Phishing emails used to be easy to spot from bad grammar and obvious fakes. That's less reliable now — scam emails are often well-written and visually convincing. The tells that still hold up are structural, not stylistic.
Check the actual sender address, not the display name
Email clients show a friendly display name ("Bank Security Team") that can say anything, regardless of the real address behind it. Tap or hover on the sender name to reveal the actual email address. A message claiming to be from a company but sent from a personal-looking or misspelled domain is the single most reliable red flag.
Hover before you click — check where a link actually goes
On desktop, hovering over a link (without clicking) shows the real destination URL, usually in the bottom corner of the browser or email client. On mobile, press and hold a link to preview it. Look closely at the domain — scam links often use a real company's name as a subdomain or with subtle misspellings (like a hyphen or an extra letter) to look legitimate at a glance.
Urgency is the tactic, not a coincidence
"Your account will be suspended in 24 hours," "Unusual sign-in detected — verify now," "Payment failed, update your card immediately" — manufactured urgency is designed to make you act before you think carefully. Legitimate companies rarely demand immediate action through email alone, especially for account security matters.
Requests that don't match how the real company operates
Real financial institutions and most major services won't ask you to email your password, send a gift card code, or provide a one-time login code you didn't request. If an email asks for something that feels like it's bypassing normal account security rather than going through it, treat that as a strong signal, regardless of how official the email looks.
Attachments you weren't expecting
An unexpected invoice, shipping label, or "document" attachment — especially one you're pressured to open quickly — is a common malware delivery method. If you weren't expecting a file from that sender, verify through a separate channel before opening it.
When it looks like it's from someone you know
Compromised accounts sometimes send phishing emails to the real contacts of the account owner, which is why "it's from someone I know" isn't a safe assumption anymore. If a message from a known contact asks for something unusual — money, gift cards, login help — verify through a different channel (a text or call) before acting.
A quick checklist before you click anything
- Check the actual sender address, not just the display name.
- Hover or long-press links to preview the real destination.
- Be suspicious of urgency and threats of immediate consequences.
- Question requests that bypass normal account security steps.
- Verify unexpected attachments before opening them.
- When in doubt, go to the company's site directly instead of clicking through.