Phishing emails used to be easy to spot from bad grammar and obvious fakes. That's less reliable now — scam emails are often well-written and visually convincing. The tells that still hold up are structural, not stylistic.

Check the actual sender address, not the display name

Email clients show a friendly display name ("Bank Security Team") that can say anything, regardless of the real address behind it. Tap or hover on the sender name to reveal the actual email address. A message claiming to be from a company but sent from a personal-looking or misspelled domain is the single most reliable red flag.

Hover before you click — check where a link actually goes

On desktop, hovering over a link (without clicking) shows the real destination URL, usually in the bottom corner of the browser or email client. On mobile, press and hold a link to preview it. Look closely at the domain — scam links often use a real company's name as a subdomain or with subtle misspellings (like a hyphen or an extra letter) to look legitimate at a glance.

Urgency is the tactic, not a coincidence

"Your account will be suspended in 24 hours," "Unusual sign-in detected — verify now," "Payment failed, update your card immediately" — manufactured urgency is designed to make you act before you think carefully. Legitimate companies rarely demand immediate action through email alone, especially for account security matters.

Requests that don't match how the real company operates

Real financial institutions and most major services won't ask you to email your password, send a gift card code, or provide a one-time login code you didn't request. If an email asks for something that feels like it's bypassing normal account security rather than going through it, treat that as a strong signal, regardless of how official the email looks.

Attachments you weren't expecting

An unexpected invoice, shipping label, or "document" attachment — especially one you're pressured to open quickly — is a common malware delivery method. If you weren't expecting a file from that sender, verify through a separate channel before opening it.

When it looks like it's from someone you know

Compromised accounts sometimes send phishing emails to the real contacts of the account owner, which is why "it's from someone I know" isn't a safe assumption anymore. If a message from a known contact asks for something unusual — money, gift cards, login help — verify through a different channel (a text or call) before acting.

If you're ever unsure, don't click any link or button in the email. Instead, open a browser and go to the company's site directly, or use the customer service number on your card or a past statement. This sidesteps the entire question of whether the email or its links are legitimate.

A quick checklist before you click anything