How to spot a phishing email before you click
The sender, the link, and the rush: a practical check you can run in ten seconds.
Phishing works because it asks you to do something you already do: log in, pay an invoice, or check a package. The message is not trying to look like a movie hacker. It is trying to look like Tuesday. This article is about the tells that still show up, and what to do in the ten seconds before you click.
Why a fake message gets through
Attackers copy logos, tone, and subject lines from real brands. They buy lookalike domains that swap one letter. They send from a display name you recognize while the actual address is different. Mobile mail apps hide that address until you tap it. That is not an accident.
Fear and speed do the rest. “Your account will close today.” “Unusual sign-in — confirm now.” “Payment failed.” You are meant to skip the slow check. Cyber security here is mostly slowing down.
A VPN does not stop phishing. A firewall does not stop phishing. Reading the address bar after you land on the page does.
The checks that still work
Start with the sender. Open the full email address, not the friendly name. A bank you already use will come from a domain you have seen on a statement, not from a free mailbox with the bank’s name in the local part.
Hover on a computer. Press and hold on a phone. The real destination is in the link preview. If it is a string of numbers, a misspelled brand, or a page that is only a login form with no other site around it, stop.
Look at what they want. Real companies rarely ask you to paste a password into an email. They rarely ask you to move money to “verify” an account. They almost never ask you to install a remote-support app because of a problem you did not report.
If the note mentions a package, open the carrier app you already installed. If it mentions a bill, open the site from your own bookmark. Do not use the button in the message as your front door.
After you already clicked
Close the tab. Do not type anything else on that page. If you entered a password, change it from a different device or from a bookmark you trust, and change it on every site where you reused that string. Turn on two-factor if it was off.
If you entered a card number, call the card number on the back of the card, not a number in the email. If you installed software, disconnect from the network and use another computer to change the important passwords first: email, then the password manager, then banking.
Report the message as phishing in your mail app so filters can learn. Delete it after you have reported it. Do not forward it to friends “as a warning” with the links intact.
Habits that shrink the target
- Use a password manager so a fake page cannot fill a saved login for the wrong domain.
- Keep a short list of bookmarked sites for mail, bank, and taxes.
- Treat unexpected attachments as hostile, even from a name you know.
- Confirm money requests by a second channel you already use.
Phishing is a test of attention, not of hardware. The people who rarely fall for it are not smarter. They have a rule: nothing important starts from a link that arrived uninvited.