How to Spot a Phishing Email Before You Click

Most advice about phishing is out of date. It tells you to look for bad spelling, poor formatting, and generic greetings. Modern phishing has none of those — the messages are well written, correctly branded, and often personalized with details taken from a breach or from your public profile.

What hasn't changed is the underlying structure. Every phishing attempt needs to do the same three things, and those are what you look for.

The three things every phishing email needs

1. Create urgency. Your account will be suspended. A payment failed. Unusual activity detected. Someone is trying to sign in. Respond within 24 hours.

Urgency exists to stop you thinking. It's the most reliable signal there is, because a legitimate organization rarely needs you to act in the next ten minutes, and the ones that do won't email you about it.

2. Get you to a place where you'll enter something. A login page, a payment form, a verification screen. Or get you to open an attachment.

3. Make it feel plausible. Which is why the message references a service you actually use, arrives at a time that makes sense, and looks correct.

If a message is pushing you to act quickly on a link, treat it as suspicious regardless of how legitimate it looks. That's the whole heuristic, and it catches most of it.

What to actually check

The sender's actual address, not the display name. Display names are free text — anyone can set theirs to your bank. Expand the header and look at the real address. Watch for lookalike domains: an extra letter, a hyphen, a different top-level domain, a character swap that reads correctly at a glance.

Where the link actually goes. Hover over it on a computer, or long-press on a phone, and read the destination. Read it from the right: the real domain is the part immediately before the first single slash. yourbank.com.secure-login.example.net is on example.net, not your bank.

Whether they're asking for something no legitimate organization asks for. Your password. A two-factor code. Remote access to your computer. Payment in gift cards or cryptocurrency. Confirmation of full card details by email.

Whether you were expecting it. An unexpected invoice, an unexpected delivery notice, an unexpected password reset. Unexpected is the key word.

Whether the attachment makes sense. Especially documents asking you to enable content or enable macros. That prompt exists to bypass a security measure, and legitimate documents rarely need it.

The variants worth knowing by name

Spear phishing — targeted at you specifically, using real details about your job, your colleagues, or your recent activity. Far more convincing, and increasingly common because the information is cheap to gather.

Business email compromise — a message that appears to come from your boss, your accountant, or a supplier, asking for an urgent payment or a change to bank details. This is the costliest category for small businesses by a wide margin. Any request to change payment details should be verified by phone, on a number you already have, never a number in the email.

Invoice fraud — a real supplier's invoice, intercepted or imitated, with altered bank details. Same defence.

Smishing — the same techniques by text message. Delivery notices and bank alerts are the usual pretexts.

Vishing — by phone. Someone calls claiming to be your bank's fraud team, or technical support. They may know real details about you, which is disarming. Hang up and call back on a number from your card or the official website.

Fake two-factor prompts — a message or call asking you to read out a code you just received. No legitimate organization will ever ask for that code. Ever.

QR codes — increasingly used because the destination is invisible until you've scanned it. Be as cautious with an unexpected QR code as with an unexpected link.

The habit that defeats almost all of it

Never act on a link in an unexpected message. Go to the site yourself.

If your bank emails about a problem, don't click. Open your banking app or type the address you know. If there's a real problem, it'll be there.

If a service says your payment failed, log in directly and check.

If a colleague asks for something unusual, contact them another way.

This single habit removes essentially the entire attack surface. It costs you thirty seconds and it works even when the email is completely convincing — which increasingly it will be, because generated text has removed the language errors that used to give these away.

Why hardware keys and passkeys matter here

Everything above depends on your judgement, and judgement fails when you're tired, busy, or the message is unusually good.

Hardware security keys and passkeys don't depend on judgement. They verify the actual domain cryptographically, so a phishing site at a lookalike address gets nothing even if you're completely fooled and do everything the attacker wants.

That's why they're worth the friction for important accounts. They're the only defence that works when you make a mistake.

If you clicked

Don't panic, and act promptly.

If you only clicked and didn't enter anything: probably fine. Run a malware scan. Watch the account for unusual activity.

If you entered your password:

  1. Change that password immediately, from a different device if you can
  2. Change it anywhere else you used it — this is why reuse is dangerous
  3. Turn on two-factor authentication if it isn't on
  4. Sign out of all sessions on that account
  5. Check for changes: forwarding rules, recovery email, linked devices, connected apps

That last check is important. A common follow-up is to add an email forwarding rule so the attacker keeps receiving your mail after you change the password. Check your email rules specifically.

If you entered card or bank details: call your bank immediately, using the number on your card. Freeze the card.

If you opened an attachment: disconnect from the network, run a full malware scan, and consider whether the machine needs wiping. If it was a work machine, tell your IT contact now — the delay in reporting is what turns an incident into a breach.

If money was sent: contact your bank immediately. Fast reporting occasionally allows recovery. Report it to your national fraud reporting service.

In all cases: tell someone. Embarrassment is why these incidents go unreported, and unreported incidents get worse. Phishing works on competent, careful people; that's the entire point of the design.

For small businesses

Verify payment changes by phone, on a number you already had. This one rule prevents the most expensive category of loss.

Set a two-person rule for payments over a threshold.

Tell your team that no request from you will ever be urgent, unusual, and by email alone. Say it explicitly, so an unexpected message from "you" is immediately suspect.

Make reporting easy and blameless. The most damaging outcome is an employee who clicked and is too embarrassed to say so for three days.

Turn on two-factor everywhere, and consider hardware keys for anyone who can move money.

The five-second check

Before clicking anything in an email:

  1. Was I expecting this?
  2. Is it pushing me to act fast?
  3. Does the real sender address match the organization?
  4. Where does the link actually go?
  5. Could I just go to the site myself instead?

If the answer to the last one is yes — and it almost always is — do that instead.


Next in this series: How to Do a Yearly Security Checkup on Your Accounts