How to Spot a Phishing Email: 12 Red Flags to Check

You can spot a phishing email by checking four things: who really sent it, what it wants you to do, where its links actually lead, and whether it creates pressure. A message that fails any of these checks deserves suspicion, even if the logo and wording look perfect.
What phishing emails are trying to achieve
Phishing is a message designed to trick you into giving up something valuable: a password, a payment, a one-time code, or access to your device. The attacker does not need to break any technology if they can persuade you to open the door yourself.
Most phishing falls into three goals. Credential theft sends you to a fake login page. Malware delivery uses an attachment or download. Payment fraud asks you to pay a bill, buy gift cards or change bank details. Knowing the goal helps you see the trick behind the wording.
12 red flags to check
- Sender mismatch. The display name says a bank or delivery company, but the address behind it belongs to an unrelated domain.
- Lookalike domains. Letters swapped, extra words added, or a different ending, such as a hyphenated name that merely resembles the real one.
- Generic greeting. “Dear customer” from a company that normally uses your name.
- Urgency or threats. Account closure, legal action or a deadline measured in hours.
- Unexpected attachments. Especially compressed files, documents asking you to enable macros, or invoices you never requested.
- Links that do not match. Hovering shows a destination different from the text displayed.
- Requests for secrets. Legitimate organizations do not ask for passwords or full card details by email.
- Odd tone. Awkward phrasing, or a formal message from someone who normally writes casually.
- Too-good offers. Unexpected refunds, prizes or job offers.
- Unusual timing or context. A message about an order you never placed.
- Mismatched reply address. Replies go to a different address than the sender.
- Login prompts inside the message. Forms embedded in the email body asking you to sign in.
No single flag proves fraud, and polished attacks may show only one or two. Treat the combination, and your own gut feeling that something is off, as the signal.
A safe way to check a suspicious message
Slow down first. Urgency is the attacker’s main tool, and a short pause removes most of its power. Then follow this routine:
- Do not click links or open attachments in the message.
- Open the official website or app by typing the address yourself, or use a bookmark you saved earlier.
- Check whether the same notice appears in your account’s message centre.
- Look at the full sender address, not just the display name.
- If the email claims to be from a coworker or manager, confirm through a different channel such as a phone call or chat.
- Report the message using your email provider’s phishing button, then delete it.
Why good phishing still works
Attackers study what people respond to. They copy real branding, time messages around events such as tax season or holiday shopping, and reuse genuine wording from legitimate notices. Some use spear phishing, where the message mentions your name, job title or a real colleague, making it feel personal.
Another trick is the reply-chain hijack, in which an attacker who has already taken over one mailbox replies inside an existing conversation. Because the thread is familiar, people lower their guard. If a reply in a known thread suddenly asks for money or a strange file, verify it by another route.
If you already clicked
Clicking a link is not always a disaster, but act promptly depending on what happened.
- Clicked only: close the page, clear nothing, and run a security scan if the page tried to download something.
- Entered a password: change it immediately on the real site, and anywhere else you reused it, then sign out of other sessions.
- Entered card details: contact your card issuer, report the card as compromised and ask for a replacement.
- Opened an attachment: disconnect from the internet, run a full scan, and tell your IT contact if it is a work device.
Turn on multi-factor authentication for important accounts afterwards. It will not stop every attack, but it makes a stolen password far less useful.
Phishing at work versus at home
The tricks are similar, but the stakes differ. At home, attackers usually want personal accounts, card details or streaming and shopping logins. At work, they want something larger: access to company systems, payroll changes, or the ability to send convincing messages to customers.
- Payroll and bank detail changes. A message claiming to be an employee asking to update their deposit details is a classic work scam.
- Shared document notices. Fake notifications that a file has been shared with you, leading to a fake sign-in page.
- Executive requests. A message from a senior colleague asking for gift cards, urgent payments or secrecy.
- IT warnings. Fake alerts about mailbox quotas or password expiry.
If you use a work account, follow your organization’s reporting process and do not try to investigate alone. Reporting quickly helps colleagues who may have received the same message, and it gives defenders time to block the sender before others click.
Frequently asked questions
Can I be hacked just by opening a phishing email?
Opening a plain email is rarely dangerous on modern mail services, because scripts are blocked. The risk comes from clicking links, opening attachments or enabling content. Keep your software updated and avoid interacting with anything suspicious.
Why do phishing emails go to my spam folder sometimes and my inbox other times?
Filters make probabilistic guesses, and attackers constantly adjust wording and sending methods to slip through. A message in the inbox is not proof of safety, so apply the same checks everywhere.
Should I reply to tell the sender to stop?
No. Replying confirms your address is active and can invite more messages. Report the email as phishing, delete it and move on.
Key takeaways
- Check the true sender, the real link destination and the pressure level before acting.
- Go to official sites by typing the address or using a saved bookmark, never through the message.
- If you clicked or entered details, change passwords and contact your card issuer quickly.
- Report suspicious messages so filters improve for everyone.


