Phishing is the most common way accounts and money get stolen — not through hacking, but by tricking you into handing over a password or clicking a poisoned link. The emails are getting better, but they almost always leave the same fingerprints if you know where to look.
This guide is a quick checklist for spotting a phishing email, whatever brand it pretends to be.
What you need
- ✓A moment to slow down — urgency is the scammer's main weapon.
- ✓The habit of checking the real sender address and link destinations.
- ✓A rule: never enter credentials on a page reached from an email.
Step-by-step
- 1
Check the real sender address
Don't trust the display name — expand the actual email address. Scammers use lookalikes like 'support@paypa1-secure.com' or a random address that has nothing to do with the brand. A mismatch is a giveaway.
- 2
Hover over links before clicking
Hover (or long-press on mobile) to see where a link really goes. If the visible text says one thing but the URL points to a different or misspelled domain, it's a trap. Never trust the button text alone.
- 3
Watch for urgency and threats
'Your account will be closed in 24 hours', 'Suspicious login — verify now', 'Payment failed'. Manufactured urgency is designed to make you act before you think. Real companies rarely threaten instant consequences by email.
- 4
Look for generic greetings and odd details
'Dear Customer' instead of your name, subtle spelling and grammar errors, slightly-off logos, or a request that a legitimate company would never make (like your full password). Any one is suspicious; together they're conclusive.
- 5
Never enter details from the email — go direct
If an email claims there's a problem with an account, don't use its links. Open a new tab, type the site's address yourself (or use your bookmark), and check there. Legitimate issues will show up when you log in normally.
Examples
- An email 'from your bank' linking to 'secure-bank-login.net' — the real bank's domain is nothing like that, revealing the fake instantly on hover.
- A 'delivery failed, pay £1.99 redelivery fee' text with a countdown — urgency plus a tiny payment request is a classic phishing pattern.
Tips
- →Slow down — urgency is the tell; a real problem can wait the minute it takes to verify.
- →Verify by going to the site directly, never through the email's links.
- →Two-factor authentication limits the damage even if you do slip up.
- →When unsure, contact the company through a number or address you find yourself, not one in the email.
- →Report phishing to your email provider and the impersonated company.
Common mistakes
- Trusting the display name. Check the actual sender address; names are trivially faked.
- Clicking to 'check' the link. Hover to preview the URL; go to the site directly instead of clicking.
- Acting on urgency. Slow down — pressure to act instantly is the scam's core tactic.
- Entering login details from an email. Never — always log in via the site you opened yourself.
Conclusion
Phishing relies on speed and trust — so slow down and verify. Check the real sender, hover every link, distrust urgency, and never enter credentials from an email. Go to sites directly, keep 2FA on, and the vast majority of scams fall apart the moment you look closely.