Independent tech news and plain advice
Technologicall

Tech Advice

How to Spot a Phishing Email Before You Click

A phishing email tries to rush you into clicking a link, opening a file or sharing a password. Slow down, check who really sent it, and go to the company yourself instead of using the link.

To spot a phishing email, ignore how polished it looks and focus on what it wants. If it pushes you to click a link, open a file, sign in, pay, or share a code, and it creates a reason to hurry, treat it as a trick until you prove otherwise. Then go to the company yourself, using an app or a website you already trust, not the link in the email.

Phishing is the most common way accounts get stolen. A few habits stop almost all of it.

The Short Answer

  • Pressure is the biggest clue. "Act now," "your account will be closed," or "payment failed" are classic hooks.
  • Check the real sender. The name can say anything. The address after the @ tells the truth.
  • Hover before you click. On a computer, rest your mouse on the link to see where it really goes.
  • Never sign in from an email link. Open the app or type the address yourself.
  • Report and delete. Forward to reportphishing@apwg.org, then delete it.

The Warning Signs

The FTC lists the stories phishing emails tell most often. They claim there is suspicious activity on your account, a problem with your payment, or a bill you do not remember. Here is what to check.

It Wants You to Hurry

Scammers want you to act before you think. Threats of a locked account, a missed delivery, a late fee or a legal problem are all ways to rush you. A real company will give you time.

The Sender Address Does Not Match

Your email app shows a display name, like "Apple Support" or "Bank Security." Tap or click the name to see the full address. Look closely at the part after the @. Scammers use addresses like support@apple-id-help.net or swap letters, like rn for m. If it does not end in the company's real domain, it is not from them.

The Link Goes Somewhere Else

On a computer, hover your mouse over a link without clicking. The real address shows at the bottom of the window. On a phone, press and hold the link to preview it. If the address is long and strange, uses a link shortener, or does not match the company, do not open it.

It Asks for Something a Real Company Would Not

The FTC is clear on this. Real companies will not email or text you a link to update your payment information. They also will not ask for your password, a sign in code, your full Social Security number or gift card numbers by email.

There Is an Attachment You Did Not Expect

Fake invoices, shipping labels and voicemail files are common. Do not open an attachment you were not expecting, even from someone you know, until you check with them another way.

The Greeting Is Generic

"Dear customer" or "Dear user" instead of your name can be a clue. It is a weaker one today, since scammers often have your name from leaked data.

Clues That No Longer Work

People used to spot phishing by bad spelling and clumsy grammar. That is no longer reliable. AI writing tools let scammers produce clean, friendly emails in seconds, in any language. Some even copy the look of real company emails exactly.

So stop grading the writing. Grade the request. Any email that wants a click, a sign in, a payment or a code gets the same check, no matter how professional it looks. Our guide on using AI chatbots safely has more on how these tools are changing everyday scams.

The One Habit That Beats Phishing

Go around the email. If an email says there is a problem with your bank, Amazon, Apple or Netflix account, close the email. Open the company's app, or type its web address yourself, and sign in there. If there is a real problem, you will see it. If there is not, you just dodged a scam.

The FTC puts it simply. If you do have an account with the company, contact it using a phone number or website you know is real, not the details in the email.

Turn On Protection That Works Even If You Slip

Everyone clicks the wrong thing sometimes. These steps limit the damage when you do.

  • Two-factor authentication. A stolen password alone will not get a thief in. Our guide to two-factor authentication shows how to turn it on.
  • Passkeys. A passkey only works on the real website, so a fake login page cannot capture it. See passkeys explained.
  • A password manager. It will not offer to fill in your password on a fake site, which is a useful warning sign. Our guide on how to make a strong password covers picking one.
  • Updates. Keep your phone, computer and browser up to date so known holes are closed.

How to Report a Phishing Email

Reporting helps email providers and security groups block the same attack for other people.

  • Forward it to reportphishing@apwg.org. The FTC lists this address for phishing emails.
  • Use your email app's button. Gmail, Outlook and Apple Mail all have a way to report junk or phishing.
  • If it pretends to be a company, tell the company. Many have a report address on their site.
  • If you lost money or shared details, report it at ReportFraud.ftc.gov.

Phishing texts work the same way. Forward them to 7726, which spells SPAM. Our guide on how to stop spam calls covers texts too.

What to Do If You Already Clicked

Do not panic. What you do next depends on what happened after the click.

You Clicked but Did Not Type Anything

Close the page. Run a security scan on your computer. On Windows, use Windows Security. Make sure your browser and system are up to date. In most cases that is the end of it.

You Typed a Password

Change that password right away on the real site, using a device you trust. If you use the same password anywhere else, change it there too. Turn on two-factor authentication. Check the account for changes you did not make, like a new forwarding rule in your email or a new recovery phone number.

You Shared Card or Bank Details

Call your bank or card company using the number on the back of your card. Tell them what happened. They can block the card and watch for fraud.

You Shared Your Social Security Number or Other ID

Go to IdentityTheft.gov. The FTC built it to give you specific steps based on what was exposed. Consider freezing your credit with the three credit bureaus. It is free.

You Opened an Attachment

Disconnect from the internet, run a full security scan, and change important passwords from a different, clean device. If you think your phone is involved, our guide on how to tell if your phone is hacked walks through the next steps.

Common Mistakes

  • Trusting the display name. Always check the full sender address.
  • Signing in from the link "just to check." That is exactly what the scam wants.
  • Replying to ask if it is real. The scammer will say yes.
  • Thinking you are too careful to fall for it. Good phishing works on smart people when they are busy or tired.

The Bottom Line

You do not need to become a security expert. You need one rule. Never act on a link or file in an email that pushes you to hurry. Go to the company yourself instead. Add two-factor authentication or passkeys so one bad click cannot cost you your account.

Keep Reading

New phishing campaigns and data breaches land almost every week, and we cover them in our security news. Browse more plain tech advice, or add our RSS feed to get new guides first.

Questions Readers Ask

How can you tell if an email is phishing?

Look for pressure to act fast, a sender address that does not match the company, a link that goes somewhere odd, a request for passwords or payment details, or a bill you do not recognize. The FTC says real companies will not email you a link to update your payment information.

What happens if I just open a phishing email?

Opening it is usually safe on a modern, updated device. The danger comes from clicking links, opening attachments, replying or entering details. Do not load images from unknown senders if your email app asks.

What should I do if I clicked a link in a phishing email?

If you did not type anything, close the page and run a security scan. If you entered a password, change it right away on the real site and turn on two-factor authentication. If you shared card or bank details, call your bank using the number on your card.

How do I report a phishing email?

Forward it to reportphishing@apwg.org, and use the Report phishing or Report spam button in your email app. If you lost money or shared personal details, also report it at ReportFraud.ftc.gov.

Can a phishing email come from someone I know?

Yes. If a friend's or coworker's account was hacked, phishing emails can come from their real address. If a message feels off, check with them by phone or text before you click anything.

Are phishing emails easier to spot now?

Not always. AI tools help scammers write clean, natural emails with no spelling mistakes, so bad grammar is no longer a reliable clue. Focus on what the email asks you to do, not how well it is written.

What is the difference between phishing and spam?

Spam is unwanted junk, like ads. Phishing is a trick meant to steal your passwords, money or personal details. All phishing is unwanted, but not all spam is phishing.

Further Reading