiting. Pay the small redelivery fee today.”
Button label: View delivery
Destination: https://parcel.example.account-check.example/pay
| What to inspect | What this example tells us | What to do with that clue |
|---|---|---|
| The friendly name | “Parcel Desk” is text the sender can choose. | Expand sender details; do not use the name or logo as authentication. |
| The destination host | In this fictional host, parcel.example is a prefix of account-check.example, not the destination company. | Find the hostname between https:// and the next slash. A familiar word elsewhere is not enough. |
| The requested action | A delivery notice is asking for a payment, creating a reason to collect card details. | Check the order in the retailer's app and follow its established tracking path. |
| The deadline | The message asks you to decide before checking. | Pause. A real deadline can be checked through the company's known contact channel. |
This is a reason to avoid the supplied link, not a mathematical phishing score. Real organisations may use separate delivery or marketing domains; real attackers may compromise an otherwise legitimate sender. The reliable next action is independent verification. The FTC's phishing guidance likewise directs readers to contact the organisation using a website or number they already trust.
A plausible security alert needs a different decision
Synthetic example B: you receive “New sign-in detected” from security@notes.example, with no attachment and a destination beginning https://notes.example/security/. You do use that fictional service. Nothing in this short description proves fraud, and ignoring a real alert would be a mistake.
Open the service through your existing bookmark or app, inspect recent sign-ins and use its official help channel if the message remains unexplained. A lack of visible alerts does not establish that the email is fake: alerts can be delayed, stored elsewhere or sent for an event the account page does not display. If it concerns a Google Account specifically, Google's phishing instructions point to the account's recent security activity and explain the Gmail reporting action.
Sender authentication adds evidence, but it does not certify the content. Gmail's authentication guide explains the “Mailed by” and “Signed by” details. An attacker can authenticate mail from a domain they own, while legitimate forwarded mail can have authentication complications. Keep checking the request and the actual organisation.
A disposable inbox changes the recipient address, not the destination behind a link. Apply the same caution you would in your primary inbox. See are temporary emails safe.
Reduce how much phishing you get
Reducing public exposure gives attackers fewer easy ways to connect a message to your main identity. Keep a personal address off public pages, use a disposable inbox only for permitted low-stakes signups, and report phishing through your provider. More on shrinking your footprint appears in 12 email privacy tips.
If you already clicked
Close the page and distinguish what happened. Opening a page without submitting data is different from entering a password, approving a login or installing a file. A click alone does not establish account compromise. If you entered credentials, approved access or see suspicious activity, start the account steps below. If a file or app was downloaded, use your device's trusted security tools and the provider's recovery guidance too.
- Stop and enter nothing more. Close the tab. Don't finish the form or "verify" again — every extra field is a gift to the scammer.
- Replace credentials you exposed, using a trusted device. Go to the affected account directly and set a new, unique password. Replace the old password anywhere else you reused it. If you only opened a page and entered nothing, assess downloads and account activity rather than assuming every password was stolen.
- Turn on two-factor authentication. A second factor limits what a stolen password can do. An authenticator app avoids SIM-swap risk, while a passkey or security key is harder to phish when the service supports one; NIST's current authenticator guidance explains that difference.
- Hunt for what they left behind. Attackers often add a hidden forwarding rule, a filter that buries security alerts, or a logged-in session to keep access after the reset. Check your forwarding, filters, and active-sessions pages and remove anything you don't recognise.
- Watch and report. Keep an eye on statements, and report it to the real company — or your bank, if a card was involved — using a number you look up yourself, never one from the message.
A password reset may revoke some sessions, depending on the provider. It does not necessarily remove forwarding rules, connected apps or every existing session. Review those separately using the provider's recovery instructions.
How to verify a suspicious message safely
Most messages aren't worth a clean-up at all if you check them before you act. The trick is to never let the email steer you:
- Go there yourself. Open the company's known website or official app and inspect the relevant activity. If there is no matching alert, keep the message unverified and use the company's established support channel when the claim matters.
- Read the real sender domain. Look past the friendly display name to the actual address. A reassuring phrase in a domain is not proof that it belongs to the company.
- Inspect without visiting. Hover on a computer to preview a destination. Mobile previews vary; if a link cannot be inspected without opening it, use the official app instead. Redirects and shortened URLs can hide later destinations.
Address separation can reduce how often low-value signups lead back to your main inbox, but it cannot make a suspicious message safe. The sender, destination and request still need the same scrutiny.
Quick FAQ
Is it safe to open a suspicious email? Reading a message in an updated mail client is generally lower risk than clicking a link or opening an attachment, but it is not completely private: remote images can report that the message was opened. Disable remote content if your client offers that option, and do not interact with the message.
What if I replied with information? Treat whatever you sent as compromised. If it was a password, change it everywhere you reused it and follow the steps above; if it was card or identity details, contact your bank. A reply also confirms your address is live, so expect more attempts.
Does receiving it in a temporary inbox make the links safe? No. A disposable address limits what a leak of that address exposes, but it does not inspect or endorse the link's destination. More on what these inboxes do and don't protect: are temporary emails safe and protecting your email from data breaches.