GuideHQ

How do I spot a phishing email?

The signals that reliably identify a fake message, and the one habit that makes the question mostly irrelevant.

Difficulty
beginner
Time
10 min
Read
2 min

Short answer

Check the sender's actual email address, hover over links to see where they really go, and treat any urgency about your account as a warning sign. The reliable habit: never act on a link in an email — go to the site yourself instead.

Phishing works by creating urgency so you act before you think. Modern attempts are well-written and use real logos, so spotting them by quality alone no longer works. What still works is checking where the message came from and where its links actually lead.

What you'll need

  • The suspicious email

Step by step

  1. Look at the full sender address, not the display name.Display names are free text and can say anything. Expand the address — 'security@paypa1-verify.com' is not PayPal.
  2. Hover over links without clicking to see the real destination.On a phone, press and hold. The visible text and the actual address are often completely different.
  3. Treat urgency as the primary warning sign.'Your account will be closed in 24 hours' exists to stop you thinking. Real organisations do not work to that timetable.
  4. Be suspicious of any request for credentials or payment details.Banks, tax authorities and major services never ask you to confirm a password or full card details by email.
  5. Check whether it addresses you properly.'Dear Customer' from a company that knows your name is a signal — though a personalised greeting proves nothing, since names leak in breaches.
  6. Be extra careful with unexpected attachments.Invoices, delivery notes and receipts you were not expecting are the standard delivery method for malware.
  7. Go to the site yourself instead of using the link.Type the address or use your own bookmark. If the message was genuine, the same notice will be waiting in your account.
  8. Report it and delete it.Most mail clients have a report-phishing option. It helps their filters and takes one click.

Tips

  • Phishing arrives by text and phone too. The same rule applies: contact the organisation yourself using a number you already have.
  • If you clicked and entered a password, change it immediately on that service and anywhere you reused it, then check for new forwarding rules.
  • A message that is genuinely from your bank will never mind you hanging up and calling the number on your card.

Common mistakes

  • Trusting a message because it looks professional — Attackers copy real templates and logos exactly. Appearance proves nothing; the sender address and link destination do.
  • Clicking the unsubscribe link in a suspicious email — In a phishing message it confirms your address is live and monitored. Delete instead.
  • Replying to ask if it is genuine — You are asking the sender whether the sender is trustworthy. Contact the organisation through channels you already have.

Questions people ask

How can I tell if an email is really from my bank?

You often cannot from the message alone. Do not use its links — open your banking app or type the address yourself. Any genuine notice will be there too.

What should I do if I clicked a phishing link?

If you entered a password, change it immediately there and anywhere you reused it, enable two-factor authentication, and check for unfamiliar forwarding rules or recovery addresses on the account.

Written and maintained by the GuideHQ editorial team. More in Technology.