Question

How can I tell if an email is a phishing attempt?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Modern phishing is well written and often visually indistinguishable from the real thing, so advice based on spotting bad spelling is out of date. The reliable signals are structural rather than cosmetic.

Urgency and consequence are the most consistent tell. Messages claiming your account will be closed, a payment failed, or a delivery cannot proceed unless you act immediately are engineering a state where you click before thinking. Legitimate organisations rarely impose that kind of deadline by email.

Check where a link actually goes rather than what it says. Hovering reveals the destination, and the part to read is the domain immediately before the first single slash, not the beginning of the address. Attackers routinely construct names containing a real brand as a subdomain or path, which look convincing at a glance.

The sender address deserves the same scrutiny, though be aware it can be forged outright. A display name is trivially set to anything, so a message showing a company name proves nothing.

The strongest defence is procedural rather than analytical. Never act through a link in an unexpected message. Open the site yourself, or use the app, and check whether the claimed situation exists. If your account genuinely has a problem, it will be visible when you log in normally.

Be particularly careful with attachments you did not expect, especially documents prompting you to enable content, and with messages that appear to continue a conversation you do not remember starting.

One modern variant worth knowing is the message that arrives after a real event, such as a genuine delivery or a real payment, timed to seem plausible. Context is not verification.

Related Questions