Skip to content

Spot a phishing email in ten seconds

Phishing works by rushing you. Learn the handful of tells that give it away and the one habit — stop and check — that defeats almost all of it.

EveryoneIntro6 min· Updated Jul 22, 2026
TL;DR

The short version

Phishing tries to make you act before you think — usually with urgency, a scary consequence, or a too-good offer. Slow down, check who really sent it and where the link really goes, and never enter a password or code on a page you reached by clicking a link in a message. When unsure, go to the site yourself.

Phishing is a message — email, text, chat, or call — that pretends to be from someone you trust to trick you into handing over a password, a code, money, or access. It's the most common way accounts get compromised, and it doesn't rely on you being careless. It relies on you being busy. The whole trick is to create a moment of pressure so you click before you think.

The tells

  • **Urgency and threats** — "Your account will be closed in 24 hours," "Unusual login — verify now." Real organizations rarely demand instant action under threat.
  • **A sender address that's slightly off** — the display name says your bank, but the actual email address is a jumble or a look-alike domain (paypaI-secure.com, not paypal.com).
  • **Links that don't go where they claim** — hover over a link (or long-press on mobile) to see the real destination before tapping.
  • **Requests for passwords, codes, or payment** — legitimate services never ask you to send them your password or one-time code.
  • **Generic greetings and odd wording** — "Dear Customer," awkward phrasing, or small grammatical slips.
  • **An unexpected attachment** — especially anything asking you to "enable content" or that arrives out of the blue.
Pitfall

The most dangerous phish looks perfect

Modern phishing can be flawless — correct logo, clean grammar, a real-looking domain. Don't rely only on spotting mistakes. The reliable defense is the habit below, not your eye for typos.

The one habit that beats it: stop and check

You don't have to correctly judge every message. You just have to refuse to act inside the message. If an email says there's a problem with your account, don't click its link — open a new tab and type the address yourself, or use the app. If a text from "your bank" asks you to confirm something, call the number on the back of your card, not any number in the message. This single habit — verify through a channel you already trust — defeats phishing even when the message is convincing.

Never hand over a one-time code

A common scam calls or messages you, says there's fraud on your account, and asks you to read back the verification code you just received "to confirm your identity." That code is the attacker logging in as you — reading it to them hands over your account. No legitimate company will ever ask you to share a one-time code. Treat any such request as an attack in progress.

If you clicked

Clicking a link isn't the end of the world, and panicking helps no one. If you entered a password, change it now (and anywhere you reused it) and turn on MFA. Then report it — see what to do if something goes wrong. Reporting quickly is how your IT team protects everyone else who got the same message.