Security & Privacy

How to Spot a Phishing Email

Learn the calm, simple signs that reveal a phishing email, so you can recognize scams, protect your accounts, and respond with confidence instead of panic.

A person reading an email on a laptop with a suspicious warning symbol
Photograph via Unsplash

The fastest way to spot a phishing email is to ignore how it looks and check two things a scammer struggles to fake: the real sending domain and the true destination of every link. Logos, colors, and a familiar "From" name are trivial to copy, so treating them as proof is exactly what gets people caught. The underlying address and URL are where the deception falls apart.

Read the real sender address, not the display name#

The "From" line has two parts, and only one of them matters. The friendly display name ("PayPal Service," "Microsoft account team," "IT Helpdesk") is just editable text the sender typed. The real identity is the address in angle brackets, and one level deeper, the authenticated sending domain.

To see the truth, open the raw headers. In Gmail, click the three-dot menu on the message and choose Show original; in Outlook on the web, use ... > View > View message source. At the top of that view you will see three authentication results: SPF, DKIM, and DMARC. For a genuine message from a large brand, DMARC almost always shows PASS and the authenticated domain matches the brand exactly (for example paypal.com, not paypal-security.com).

One important nuance most guides skip: SPF or DKIM passing does not mean the email is safe. A scammer who owns secure-paypal-alerts.com can make their own domain pass SPF perfectly. What matters is alignment — whether the authenticated domain is the actual company's domain. A pass on an unrelated domain is meaningless.

Look-alike domains and the subdomain trap#

Scammers register domains that read correctly at a glance:

  • Character swaps: paypaI.com using a capital "I" instead of a lowercase "l," or rn standing in for "m" as in arnazon.com.
  • Homograph/punycode attacks: Cyrillic or accented letters that render like Latin ones. In the raw address these show up with an xn-- prefix — a strong danger sign.
  • The subdomain trick: apple.com.account-verify.xyz. The real domain is always the label immediately to the left of the top-level suffix, so this is really account-verify.xyz, not Apple. Read domains right-to-left to find the true owner.

Never trust the visible link text. "Click here to verify" or a printed www.yourbank.com is just a label; the actual href can point anywhere. On a computer, hover your cursor over the link and read the real URL in the status bar at the bottom of the window. On a phone, press and hold the link to preview the destination without opening it.

Watch specifically for:

  • Shorteners and redirects: bit.ly, tinyurl, or tracking links that hide the final destination. Legitimate password-reset and billing links from major providers rarely need a shortener.
  • Domain mismatch: the button says "Netflix" but the URL is netflix-billing-update.info.
  • Credential harvesters: a link that jumps straight to a login form asking for your existing password.

The single habit that defeats nearly every phishing link: don't log in from email links at all. Open a new browser tab and type the address yourself, or use the company's official app. If the "urgent" alert is real, it will be waiting in your account when you get there.

The pressure and content tells#

Phishing is social engineering first and technology second. The message is engineered to make you act before you think, so the emotional texture is a signal in itself.

  • Manufactured urgency: "Your account will be suspended in 24 hours," "unusual login detected," "payment failed — update now." Real companies give you time and a calm path to respond.
  • Requests for secrets: any email asking for your full password, card PIN, or a one-time verification code is a scam. No legitimate bank or provider will ever ask you to read back a 2FA code they sent you.
  • Odd greetings: "Dear Customer" or "Dear [email protected]" from a company that knows your name.
  • Off-brand language: awkward grammar, or conversely, unnaturally perfect corporate phrasing that doesn't match the sender's usual tone. AI has made spelling mistakes a weaker signal than they used to be, so weigh it alongside the other checks rather than relying on it.

Attachments, QR codes, and the reply trap#

Not every payload is a link. Treat unexpected attachments as guilty until proven innocent, especially these file types:

  • .html or .htm attachments that open a local fake login page (no suspicious domain to spot, because it runs from the file itself).
  • Macro-enabled Office files (.docm, .xlsm) that prompt you to "Enable Content" or "Enable Editing" — that click is the attack.
  • .zip, .iso, or .lnk files that hide an executable.
  • PDFs containing a "View secure document" button that leads to a credential form.

Two newer variants deserve attention. Quishing replaces the link with a QR code in the email body or an attached PDF, because a code sidesteps link-hovering and often gets scanned on a phone with weaker filtering — point your camera to preview the URL before opening it, and apply the same domain check. And beware the thread hijack, where a scammer replies inside a real, existing email conversation (sometimes from a genuinely compromised contact). Familiarity is not verification; check the link and sender anyway.

Common mistakes that get people caught#

  • Trusting the padlock/HTTPS. The padlock only means the connection is encrypted, not that the site is honest. Free certificates mean most phishing pages now show HTTPS too.
  • Trusting a perfect logo. Images are copied in seconds. A flawless design is not evidence.
  • Checking only the display name. As above, that field is free text. Always read the real address.
  • Assuming mobile is safer. Small screens hide the full URL and truncate sender addresses, which is exactly why phishing click-throughs are often higher on phones.
  • Reusing one password. If a fake page captures a password you use elsewhere, one compromise becomes many.

The strongest structural defense is passkeys or app-based two-factor authentication. A passkey is cryptographically bound to the real website's domain, so even if you're tricked onto a look-alike page, there is no reusable secret for the attacker to steal.

If you already clicked#

Acting within minutes limits the damage.

  1. Change the password immediately — but from the official app or a URL you typed yourself, never the email link. Then change it anywhere you reused it.
  2. Turn on two-factor authentication (or a passkey) if it wasn't already active.
  3. Sign out other sessions. Most services have a "log out all devices" or "where you're signed in" option in security settings; use it to kick out an attacker who already got in.
  4. If you shared card or bank details, call your bank using the number on the back of your card, not any number from the email, and watch your statements.
  5. If you opened an attachment, run a full antivirus scan and, on a work device, tell IT right away.

How and where to report#

Reporting helps providers block the campaign for everyone. In Gmail and Outlook, use the built-in Report phishing option rather than plain "Delete," which trains the spam filters. You can also forward the message to the Anti-Phishing Working Group at [email protected]. In the US, report fraud at reportfraud.ftc.gov; in the UK, forward suspicious emails to [email protected] and text scam SMS to 7726.

FAQ#

Can a phishing email harm me if I only open it, without clicking?#

Usually just opening the message is low-risk on a modern, updated mail client, which blocks remote content by default. The danger comes from clicking links, opening attachments, or entering information. Still, avoid loading images from unknown senders, since that can quietly confirm your address is active.

Is bad spelling still a reliable sign of phishing?#

Less than it used to be. Attackers now use AI to write clean, convincing copy, so polished grammar is no longer reassuring. Rely on the sender domain, link destination, and urgency tactics instead of typos alone.

Why do phishing sites still show the padlock icon?#

Because the padlock only confirms the connection is encrypted, not that the owner is legitimate. Free certificates are available to anyone, including scammers. Judge the site by its actual domain name, not the padlock.

What is quishing and why is it dangerous?#

Quishing is phishing that uses a QR code instead of a clickable link. It is effective because a code hides the destination URL and is typically scanned on a phone, where filtering is weaker and the full address is hard to inspect. Preview the link your camera app shows before opening it, and apply the same domain checks.

Theo Vance
Written by
Theo Vance

Theo writes about online safety the way a good friend would — clearly, calmly, and without trying to scare you. He's interested in the simple habits that stop most problems, and he thinks staying private online is a skill anyone can learn.

More from Theo