Phishing

How to Spot a Phishing Email: 8 Red Flags

How to Spot a Phishing Email: 8 Red Flags | Best Password Generator — key points at a glance
How to Spot a Phishing Email: 8 Red Flags | Best Password Generator — key points at a glance

By Marcus Hale · · 7 min read

A phishing email tries to make you act before you think — usually by pretending to be a company you trust and pushing you toward a link. The good news: nearly every one of them shows the same handful of tells. Learn these eight red flags and you will catch the vast majority before any harm is done.

1. Urgency and threats

"Your account will be suspended in 24 hours." "Unusual activity detected — act now." Manufactured panic is the heart of phishing, because a rushed person skips the checks they would normally make. Real companies rarely threaten you into immediate action. When a message tries to start a countdown, that alone is reason to slow down.

2. A lookalike sender address

The display name might say "Your Bank," but the actual address tells the truth. Look closely: support@yourbank.com is very different from support@yourbank-alerts.com or yourbank@secure-mail.co. Scammers register addresses that are close enough to pass a quick glance. A few seconds reading the full email address catches a lot of fakes.

3. Generic or wrong greetings

"Dear Customer" or "Dear user@email.com" suggests a message blasted to thousands of people rather than written to you. It is not proof on its own — some real emails are generic too — but combined with other flags it is a strong hint.

4. Links that do not match

Before clicking anything, hover your cursor over the link (or press and hold on a phone) to preview where it really goes. If the visible text says one thing and the preview shows an unrelated address, stop. Better yet, ignore the link entirely and reach the site by typing the address yourself or using a saved bookmark.

Habit worth keeping: never log in via a link in an email. Always navigate to the site directly. This single rule defuses most phishing, even the convincing kind.

5. Requests for passwords, codes, or payment

Legitimate organisations do not email asking you to "confirm" your password, your full card number, or a one-time security code. Anyone asking for your 2FA code is almost certainly trying to break into your account — those codes are for you alone. Treat any such request as a scam until proven otherwise.

6. Spelling, grammar, and odd formatting

Clumsy wording, strange spacing, and mismatched logos are classic signs. Attacks are getting more polished, so a clean-looking email is no guarantee of safety — but obvious mistakes are still a reliable giveaway when you see them.

7. Unexpected attachments

An invoice you were not expecting, a "delivery notice" as a file, a document you must "enable content" to read — attachments are a common way to deliver malware. If you did not request the file and were not expecting it, do not open it. Verify with the sender through a channel you trust first.

8. Offers that are too good, or fears that are too big

A surprise refund, a prize you never entered for, an inheritance, a tax rebate — or, on the flip side, a frightening legal threat. Both extremes exist to flood you with emotion so you stop reasoning. If a message makes your pulse jump, that is precisely the moment to pause.

What to do if you slip up

Everyone has a bad day. If you clicked a link, do not enter anything — just close it. If you already typed a password, change it on the real site at once and turn on two-factor authentication; you can build a fresh, strong one with our password generator. If you shared card details, call your bank. Phishing is also the on-ramp for many wider scams, which we cover in common online scams in 2026 and how to avoid them. For the broader habits that keep you protected, see our web security basics guide.

Frequently asked questions

What is phishing?

Phishing is a scam where someone impersonates a trusted person or company to trick you into handing over passwords, money, or personal details, usually through email, text, or a fake website.

I clicked a phishing link. What should I do?

Do not enter any details. Close the page. If you already typed a password, change it immediately on the real site and turn on two-factor authentication. If you shared card details, contact your bank.

How can I tell if an email link is fake?

Hover over the link without clicking to preview the real destination. Check that the domain is exactly the official one. When in doubt, ignore the link and type the company's address yourself.

Can phishing come through text messages too?

Yes. The same tactics arrive by SMS (smishing) and phone calls (vishing). The red flags are identical: urgency, a request for details or payment, and a link or number you did not ask for.

This article is general security education, not professional advice.

How Phishing Emails Have Evolved

Early phishing attempts were easy to dismiss: broken images, obvious misspellings, and requests sent from clearly personal email addresses. Today the picture is more complicated. Attackers now copy the exact layout of a real company's emails, including logos, footer links, and legal disclaimers. They personalise the greeting with your real name, reference your actual account, and time the message to arrive just after a legitimate transaction.

Understanding this shift matters because it changes how you need to read suspicious messages. You can no longer rely on a single obvious mistake to flag a fake. Instead, you need to check several signals at once, because a sophisticated phishing email may pass most of them while failing just one or two.

Why Context Is the Most Reliable Signal

Before examining any link or attachment, ask a simple question: did I expect this email? Phishing works by inserting a fake message into a stream of real ones. The fake typically arrives without context — you did not request a password reset, you did not start a new subscription, you did not place the order being "confirmed."

Legitimate services rarely contact you without a prior action on your part. When a message demands a response but you cannot trace it back to something you did, treat that gap as a red flag in its own right, regardless of how professional the email looks.

Common Mistakes People Make When Checking Emails

Practical Steps to Verify a Suspicious Message

If an email asks you to act on your account, the safest path is to navigate directly rather than follow the link. Open a new browser tab, type the company's address yourself, and log in from there. Any genuine alert will show up in your account dashboard. This one habit breaks the majority of phishing attempts at no cost to you.

You can also verify sender authenticity without specialised tools. Look at the full "From" header, not just the display name. In most email clients this is hidden behind a friendly name, but a click or hover reveals the actual address. If the display name says a well-known company but the address ends in an unfamiliar domain, the message is not from that company.

For links, hover over them before clicking. The destination shown in the status bar at the bottom of your screen should match where you expect to go. Mismatches, extra subdomains, or very long strings of characters that obscure the true domain are all warning signs.

Protecting Other People Around You

Phishing emails are often forwarded between family members and colleagues with a note like "is this real?" Forwarding a phishing message can itself spread risk if the recipient clicks before reading your warning. When you need to share a suspicious email for a second opinion, describe it in words or take a screenshot rather than forwarding the original.

It is also worth having a brief, non-judgmental conversation with people you share accounts or devices with. Many people feel embarrassed to admit they nearly fell for a scam. Making it a normal topic rather than a failure reduces the chance that someone hides a click that led somewhere dangerous, which is information you need to act on quickly.