Mailfornet

How to spot a phishing email: 8 signs people miss

Imagine it arrives at 11:40 at night, when you're half asleep. The subject says "Your parcel could not be delivered". The logo looks right. There's a small fee, less than the price of a cup of tea, to "reschedule". You really do have a parcel on the way, so you pay. This is one of the most common scams out there, and by the next morning the card details are already being used somewhere else.

Phishing emails used to be easy to spot, with broken English and a prince who needed help. Now they're short, clean, and timed to catch you when you're tired. The good news is that almost every one still leaves small clues. Here are the ones people skip past.

1. The sender name is right, the address isn't

Your email app shows the name, like "Amazon Support". Tap or hover over it to see the actual address. If it ends in something like @amazon-delivery-help.co or a random Gmail account, it's not Amazon.

2. It wants you to act in minutes

"Your account will be closed in 24 hours." "Last warning." Real companies rarely threaten you with a countdown. Urgency is there to stop you from thinking, so treat it as a reason to slow down.

3. The link text and the link don't match

A button says "Log in to PayPal", but when you hover over it on a computer, or long-press it on a phone, the web address underneath is something else entirely. Check the part just before .com. paypal.com.secure-login.net belongs to secure-login.net, not PayPal.

4. It greets you like a stranger

"Dear customer" or "Hello user" from a company that knows your name is a small red flag. It's not proof on its own, but it adds up.

5. It asks for something they'd never ask for

Your bank won't email you asking for your PIN, your password, or a one-time code. Nobody legitimate needs the code that was just texted to you. If someone asks you to read it back, it's a scam, full stop.

6. The attachment doesn't fit

An "invoice" you weren't expecting, a zipped file, or a document that asks you to "enable content" or "enable macros" to view it. Don't open it. Real invoices usually come from companies you already buy from, and you can check them by logging in to the site directly.

7. Small mistakes in a professional email

Scammers have gotten better at writing, but look closely. A slightly off logo, odd spacing, a date format that isn't used in your country, or a footer address that doesn't exist.

8. It's about something you never did

A receipt for a phone you didn't buy, or a password reset you didn't request. These are designed to make you panic and click "Cancel this order". Instead, open the company's app or type their website yourself and check there.

One habit that stops most phishing: never log in through a link in an email. Open the app, or type the website address yourself. If the problem is real, you'll see it there too.

If you already clicked

Don't feel stupid. It happens to careful people. Move quickly instead:

  1. Change the password for that account from the real website, and anywhere else you used the same password.
  2. Turn on two-factor authentication.
  3. If you entered card details, call your bank and block the card. The number is on the back of the card.
  4. Report the email as phishing in Gmail or Outlook so it gets blocked for others.
  5. Watch your accounts for a few weeks for anything unusual.

Fewer places your email lives, fewer phishing emails

Scammers need your address first. Every newsletter, contest, and random sign-up is another list your email could leak from. Using a temporary email for one-time sign-ups keeps your real inbox off those lists. For more on keeping your inbox quiet, see how to stop spam emails.

Get a temporary email Is temporary email safe?