How to Spot a Phishing Email: 9 Red Flags Everyone Should Know
Last month, my dad called me in a panic. He’d gotten an email saying his bank account was “locked due to suspicious activity” and he needed to verify his identity immediately. The logo, the colors — it all looked real. He was one click away from typing in his password.
It was fake. Completely fake. And honestly? It was a good fake — good enough that I don’t blame him for almost falling for it.
Forget the obvious “Nigerian prince” scams — modern phishing emails are slick, professional, and designed to catch smart people on a busy day. Learning how to spot a phishing email is basic digital hygiene, like locking your front door.
Here are the 9 red flags I always check. Run through them every time an email makes you feel even slightly uneasy.
1. The Sender’s Address Doesn’t Match the Company
This is the single most important check, and it takes five seconds. The display name might say “PayPal” or “Amazon” — but what does the actual email address say?
On your phone, tap the sender’s name to reveal the full address. On a computer, hover over it. A real email from your bank comes from something like support@yourbank.com. A phishing email comes from something like support@yourbank-secure-verify.net or yourbank@gmail.com.
Scammers love adding words like “secure,” “verify,” or “alert” to look official. They also use lookalike characters — like replacing the letter “l” with the number “1.” If the domain looks even slightly off, that’s your answer right there.
2. You’re Greeted Like a Stranger
“Dear Customer.” “Dear Account Holder.” “Hello User.”
Your bank knows your name. Amazon knows your name. Legitimate companies personalize emails because they have your account on file.
Phishing emails go out to thousands of people at once, so scammers use generic greetings. On its own it’s not proof — but combined with any other red flag here, it’s a strong warning.
3. It Tries to Scare You Into Acting Fast
“Your account will be SUSPENDED in 24 hours.” “Unauthorized login detected — verify NOW.” “Your package delivery FAILED — click here immediately.”
This is the oldest trick in the book, and it still works because it bypasses your thinking brain. Urgency and fear make you act before you question. That’s exactly what the scammer wants.
Here’s my rule: any email pressuring you to act immediately deserves extra suspicion, not faster action. If something is genuinely urgent, log into the company’s official website or app directly — never through the email’s link.
4. The Links Don’t Go Where They Claim
This one is sneaky. The email says “Log in to your account” and the link text looks perfectly normal. But where does it actually go?
On a computer, hover your mouse over the link (don’t click!) and look at the address that appears in the bottom corner of your browser. On a phone, long-press the link to preview the URL.
A legit link goes to the company’s real domain. A phishing link goes somewhere else entirely — often a jumble of random words, a URL shortener, or a domain that’s close-but-not-quite, like amaz0n-deals.com instead of amazon.com.
I check this on every unexpected email. It takes two seconds.
5. There’s an Attachment You Didn’t Ask For
Got an unexpected invoice, receipt, or “shipping document” attached? Be very careful. Malicious attachments are one of the main ways scammers install malware on your computer.
The golden rule: never open an attachment you weren’t expecting, even if it comes from someone you know — their account could be compromised. If a company supposedly sent you a document, go to their official website and download it from your account there instead.
And if the attachment asks you to “enable macros” or “enable content” to view it? That’s not a document, that’s a trap. Close it immediately.
6. It’s Too Good to Be True
“You’ve won a $500 gift card!” “You’re owed a tax refund of $847.32!” “Claim your free iPhone!”
Come on. You know how this works. Nobody is giving away free iPhones over email.
These “prize” emails prey on excitement instead of fear, but the goal is identical: get you to click and hand over your details. If you didn’t enter a contest, you didn’t win one.
7. The Writing Feels… Off
I want to be honest here: this red flag is less reliable than it used to be. A few years ago, phishing emails were full of broken English and obvious typos. These days, scammers use AI tools that write perfectly polished emails.
Still, plenty of phishing emails do have awkward phrasing, weird capitalization, or sentences that just don’t sound like a professional company wrote them. If an email from “Microsoft Support” reads like it was translated three times, trust your gut.
But don’t rely on this one alone. A perfectly written email can still be fake — which is why you check the sender address and links first.
8. It Asks for Sensitive Information Directly
This is the big one. No legitimate company will ever ask for your password, bank PIN, social security number, or full credit card details over email. Ever. Not your bank, not PayPal, not the tax office, not anyone.
If an email asks you to “confirm” your password or “verify” your card number by replying or filling in a form, that is phishing. Full stop. Real companies direct you to log into your secure account through their official website or app.
My dad’s fake bank email? It asked him to “verify his identity” by entering his online banking password on the linked page. That’s the moment I knew for sure. Real banks don’t do that.
9. It’s About a Login or Code You Didn’t Request
“Your verification code is 483920.” “Someone just signed into your account from a new device.”
If you get one of these and you didn’t just try to log in somewhere, pay attention. It could mean someone else is trying to access your account right now — possibly because they got your password from an earlier phishing attempt.
Don’t click any links in that message. Instead, go directly to the company’s website or app, log in normally, and check your account activity. Change your password if anything looks unfamiliar, and turn on two-factor authentication if you haven’t already.
What to Do If You Already Clicked
Okay, deep breath. It happens to millions of people. Here’s what to do right now:
- Don’t enter any information. If you clicked but haven’t typed anything, you’re probably fine — just close the page.
- If you entered a password, change it immediately on the real website, and change it anywhere else you used the same password.
- If you entered card or bank details, call your bank right away using the number on the back of your card.
- Run a security scan on your device if you downloaded anything.
- Report it. In Gmail, open the message and click the three dots > Report phishing. In the UK, you can forward suspicious emails to report@phishing.gov.uk. In the US, report to the FTC at reportfraud.ftc.gov.
Final Thoughts
Here’s what I tell my family: you don’t need to become a cybersecurity expert. You just need to build one habit — pause before you click. Check the sender. Hover over the link. Ask yourself: did I expect this?
Scammers are counting on you being busy, tired, or distracted. The five seconds it takes to check is the most valuable five seconds of your online day.
And if you’re ever unsure? Forward it to a tech-savvy friend and ask. There’s no shame in double-checking.
