How to spot phishing
Phishing emails keep getting harder to spot – logos, sender names and wording often look convincingly real. Still, there are warning signs you can check yourself before you click. This checklist helps you do that. Still unsure? Just forward me the email as an attachment.
5 typical warning signs
1. An unusual sender address
The displayed name can look real ("PayPal Support"), while the actual address behind it is completely unrelated. Don't trust the name – check the full email address for swapped letters or an unusual domain ending.
2. Artificial urgency or threats
"Your account will be locked in 24 hours", "Act now", "Final notice" – phishing relies on you clicking before you think. Legitimate companies rarely pressure you like this.
3. An impersonal or wrong greeting
"Dear Customer" instead of your name is a hint, not proof – some phishing emails are personalized these days. Always check the sender and the link as well.
4. Links that don't match the sender
On a computer, hover your mouse over a link without clicking – the actual destination shows up in your browser or mail program. If the target address doesn't match the claimed sender, be careful.
5. A request for login or payment details
Banks, insurers and legitimate shops never ask for passwords, PINs or one-time codes by email. Requests to pay via gift cards or instant transfer are also a clear red flag.
Bonus: An unexpected attachment
An invoice, overdue notice or "voice memo" you weren't expecting? Don't open it – especially .zip, .exe, .js files or Office documents asking you to enable macros.
Common phishing scams
- Parcel scams: A fake delivery notice from a courier claiming a failed delivery, linking to a bogus "redelivery fee" page.
- Bank phishing: A fake security alert from your bank or PayPal asking you to "verify" via a link.
- Fake invoices: An invoice for an order or subscription you never made – often with a malicious attachment instead of a link.
- CEO fraud: An email that appears to come from an executive, requesting an urgent, confidential transfer – mostly relevant in a business context.
- Fake prize notifications: A claimed prize that first requires you to hand over personal details or pay a fee to receive it.
- Extortion emails: A claim that your device is hacked and compromising material exists – usually an empty bluff with no real basis.
Still not sure?
When in doubt, don't click any link and don't open any attachment. Forward the suspicious email to me instead as an attachment – I'll check the headers, links and typical phishing traits automatically, for free.
Get your email checked nowHow it works: Guide for your email program