Security & Privacy
How to Spot a Phishing Email
Learn the calm, simple signs that reveal a phishing email, so you can recognize scams, protect your accounts, and respond with confidence instead of panic.
Security & Privacy
Learn the calm, simple signs that reveal a phishing email, so you can recognize scams, protect your accounts, and respond with confidence instead of panic.
The fastest way to spot a phishing email is to ignore how it looks and check two things a scammer struggles to fake: the real sending domain and the true destination of every link. Logos, colors, and a familiar "From" name are trivial to copy, so treating them as proof is exactly what gets people caught. The underlying address and URL are where the deception falls apart.
The "From" line has two parts, and only one of them matters. The friendly display name ("PayPal Service," "Microsoft account team," "IT Helpdesk") is just editable text the sender typed. The real identity is the address in angle brackets, and one level deeper, the authenticated sending domain.
To see the truth, open the raw headers. In Gmail, click the three-dot menu on the message and choose Show original; in Outlook on the web, use ... > View > View message source. At the top of that view you will see three authentication results: SPF, DKIM, and DMARC. For a genuine message from a large brand, DMARC almost always shows PASS and the authenticated domain matches the brand exactly (for example paypal.com, not paypal-security.com).
One important nuance most guides skip: SPF or DKIM passing does not mean the email is safe. A scammer who owns secure-paypal-alerts.com can make their own domain pass SPF perfectly. What matters is alignment — whether the authenticated domain is the actual company's domain. A pass on an unrelated domain is meaningless.
Scammers register domains that read correctly at a glance:
paypaI.com using a capital "I" instead of a lowercase "l," or rn standing in for "m" as in arnazon.com.xn-- prefix — a strong danger sign.apple.com.account-verify.xyz. The real domain is always the label immediately to the left of the top-level suffix, so this is really account-verify.xyz, not Apple. Read domains right-to-left to find the true owner.Never trust the visible link text. "Click here to verify" or a printed www.yourbank.com is just a label; the actual href can point anywhere. On a computer, hover your cursor over the link and read the real URL in the status bar at the bottom of the window. On a phone, press and hold the link to preview the destination without opening it.
Watch specifically for:
bit.ly, tinyurl, or tracking links that hide the final destination. Legitimate password-reset and billing links from major providers rarely need a shortener.netflix-billing-update.info.The single habit that defeats nearly every phishing link: don't log in from email links at all. Open a new browser tab and type the address yourself, or use the company's official app. If the "urgent" alert is real, it will be waiting in your account when you get there.
Phishing is social engineering first and technology second. The message is engineered to make you act before you think, so the emotional texture is a signal in itself.
Not every payload is a link. Treat unexpected attachments as guilty until proven innocent, especially these file types:
.html or .htm attachments that open a local fake login page (no suspicious domain to spot, because it runs from the file itself)..docm, .xlsm) that prompt you to "Enable Content" or "Enable Editing" — that click is the attack..zip, .iso, or .lnk files that hide an executable.Two newer variants deserve attention. Quishing replaces the link with a QR code in the email body or an attached PDF, because a code sidesteps link-hovering and often gets scanned on a phone with weaker filtering — point your camera to preview the URL before opening it, and apply the same domain check. And beware the thread hijack, where a scammer replies inside a real, existing email conversation (sometimes from a genuinely compromised contact). Familiarity is not verification; check the link and sender anyway.
The strongest structural defense is passkeys or app-based two-factor authentication. A passkey is cryptographically bound to the real website's domain, so even if you're tricked onto a look-alike page, there is no reusable secret for the attacker to steal.
Acting within minutes limits the damage.
Reporting helps providers block the campaign for everyone. In Gmail and Outlook, use the built-in Report phishing option rather than plain "Delete," which trains the spam filters. You can also forward the message to the Anti-Phishing Working Group at [email protected]. In the US, report fraud at reportfraud.ftc.gov; in the UK, forward suspicious emails to [email protected] and text scam SMS to 7726.
Usually just opening the message is low-risk on a modern, updated mail client, which blocks remote content by default. The danger comes from clicking links, opening attachments, or entering information. Still, avoid loading images from unknown senders, since that can quietly confirm your address is active.
Less than it used to be. Attackers now use AI to write clean, convincing copy, so polished grammar is no longer reassuring. Rely on the sender domain, link destination, and urgency tactics instead of typos alone.
Because the padlock only confirms the connection is encrypted, not that the owner is legitimate. Free certificates are available to anyone, including scammers. Judge the site by its actual domain name, not the padlock.
Quishing is phishing that uses a QR code instead of a clickable link. It is effective because a code hides the destination URL and is typically scanned on a phone, where filtering is weaker and the full address is hard to inspect. Preview the link your camera app shows before opening it, and apply the same domain checks.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.