How to Spot a Phishing Email: 8 Red Flags
Phishing works best when a message makes you act before you inspect it. The design may be polished and the wording may be clean, so do not wait for an obvious spelling mistake. Check who sent it, where the link goes and what the message is asking you to do.
Eight tells of a phishing email
- 1. Urgency or fear. “Your account will be closed in 24 hours.” Pressure is the scammer's main tool.
- 2. A mismatched sender. The display name says “Your Bank” but the actual address is a random domain. Always check the real address.
- 3. Links that don't match. Hover over a link — if the destination isn't the official domain, don't click.
- 4. A greeting or detail that does not fit. “Dear customer” can be a clue, but personalised names can be copied too. Treat context as evidence, not proof.
- 5. Unexpected attachments. Invoices or “documents” you didn't request can carry malware.
- 6. Requests for credentials. A legitimate service should not ask you to reply with a password or enter full card details through an emailed form.
- 7. Subtle misspellings.
paypa1.com,amaz0n-support.com— look closely at the domain. - 8. Too good to be true. Refunds, prizes, and inheritances you never expected.
What to do instead of clicking
If a message might be real, leave its links alone. Open a new tab and type the company's address yourself, or use its official app. You can then check the account without letting the email choose your destination.
A disposable inbox changes the recipient address, not the destination behind a link. Apply the same caution you would in your primary inbox. See are temporary emails safe.
Reduce how much phishing you get
Reducing public exposure gives attackers fewer easy ways to connect a message to your main identity. Keep a personal address off public pages, use a disposable inbox only for permitted low-stakes signups, and report phishing through your provider. More on shrinking your footprint appears in 12 email privacy tips.
If you already clicked
Maybe the doubt arrived after you tapped the link or entered a password. Do not spend the next hour deciding whether it was really a scam. Close the page and work through the affected account while the details are still fresh.
- Stop and enter nothing more. Close the tab. Don't finish the form or "verify" again — every extra field is a gift to the scammer.
- Change the password from a known-good device. If the machine you just used might be compromised, switch to a phone or computer you trust, go to the account directly, and set a new, unique password — not a variation of the old one.
- Turn on two-factor authentication. A second factor limits what a stolen password can do. An authenticator app avoids SIM-swap risk, while a passkey or security key is harder to phish when the service supports one; NIST's current authenticator guidance explains that difference.
- Hunt for what they left behind. Attackers often add a hidden forwarding rule, a filter that buries security alerts, or a logged-in session to keep access after the reset. Check your forwarding, filters, and active-sessions pages and remove anything you don't recognise.
- Watch and report. Keep an eye on statements, and report it to the real company — or your bank, if a card was involved — using a number you look up yourself, never one from the message.
Resetting a password does not evict someone already signed in or forwarding your mail. The clean-up step matters as much as the new password — skip it and you lock the front door while the side gate stays open.
How to verify a suspicious message safely
Most messages aren't worth a clean-up at all if you check them before you act. The trick is to never let the email steer you:
- Go there yourself. Open a fresh tab and type the company's address, or use its official app. Reaching your account this way and seeing no alerts tells you the email was noise.
- Read the real sender domain. Look past the friendly display name to the actual address.
support@account-security-check.comis not your bank, whatever the name says. - Hover before you trust. Resting on a link (or long-pressing on mobile) shows the true destination. If the text says one site and the preview shows another, that gap is the whole scam.
Address separation can reduce how often low-value signups lead back to your main inbox, but it cannot make a suspicious message safe. The sender, destination and request still need the same scrutiny.
Quick FAQ
Is it safe to open a suspicious email? Reading a message in an updated mail client is generally lower risk than clicking a link or opening an attachment, but it is not completely private: remote images can report that the message was opened. Disable remote content if your client offers that option, and do not interact with the message.
What if I replied with information? Treat whatever you sent as compromised. If it was a password, change it everywhere you reused it and follow the steps above; if it was card or identity details, contact your bank. A reply also confirms your address is live, so expect more attempts.
Does receiving it in a temporary inbox make the links safe? No. A disposable address limits what a leak of that address exposes, but it does not inspect or endorse the link's destination. More on what these inboxes do and don't protect: are temporary emails safe and protecting your email from data breaches.