All resources

Guide · For individuals

How to spot a phishing email: 7 red flags that give scammers away.

Almost every account takeover starts the same way: a message that looks normal and asks for something small. Here's how to catch it in the ten seconds before you click — plus exactly what to do if you already did.

~8 min read Updated July 2026 No jargon, promise

Hi 👋 Let's get one thing out of the way first: falling for a phishing email doesn't mean you're careless. These messages are designed by people who do this full-time, and they only need you to be distracted for one moment out of thousands. In 2025, people reported losing $3.5 billion to imposter scams — messages and calls pretending to be your bank, a government agency, a delivery service, a colleague. Roughly one in three fraud reports is one of these.

Source: U.S. Federal Trade Commission, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025,” June 2026.

The good news: nearly all of these messages share a handful of tells. Train your eye on the seven below and you'll catch the overwhelming majority — not by being paranoid, but by knowing exactly where to look.

The 7 red flags

Red flag

Manufactured urgency

“Your account will be suspended in 24 hours.” “Unusual sign-in detected — verify immediately.” Urgency is the engine of every scam, because stress narrows your attention exactly when you need it wide. Real companies almost never demand action within hours, and nothing legitimate is ruined by you taking ten minutes to check.

The move: when a message makes your stomach drop, that feeling itself is the signal to slow down, not speed up.

Red flag

The sender's address doesn't match the name

The display name says PayPal; the actual address is [email protected] or a random string at a free mail provider. The display name is whatever the sender wants it to be — the address is much harder to fake.

The move: tap or hover on the sender's name to expand the real address. Look hard at the part after the @ and right before the last dot: paypal.com is PayPal; paypal.com.account-verify.net is account-verify.net.

Red flag

Generic greetings and slightly-off details

“Dear Customer” from a bank that normally greets you by name. A parcel notification when you didn't order anything. An invoice from a service you don't use. Scammers send millions of copies, so the details are generic — or wrong in ways a real sender wouldn't get wrong.

The move: ask “does this match my actual life right now?” If the story doesn't fit, don't make it fit.

Red flag

Links that don't go where they claim

The text says www.yourbank.com; the link underneath goes somewhere else entirely. This is the single most reliable tell, because the attacker must get you to their site — everything else in the email can be perfect, but the link has to betray them.

The move: on a computer, hover over the link and read the URL preview in the corner before clicking. On a phone, long-press the link to see the destination. Better yet: don't click at all — open the app or type the site address yourself.

Red flag

Attachments you weren't expecting

An unexpected “invoice,” “voicemail,” “shared document,” or ZIP file. Attachments can carry malware that runs the moment you open them, and file names lie — invoice.pdf.exe is a program, not a PDF.

The move: never open an attachment you didn't ask for. If it claims to be from someone you know, confirm with them through another channel first — a text, a call, anything but replying to the email itself.

Red flag

Weird payment methods or a push to switch channels

Gift cards, cryptocurrency, wire transfers, payment apps — or “let's continue this on WhatsApp.” No legitimate company or agency collects debts in gift cards, and moving you to a private channel gets the conversation away from spam filters and witnesses. Add secrecy — “don't tell anyone about this” — and you can be certain.

The move: treat any unusual payment request as a full stop, not a detail to negotiate.

Red flag

It asks for credentials, codes, or personal data

Your bank will never ask for your password. Nobody legitimate will ever ask for a one-time code from your authenticator app or SMS — those codes exist precisely so that only you can use them. A message asking you to “verify” a code, a password, or your card details is the scam itself, not a security step.

The move: codes and passwords go into apps and websites you opened yourself — never into a reply, a form from an email link, or a phone call you didn't initiate.

“But it was so well written” — AI changed the game

For years the standard advice was “look for bad grammar.” Retire that one. Language models write flawless, personalized messages in any language, so polish tells you nothing anymore. The FBI's Internet Crime Complaint Center logged more than 22,000 complaints involving AI-enabled fraud in 2025, with reported losses topping $893 million — and voice cloning now powers “distress” scams, where a cloned voice that sounds exactly like a family member calls asking for urgent money. Those alone cost reported victims more than $5 million that year.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, pp. 39–40 (“Artificial Intelligence (AI) Used in Cybercrime”).

What still works when polish doesn't: verifying through a second channel. If “your bank” emails, call the number on the back of your card. If “your boss” asks for something odd, message them where you normally talk. And agree on a family safe word — a phrase only your family knows, to use if anyone ever calls in distress asking for money. A cloned voice can't answer it.

Already clicked? Do this in the next ten minutes

No shame, just speed. In order:

  1. If you entered a password: change it now, from a device you trust — and everywhere else you reused it. Turn on two-factor authentication on that account while you're there (here's the full passwords & 2FA setup when you have an evening).
  2. Sign out other sessions. Most services have a “log out of all devices” option in security settings; it kicks out anyone who got in.
  3. If you entered card or bank details: call your bank using the number on your card, not any number from the message. They handle this every day.
  4. If you opened an attachment: run your device's built-in security scan (Windows Defender or macOS's protections do a real job today) and keep an eye out for odd behaviour.
  5. Report it. Use your mail app's “report phishing” button — it trains filters for everyone. In the US you can also report at reportfraud.ftc.gov or ic3.gov.
  6. Watch your statements for the next couple of months — especially small “test” charges and new recurring subscriptions you don't recognize. Dispute anything unfamiliar.

If it turns out the message didn't just fish for a click but actually got into an account — you're locked out, or you can see activity you didn't do — switch to the full playbook: what to do in the first hour after a hack, in the right order.

The 60-second gut check

Before acting on any message that asks you to click, pay, or share:

  • Was I expecting this message?
  • Does the real sender address match the claimed sender?
  • Does the link's actual destination match the claimed one? (Hover or long-press.)
  • Is it pressuring me to act right now?
  • Is it asking for a password, a code, or an unusual payment?
  • Could I do this through the official app or website instead?
The one-line version

Never act on the message — act beside it. Open the app yourself, type the address yourself, call the number you already have. A real request survives that detour; a scam never does.

Quick answers

Doesn't my spam filter catch all this?

It catches most of the mass-produced stuff, which is exactly why the messages that do reach you deserve attention — they've already beaten the first line of defense. Filters are a seatbelt, not a self-driving car.

How did scammers get my email in the first place?

Usually from a data breach at some service you signed up for years ago, bought and sold in bulk. It's not personal, and it's not something you leaked — but it does mean “they knew my email” proves nothing about a sender being legitimate.

Is reporting actually worth the click?

Yes. Reports train the filters that protect everyone in your mail provider's network, and aggregate reports are how agencies like the FTC and FBI spot campaigns early. It's the cheapest good deed in security.

Keep going

This was one email. Lock down the rest of your digital life.

Get the free Security Starter Kit — ten moves, ordered by protection-per-effort, in plain language. Plus one short, practical email a week. No fluff, no spam.

Unsubscribe anytime. Explore more guides and resources.

Scroll to Top