How to Spot a Phishing Email
Spot a phishing email by checking the sender address and the real link destination first, then by judging the request, not the grammar. Expand the From field and confirm the domain after the @ symbol matches the real organization, hover over any link to read its true URL before clicking, and distrust urgent threats, unexpected attachments, and any request for a password, code, or payment. Because attackers now use AI to write clean, well-branded messages, spelling mistakes are a weak signal in 2026; the sender and the link are the reliable tells. When a message fails the check, report it, verify any real request through a known channel, and delete it.
A phishing email impersonates a trusted sender to trick the reader into revealing credentials, sending payment, or opening malware. It differs from ordinary spam because it aims to steal rather than merely advertise, and it almost always carries several detectable signs at once. The wider deception is covered in the overview of what phishing is, and the specific scams are listed in types of phishing attacks.
Read every message against the full checklist below, because a convincing phishing email may pass one test while failing another. The signs are ordered from the most reliable in 2026 (the sender and the link) to the weakest (grammar).
What Are the Top Red Flags in a Phishing Email?
Four red flags catch most phishing: a mismatched sender address, manufactured urgency, a link that points somewhere unexpected, and an attachment you did not ask for. Each names exactly what to inspect.
How Do I Check the Sender Address?
Checking the sender address reveals whether the message truly comes from the organization it claims. A phishing email often shows a trusted display name over a domain that does not match, so the display name alone is never proof.
- Expand the sender field to see the full email address behind the display name.
- Compare the domain after the @ symbol with the official domain of the organization.
- Watch for look-alike domains that swap or add characters, such as a zero for an O or an extra word like secure-.
- Treat a free webmail address claiming to be a bank or company as a strong warning sign.
- For a borderline message, open the header and check that the From, Reply-To, and Return-Path agree and that SPF, DKIM, and DMARC show Pass.
A spoofed sender is the foundation of most phishing, because the whole message depends on looking like a trusted source. A reply going to a different address than the one shown is a classic sign the From line was forged.
Why Is a Generic Greeting a Warning Sign?
A generic greeting flags a message sent to many recipients rather than to one named account holder. A real organization that holds your account usually addresses you by name.
- Treat “Dear Customer” as a warning sign. A generic greeting suggests a bulk message rather than one tied to a real account.
- Note a missing name on an account message. A bank or service that holds your real name rarely omits it on a genuine alert.
- Watch for the email address used as the name. A greeting that inserts your email address signals an automated bulk send.
- Weigh the greeting with other signs. AI now lets attackers personalize greetings cheaply, so a name is weaker proof than it was; treat the greeting as one input, not a verdict.
How Does Urgency Pressure the Reader?
Urgent or threatening language is the pressure tactic phishing uses to force a fast reaction. Urgency aims to stop the reader from checking the message carefully.
- Notice account suspension threats. A claim that an account closes within hours pressures an immediate, unverified click.
- Notice fake security alerts. A warning of a breach that demands a password reset through the email link is a common tactic.
- Notice unexpected reward or refund claims. A surprise prize or refund that requests details is designed to trigger a quick response.
- Pause on any deadline. A genuine organization allows time and offers a way to verify outside the email itself.
How Do I Inspect a Link Before Clicking?
Inspecting a link before clicking reveals the real destination, which often differs from the text shown. Hovering over a link displays the true URL in the status bar or a tooltip.

- Hover the cursor over the link without clicking and read the URL that appears.
- Compare the domain in the real URL with the official domain of the organization.
- Watch for a different domain hidden behind familiar link text or a shortened URL.
- Check for a misspelled or extra-word domain that imitates the real one.
- Open the site by typing the known address directly instead of clicking the link.
The visible link text can show one address while the real URL points to another. On a phone you cannot hover, so press and hold the link to preview the destination, and apply the same caution to a QR code, which simply hides a link inside an image.
Why Are Unexpected Attachments Dangerous?
Treating an unexpected attachment with caution prevents malware from running on the device. Phishing emails deliver malicious files disguised as invoices, receipts, or documents.
- Distrust files from unknown senders. An unexpected file from an unfamiliar address is a common malware delivery method.
- Watch for risky file types. An .exe, .scr, or macro-enabled Office file can run code when opened.
- Question an attachment that asks to enable content. A document prompting you to enable macros often hides malicious code.
- Verify before opening. Confirm an unexpected attachment with the sender through a separate channel first.
An opened malicious attachment can install malware that steals data or locks files. Removing such an infection is covered in the guide to remove malware from a PC.
Why Should I Never Send Credentials or Payment?
Any request for credentials or payment is the core goal of most phishing. A legitimate organization does not ask for a password or full payment details through an email link.
- Never enter a password from an email link. A login page reached through an email link can be a fake built to capture credentials. A strong, unique password still helps only if it is never typed on a fake page.
- Refuse requests for full card or bank details. A genuine institution does not collect full payment details by email.
- Distrust requests for one-time codes. A message asking for a verification code aims to defeat two-factor authentication.
- Reject pressure to bypass normal channels. A request to pay or share details outside the usual process is a strong fraud signal.
Credentials entered on a fake page hand an attacker direct account access. A second login step limits the damage, as covered in the guide to set up two-factor authentication.
Are Grammar Mistakes Still a Reliable Sign?
Grammar and branding errors used to expose phishing, but in 2026 they catch only the laziest attempts. Treat clean writing as no proof of safety, and keep your judgment on the sender and the link.

- A clumsy message is still suspect. Frequent spelling and grammar errors in an official-looking email still point to a fraudulent or low-effort source.
- But polished writing proves nothing. A grammatically perfect, well-branded message can be AI-generated, so it never clears the sender and link checks.
- Compare the logo and formatting. A stretched logo, wrong colors, or an off layout can still betray an imitation, though good fakes copy branding closely.
- Check the signature and contact details. A missing or inconsistent signature block differs from genuine correspondence.
What Should I Do With a Suspected Phishing Email?
Responding correctly removes the threat and warns the provider. The safe response avoids the links and verifies any real request separately.
- Do not click any link, scan any QR code, open any attachment, or reply to the message.
- Use the report phishing option in the email client to send the message to the provider.
- Verify any real-seeming request by contacting the organization through a known phone number or a bookmarked site, never the contact details in the email.
- Delete the message after reporting it.
- Change the password and review two-factor authentication if a link was already clicked or details entered.
Reporting a phishing email helps the provider block similar messages to other users. The broader habits that reduce exposure appear in the overview of online safety for beginners.
Common Mistakes to Avoid
- Trusting the display name alone. The display name is easily faked; the full sender address behind it must be checked.
- Trusting an email because it reads well. AI writes clean phishing, so good grammar is not safety; check the sender and the link instead.
- Clicking a link to verify a claim. A link must be inspected by hovering, and the site reached by typing the known address instead.
- Entering a password from an email link. A login page reached through an email can be a fake built to capture credentials.
- Acting on urgency without checking. Urgent deadlines are a pressure tactic; a genuine request allows time to verify.
Last Thoughts on Spotting Phishing Emails
A phishing email is spotted by reading it against a fixed checklist, but the weight of each sign has shifted. The sender address and the real link destination are now the reliable tells, while grammar has become a weak one, because attackers use AI to write clean, well-branded messages that older advice would wave through. Expand the From field, hover before clicking, distrust urgency and unexpected attachments, and refuse any request for a password, code, or payment.
When a message fails the check, the safe response is always the same: report it, verify any real request through a known channel, and delete it. Pairing this habit with a second login step and broader caution closes most of the gap. The collected security and how-to guides sit on the PC tutorials hub.
Key Takeaways:
- Check the full sender address first; a mismatched or look-alike domain behind a trusted display name is the strongest sign.
- Hover before clicking any link, and type the known address instead when the destination looks off.
- Treat urgency and threats as a tactic; a genuine request allows time to verify outside the email.
- Never enter credentials or send payment from an email link or reply, and never share a one-time code.
- Do not trust clean grammar; AI writes polished phishing, so judge the sender and the link, not the writing.
- Report the message, verify any real request through a known channel, and delete it.
Frequently Asked Questions (FAQs)
What is the first thing to check in a phishing email?
Check the full sender address, not the display name. Expand the From field and compare the domain after the @ symbol with the organization’s real domain. A trusted name over a look-alike or webmail domain is a primary warning sign.
Can a phishing email have perfect grammar?
Yes. Since 2025, attackers use AI to write phishing emails with flawless grammar and accurate branding, so spelling mistakes are now a weak signal. Judge the sender address and the link destination, which are far harder to fake convincingly.
How do I check if a link in an email is safe?
Hover the cursor over the link without clicking and read the real URL that appears in the status bar. Compare its domain with the official one. If the destination is unfamiliar or shortened, open the site by typing the known address instead.
Should I open an attachment from a suspicious email?
No. An unexpected attachment can run malware, especially .exe, .scr, or macro-enabled Office files. Verify the attachment with the sender through a separate, known channel before opening it.
Is a QR code in an email safe to scan?
Treat it with the same caution as a link. QR-code phishing, called quishing, rose sharply through 2025 and 2026 because the code moves the attack to a phone where security filters and link previews do not apply. Do not scan a QR code in an unexpected email.
What should I do if I clicked a phishing link?
Change the password for the affected account immediately and review two-factor authentication. Run a malware scan if a file was downloaded, watch the account for unauthorized activity, and report the message to your provider so it can block similar emails.


