Knowledge · Guides & Articles · Guide

Phishing Email Red Flags: A Quick Spotter’s Guide

The warning signs of a phishing email and the safe habits that keep you from taking the bait.

security 3 min read Updated 2026-07-15

Phishing Email Red Flags: A Quick Spotter’s Guide

Phishing is a scammer pretending to be someone you trust — your bank, a delivery company, Microsoft, your boss — to trick you into clicking a bad link, opening a malicious attachment, or handing over a password. It’s the single most common way both individuals and businesses get compromised. The good news: most phishing shares the same tells.

The red flags

Safe habits

  1. Slow down. Urgency is the weapon. A real problem will still be real in ten minutes.
  2. Go direct. Instead of clicking the link, open a browser and type the company’s address yourself, or use their app. Log in there and check.
  3. Verify money and password requests out of band. Call the person or company using a number you look up independently — not the one in the email.
  4. Turn on two-factor authentication. Even if you slip and give up a password, 2FA can stop the attacker from getting in.
  5. When unsure, don’t click — ask. For a business, report it to whoever handles IT. For home, delete it, or have someone you trust take a look.

If you already clicked

Don’t panic. If you entered a password, change it immediately from a different, clean device and turn on 2FA. If it was a work account or money is involved, report it right away — quick reporting limits the damage. Watch the affected accounts closely for the next while.

Phishing works by rushing you. Recognize the pressure, slow down, and verify — that habit alone stops the vast majority of attacks.

← Back to the Knowledge hub