The 9 Red Flags of a Phishing Email
Got an unexpected email asking you to click, download, or “verify” something? Run through this list first. One red flag means slow down. Two or more? It’s almost certainly phishing — delete it and move on.
1. The sender address doesn’t match the company
The display name says “PayPal” or “Amazon,” but the actual address behind it is support@paypa1-secure.com, amaz0n-billing.net, or some random Gmail account. On a computer, hover over the sender name to reveal the real address. On a phone, tap the sender name to expand it. Scammers are counting on one thing: that you’ll never look past the display name. I nearly fell for one of these myself last year — a “delivery failed” email from a name I trusted, with a nonsense address hiding underneath.
2. Manufactured urgency or threats
“Your account will be suspended in 24 hours.” “Unauthorized login attempt — verify immediately.” “Your package will be returned today.” Feel that little spike of panic? That’s the entire trick. Urgency shuts down your judgment, which is exactly why scammers manufacture it. Here’s the reality check: legitimate companies almost never threaten account closure by email, and they never demand action within hours. When an email tries to rush you, slow down.
3. Links that lie about where they go
Hover over any link — don’t click, just hover — and glance at the preview in your browser’s bottom-left corner. Watch for misspelled domains (micorsoft.com), tacked-on words (apple-support-desk.com), and URL shorteners hiding the real destination. If the visible text says “bankofamerica.com” but the actual link points somewhere else entirely, you have your answer. Walk away.
4. Attachments you didn’t ask for
“Invoice.zip.” “Payment Details.html.” Real companies send you a link to log into your account; they don’t fire executable-style attachments at you out of nowhere. The one to watch right now: HTML attachments that open a fake login page. The “document” is just a password-stealing form in disguise. Didn’t ask for it? Don’t open it.
5. Generic greetings
“Dear Customer,” “Dear User,” “Hello.” Companies you actually do business with usually address you by name. Mass phishing campaigns blast out millions of emails, so personalization isn’t an option — they don’t even try. One caveat: targeted “spear phishing” can use your real name. So a personalized greeting doesn’t prove an email is safe; it just means a generic one is a clue that it’s not.
6. Too-good-to-be-true offers
Surprise tax refunds. Prize winnings for a contest you never entered. Mystery-shopper jobs. Crypto schemes that double your money overnight. If you didn’t enter it, you didn’t win it. These work because excitement feels a lot like urgency — both switch off careful thinking. Sound familiar? That’s the point.
7. Requests for sensitive information
No legitimate bank — and no real government agency — asks for your full Social Security number, your password, or your card PIN by email. Ever. The IRS doesn’t even initiate contact by email, full stop. Any email asking you to “confirm” sensitive details is phishing. No exceptions.
8. Slightly-off branding and sloppy details
Blurry or stretched logos. Wrong brand colors. A strange footer address. An “urgent” email from the CEO landing at 3 AM. All worth noticing — but here’s an important update: don’t lean on bad grammar anymore. AI-written phishing now has perfect spelling and a polished corporate tone. Treat flawless English as neutral evidence, not proof of legitimacy.
9. Login or code prompts you didn’t trigger
“Someone requested a password reset for your account.” A two-factor code text you never asked for. This one is different — it’s not just a warning sign, it’s an emergency. It means someone already has your password and is standing at the 2FA gate right now. Don’t approve it, don’t click it — go straight to the real site and change your password immediately.
What to Do If You Already Clicked (or Entered Info)
Okay, deep breath. Clicked the link? Maybe even typed something in? Don’t panic — most phishing damage is still preventable if you act in the next few minutes. Here’s the order of operations:
- Stop and don’t enter anything else. Close the tab. Honestly, clicking a link alone rarely infects a modern, updated browser — the damage happens when you type credentials or open downloads. If you haven’t done either, you’re probably fine.
- If you downloaded a file, don’t open it. Delete it, then run a full antivirus scan with Windows Security or Malwarebytes Free, just to be safe.
- Change your password from the real site. Type the address manually or use a bookmark — never use the email’s link. Start with your email account, since it controls all your other password resets.
- Turn on two-factor authentication. Even with your password in their hands, 2FA can lock attackers out. See our two-factor setup guide for the 5-minute version.
- Check for damage. Review recent login activity on the account, and scan bank and card statements for charges you don’t recognize. Most banks show pending transactions the same day — don’t wait for the monthly statement.
- Report it. In Gmail, open the message, click ⋮ > Report phishing. Got a phishing text instead? Forward it to 7726 (SPAM). In the US, report to the FTC at reportfraud.ftc.gov — those reports power the takedowns that protect everyone else.
- If you entered card or bank details, call your bank now. They can freeze the card and issue a new number in minutes. Don’t let embarrassment slow you down — bank fraud teams deal with this every single day. It’s routine for them.
Phishing FAQs
Can phishing come by text message?
Yes — it’s called “smishing,” and it’s everywhere now. Fake delivery texts, toll-road payment demands, bogus bank alerts — same playbook, smaller screen. Don’t tap the link; open the official app or type the address yourself. And forward spam texts to 7726.
Are QR codes safe to scan?
Not automatically. “Quishing” is a real thing — malicious QR stickers slapped on parking meters, restaurant tables, and even mailed letters, all routing you to phishing sites. Your phone shows a URL preview before opening it; read that preview the way you’d hover over an email link.
Will my antivirus stop phishing?
Partially. Antivirus helps with malicious downloads and blocks some known phishing pages, but phishing is fundamentally social engineering — it’s tricking you, not your software. Your judgment is the real filter; the red flags above are its training data.
I replied to a phishing email. Now what?
Don’t reply again — but otherwise treat it like a click: change the relevant passwords from the real site, enable 2FA, and keep an eye on your accounts. One more thing: replying confirms your address is active, so expect more spam and phishing over the next few weeks. Stay sharp.