A phishing email is one of the most common tricks scammers use to steal money or personal information. It lands in your inbox looking like it came from your bank, the post office, Amazon, or even a family member.

The good news is that most phishing emails share the same handful of warning signs. Once you know what to look for, they get much easier to spot.

This guide walks through the 7 signs to check, how to look at a link safely before you click it, and exactly what to do if you already clicked one. None of it requires any special tech skill, just a habit of slowing down for a moment before you act.

How Do You Spot a Phishing Email?

The fastest way to spot a phishing email is to check whether it is trying to rush you into clicking a link or handing over personal information. Real companies rarely demand instant action by email. Once you notice that pressure, look for the other signs below to confirm your suspicion.

Plain talk: phishing

Phishing is a fake email, text, or website built to look like it comes from a real company or person, with the goal of tricking you into giving up money, passwords, or personal details.

The 7 warning signs

  1. A sense of urgency or fear. The email says your account will be closed, a payment failed, or you will be charged unless you act “immediately” or “within 24 hours.” Scammers want you to react before you think.
  2. A sender address that does not match. The display name might say “Amazon Support,” but the actual email address is a long string of letters at a strange domain, not amazon.com.
  3. Links that lead somewhere odd. The blue link text might say “Update Your Account,” but the web address underneath goes to a completely different, unfamiliar site.
  4. Spelling and grammar mistakes. Real companies proofread their emails carefully. Odd phrasing, missing words, or misspelled company names are a red flag.
  5. Requests for personal information. Legitimate banks and government agencies do not email you asking for your password, full Social Security number, or a one time login code.
  6. Generic greetings. “Dear Customer” or “Dear Valued Member” instead of your actual name can mean the sender does not really know who you are, because they sent the same email to thousands of people.
  7. Unexpected attachments. An invoice, shipping label, or “voicemail” file you were not expecting can carry harmful software. Do not open attachments from senders you do not recognize.

Safety tip

Never give a one time login code from a text or authenticator app to anyone who contacts you by email or phone, even if they say they work for your bank. Banks never need that code from you.

Real email vs. phishing email

What to check Real company email Likely phishing email
Sender address Matches the company’s real domain exactly Odd domain, extra words, or misspelled name
Tone Calm, no deadline pressure Urgent, threatening, or “act now”
Greeting Often uses your real name “Dear Customer” or no name at all
Links Match the company’s real website Lead to an unfamiliar or misspelled site

According to the Federal Trade Commission’s guide on phishing scams, legitimate companies will not email or text you a link asking you to update your payment information out of the blue. That single habit, treating any unexpected “update your payment” link as suspicious, blocks a large share of phishing attempts on its own.

Phishing is also common enough that it is worth taking seriously. The FBI’s Internet Crime Complaint Center received 323,972 complaints about phishing, vishing, smishing, and pharming in 2021, more than any other crime type it tracks. Separately, Verizon’s 2022 Data Breach Investigations Report found that 82 percent of data breaches involved a human element, such as someone clicking a phishing link or handing over login details. The Anti-Phishing Working Group, an industry and law enforcement group that tracks phishing worldwide, reported that attacks kept climbing through 2022 in its quarterly trends reports, so this is not a problem that is going away on its own.

You do not need to click a link to see where it actually goes. A quick check first can save you a lot of trouble later.

On a computer:

  1. Move your mouse pointer over the link, but do not click.
  2. Look at the bottom left corner of your browser window. The real web address the link leads to will pop up there.
  3. Compare that address to the company’s actual website. Watch for extra words, odd endings, or a misspelled company name, such as “arnazon” instead of “amazon.”

On an iPhone or iPad:

  1. Press and hold your finger on the link, without lifting it.
  2. A preview box will pop up showing the full web address.
  3. Read the address carefully, then lift your finger away from the screen to close the preview without opening anything.

On an Android phone:

  1. Press and hold the link the same way.
  2. A menu will appear, often showing the address near the top.
  3. Tap outside the menu to close it if you do not trust what you see.

Try this

If a link claims to be from your bank or a company you use, close the email and open that company’s app or website yourself instead, using an address you already know or have saved. Do not use the link in the email at all.

Plain talk: look-alike domain

A look-alike domain is a web address built to resemble a real company’s name, such as “paypal-secure-login.com” instead of paypal.com. It is close enough to fool a quick glance.

Reading the web address carefully matters more than the padlock icon or the word “secure” in the address. Scammers can and do use those too. Focus on the actual company name right before the “.com” or other ending, and be suspicious of anything with extra words tacked on.

If you clicked a phishing link, stay calm. Clicking alone is usually not the same as being hacked, and there are clear next steps. What you do next depends on whether you also entered any information.

  1. Do not enter anything. If a fake login page opened and you have not typed anything yet, simply close the browser tab or window.
  2. If you typed a password, change it right away. Go to the real website directly (not through the email link) and update that password, plus any other account using the same password.
  3. If you entered a credit card or bank number, call your bank. Use the phone number on the back of your card, not any number from the email.
  4. Run a security scan. Open your device’s security software and run a full scan to check for anything unusual.
  5. Watch your accounts closely for the next few weeks for charges or logins you do not recognize.

Our article on what to do after clicking a scam link walks through this same checklist in more detail, including how to spot warning signs that something was installed on your device.

If you shared enough personal information that you are worried about identity theft, our guide on freezing your credit after a scam explains how to lock things down with the credit bureaus.

Type or say this

If a family member calls worried they clicked something, you can say: “Let’s stop for a second. Did you type in a password or card number, or just click the link?” That one question tells you how serious it is.

Reporting a Phishing Email

Reporting a phishing email helps your email provider and government agencies track and block scammers faster.

  • In Gmail, open the email, click the three dot “More” menu next to Reply, and choose “Report phishing.”
  • In Outlook and most other email apps, look for a similar “Report” or “Junk” option in the same menu.
  • You can also forward suspicious emails to the Anti-Phishing Working Group at [email protected], a group of security companies and law enforcement that tracks phishing trends.
  • For scams that cost you money or personal information, file a report at ReportFraud.ftc.gov.

Our guide on where to report a scam breaks this down by country, including the US, UK, Australia, and Canada.

Phishing by text message uses many of the same tricks as phishing by email. If a suspicious text about a package or toll payment has you wondering, our article on package delivery scam texts covers those specific red flags.

If you would like a simple, printable checklist to keep near your computer, our Scam-Stopper Kit (free when you join our email letter) includes a one page version of these warning signs.

Where to go from here

Phishing emails rely on catching you off guard for just a few seconds. Slowing down before you click, checking the sender address, and hovering over links before trusting them will stop the vast majority of attempts. For a wider look at protecting yourself and older family members from scams like this one, our book Scam-Proof covers phishing alongside phone, text, and in person scams in plain language.