LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Tutorials
Beginner 8 min read

How to Spot a Phishing Attack

Phishing emails mimic banks, employers, and services you trust. Learn to spot fake sender addresses, urgent language, and deceptive links before you click.

1 May 2026

What Is Phishing?

Phishing is one of the most common cyberattacks in the world. The name comes from the word "fishing" — attackers cast a wide net, hoping someone takes the bait. The goal is simple: trick you into handing over sensitive information like passwords, credit card numbers, or personal details.

Phishing can arrive in your email inbox, as an SMS text message (called smishing), over the phone (called vishing), or even through social media. Regardless of the channel, the core tactic is always the same — impersonate a trusted source and create a sense of urgency.

Red Flags in Phishing Emails

Email remains the most popular vehicle for phishing. Here are the warning signs to watch for:

Suspicious Sender Address

The display name might say "PayPal Support" but the actual email address could be something like support@paypa1-help.com. Always click on the sender's name to reveal the full address. Legitimate companies send email from their own domains — if it doesn't match, don't trust it.

Generic Greetings

Legitimate companies that have your account information will usually address you by name. Phrases like "Dear Customer", "Dear User", or "Hello Friend" are classic phishing signals.

Urgent or Threatening Language

Attackers want you to act before you think. Phrases like:

  • "Your account will be suspended in 24 hours"
  • "Unusual activity detected — verify immediately"
  • "You have a pending package — click to reschedule"

...are designed to bypass your critical thinking. Slow down whenever you feel pressured to click quickly.

Mismatched or Suspicious Links

Hover your mouse over any link before clicking — the actual URL will appear in your browser's status bar or as a tooltip. Look for:

  • Misspelled domain names (e.g., arnazon.com instead of amazon.com)
  • Extra subdomains (e.g., amazon.com.suspicious-site.com — the real domain here is suspicious-site.com)
  • URL shorteners like bit.ly used to hide the true destination

Poor Grammar and Spelling

Many phishing messages originate from non-native speakers or automated tools. Obvious typos, awkward phrasing, or inconsistent formatting are red flags — though note that modern AI tools have made phishing messages increasingly polished.

Unexpected Attachments

If you weren't expecting an invoice, shipping notice, or document, don't open it. Malicious attachments — especially .exe, .zip, .docm, or .pdf files — can install malware the moment you open them.

Spotting Phishing SMS Messages

SMS phishing (smishing) follows the same playbook. Common examples include fake package delivery notifications, bank alerts, and prize notifications. Rules to follow:

  • Don't click links in unsolicited texts. Go directly to the company's official website instead.
  • Be suspicious of any text from an unknown number asking you to verify account information.
  • Legitimate banks will never ask for your PIN or full account number via text.

How to Verify a Suspicious Website

If you do land on a website and aren't sure it's legitimate, check these things:

  1. Look at the URL carefully. Make sure the domain is spelled correctly and that you're on the right site.
  2. Check for HTTPS. A padlock icon in the address bar means the connection is encrypted — but it does NOT mean the site is safe. Phishers use HTTPS too. The padlock only tells you your connection is secure, not that the site is trustworthy.
  3. Look for trust signals. Does the site have a privacy policy? Contact information? Does it look professionally designed?
  4. Search for the company independently. If you're unsure, open a new tab and Google the company's name to find their official site.

What to Do If You Suspect Phishing

  • Don't click, don't reply, don't call any number listed in the message.
  • Report it. Forward phishing emails to your email provider's abuse address or use the "Report Phishing" button in Gmail or Outlook.
  • Delete the message.
  • If you accidentally clicked a link or submitted information, change your passwords immediately and contact the impersonated organization directly.

Quick Reference Checklist

Before clicking any link in an email or text, ask yourself:

  • Do I recognize this sender?
  • Was I expecting this message?
  • Does the link go where it claims to go?
  • Is it creating urgency or fear?
  • Does anything look slightly "off"?

If you answer "no" or "I'm not sure" to any of these, treat the message as suspicious. When in doubt, go directly to the organization's website by typing the address in your browser yourself.

#phishing#email#SMS#security basics