How to Spot a Phishing Attack
Phishing emails mimic banks, employers, and services you trust. Learn to spot fake sender addresses, urgent language, and deceptive links before you click.
Table of Contents
- What Is Phishing?
- Red Flags in Phishing Emails
- Suspicious Sender Address
- Generic Greetings
- Urgent or Threatening Language
- Mismatched or Suspicious Links
- Poor Grammar and Spelling
- Unexpected Attachments
- Spotting Phishing SMS Messages
- How to Verify a Suspicious Website
- What to Do If You Suspect Phishing
- Quick Reference Checklist
What Is Phishing?
Phishing is one of the most common cyberattacks in the world. The name comes from the word "fishing" — attackers cast a wide net, hoping someone takes the bait. The goal is simple: trick you into handing over sensitive information like passwords, credit card numbers, or personal details.
Phishing can arrive in your email inbox, as an SMS text message (called smishing), over the phone (called vishing), or even through social media. Regardless of the channel, the core tactic is always the same — impersonate a trusted source and create a sense of urgency.
Red Flags in Phishing Emails
Email remains the most popular vehicle for phishing. Here are the warning signs to watch for:
Suspicious Sender Address
The display name might say "PayPal Support" but the actual email address could be something like support@paypa1-help.com. Always click on the sender's name to reveal the full address. Legitimate companies send email from their own domains — if it doesn't match, don't trust it.
Generic Greetings
Legitimate companies that have your account information will usually address you by name. Phrases like "Dear Customer", "Dear User", or "Hello Friend" are classic phishing signals.
Urgent or Threatening Language
Attackers want you to act before you think. Phrases like:
- "Your account will be suspended in 24 hours"
- "Unusual activity detected — verify immediately"
- "You have a pending package — click to reschedule"
...are designed to bypass your critical thinking. Slow down whenever you feel pressured to click quickly.
Mismatched or Suspicious Links
Hover your mouse over any link before clicking — the actual URL will appear in your browser's status bar or as a tooltip. Look for:
- Misspelled domain names (e.g.,
arnazon.cominstead ofamazon.com) - Extra subdomains (e.g.,
amazon.com.suspicious-site.com— the real domain here issuspicious-site.com) - URL shorteners like
bit.lyused to hide the true destination
Poor Grammar and Spelling
Many phishing messages originate from non-native speakers or automated tools. Obvious typos, awkward phrasing, or inconsistent formatting are red flags — though note that modern AI tools have made phishing messages increasingly polished.
Unexpected Attachments
If you weren't expecting an invoice, shipping notice, or document, don't open it. Malicious attachments — especially .exe, .zip, .docm, or .pdf files — can install malware the moment you open them.
Spotting Phishing SMS Messages
SMS phishing (smishing) follows the same playbook. Common examples include fake package delivery notifications, bank alerts, and prize notifications. Rules to follow:
- Don't click links in unsolicited texts. Go directly to the company's official website instead.
- Be suspicious of any text from an unknown number asking you to verify account information.
- Legitimate banks will never ask for your PIN or full account number via text.
How to Verify a Suspicious Website
If you do land on a website and aren't sure it's legitimate, check these things:
- Look at the URL carefully. Make sure the domain is spelled correctly and that you're on the right site.
- Check for HTTPS. A padlock icon in the address bar means the connection is encrypted — but it does NOT mean the site is safe. Phishers use HTTPS too. The padlock only tells you your connection is secure, not that the site is trustworthy.
- Look for trust signals. Does the site have a privacy policy? Contact information? Does it look professionally designed?
- Search for the company independently. If you're unsure, open a new tab and Google the company's name to find their official site.
What to Do If You Suspect Phishing
- Don't click, don't reply, don't call any number listed in the message.
- Report it. Forward phishing emails to your email provider's abuse address or use the "Report Phishing" button in Gmail or Outlook.
- Delete the message.
- If you accidentally clicked a link or submitted information, change your passwords immediately and contact the impersonated organization directly.
Quick Reference Checklist
Before clicking any link in an email or text, ask yourself:
- Do I recognize this sender?
- Was I expecting this message?
- Does the link go where it claims to go?
- Is it creating urgency or fear?
- Does anything look slightly "off"?
If you answer "no" or "I'm not sure" to any of these, treat the message as suspicious. When in doubt, go directly to the organization's website by typing the address in your browser yourself.