Phishing Email Red Flags: A Quick Spotter’s Guide
Phishing is a scammer pretending to be someone you trust — your bank, a delivery company, Microsoft, your boss — to trick you into clicking a bad link, opening a malicious attachment, or handing over a password. It’s the single most common way both individuals and businesses get compromised. The good news: most phishing shares the same tells.
The red flags
- Urgency and threats. “Your account will be closed,” “unusual activity, act now,” “payment failed.” Pressure to act immediately, before you think, is the oldest trick in the book.
- Unexpected attachments or links. Especially invoices, “receipts,” shipping notices, or documents you weren’t expecting. When in doubt, don’t open it.
- A link that doesn’t match the sender. Hover over a link (don’t click) and look at where it actually goes.
paypa1-secure.comis notpaypal.com. On a phone, press and hold to preview the address. - Lookalike sender addresses. The display name says “Amazon” but the actual email address is a random string or a misspelled domain.
- Requests for passwords, codes, or payment. Legitimate companies don’t email asking you to confirm your password, and no real support line asks for your two-factor code. Requests for gift cards or wire transfers are almost always a scam.
- Generic greetings and off details. “Dear Customer,” odd grammar, or a logo that’s slightly wrong. Modern phishing can look polished, though — don’t rely on typos alone.
- The “boss” or “coworker” asking for something urgent and secret. Business email compromise often impersonates an executive asking for a quick payment or gift cards. Verify through another channel.
Safe habits
- Slow down. Urgency is the weapon. A real problem will still be real in ten minutes.
- Go direct. Instead of clicking the link, open a browser and type the company’s address yourself, or use their app. Log in there and check.
- Verify money and password requests out of band. Call the person or company using a number you look up independently — not the one in the email.
- Turn on two-factor authentication. Even if you slip and give up a password, 2FA can stop the attacker from getting in.
- When unsure, don’t click — ask. For a business, report it to whoever handles IT. For home, delete it, or have someone you trust take a look.
If you already clicked
Don’t panic. If you entered a password, change it immediately from a different, clean device and turn on 2FA. If it was a work account or money is involved, report it right away — quick reporting limits the damage. Watch the affected accounts closely for the next while.
Phishing works by rushing you. Recognize the pressure, slow down, and verify — that habit alone stops the vast majority of attacks.