How to Spot a Phishing Email

Learn how to spot phishing emails with sender checks, urgent language, suspicious links, attachments, payment requests, reporting steps, and FAQs.

TechnologyEdited by Pramod Tiwari
2 min read

Quick Answer

To spot a phishing email, check the sender address, look for urgent or threatening language, avoid clicking unexpected links, hover or long-press to inspect URLs, be suspicious of attachments and payment requests, verify through the official website or phone number, and report the message.

What You Need

  • Email app
  • Official website or phone number for verification
  • Password manager if available
  • Spam/report button
  • Security contact for work emails

Safety Precautions

  • Do not open unexpected attachments.
  • Do not enable macros from emailed documents.
  • If you clicked a suspicious link, change passwords from the official site and review account activity.
  • Use multifactor authentication on important accounts.

Privacy and Safety Notes

  • Do not reply with passwords, codes, bank details, ID numbers, or payment information.
  • Never share one-time codes with someone who contacted you.
  • Use official websites typed manually instead of email links.
  • Report suspicious work emails to your IT or security team.

Step-by-Step Instructions

  1. Step 1

    Check the sender

    Look beyond the display name and inspect the full email address.

  2. Step 2

    Notice pressure tactics

    Phishing often uses urgency, fear, prizes, account holds, missed deliveries, or threats.

  3. Step 3

    Inspect links safely

    Hover on desktop or long-press on mobile to preview URLs without opening them.

  4. Step 4

    Question attachments

    Unexpected invoices, shipping notices, forms, or shared files can be risky.

  5. Step 5

    Verify independently

    Go to the official website or call a known number instead of using email links.

  6. Step 6

    Report the email

    Use spam, phishing, or security reporting tools in your email app or workplace.

  7. Step 7

    Secure accounts if needed

    If you interacted with the message, change passwords, enable MFA, and monitor activity.

Practical Example

Example: An email says your bank account is locked and asks you to click a link. You close the email, type the bank website manually, and find no alert.

Common Mistakes

  • Trusting the display name
  • Clicking because the logo looks real
  • Sharing one-time codes
  • Opening unexpected attachments
  • Using email links for account recovery
  • Ignoring suspicious grammar or odd domains

Troubleshooting

I clicked the link

Do not enter more information. Change the affected password from the official site and review account activity.

I entered my password

Change it immediately, enable MFA, and update any account using the same password.

It might be a work email

Report it to IT or security before replying or opening attachments.

The email looks real

Verify through a separate official channel and do not rely on email links.

FAQs

What is phishing?

Phishing is a scam that tricks people into giving information, money, or access by impersonating a trusted source.

Are all phishing emails badly written?

No. Some look polished and convincing, so verify sender, links, and context.

Can phishing happen by text?

Yes. Similar scams can arrive by email, text, messaging apps, social media, or phone.

What should I do with a phishing email?

Do not interact. Report it, delete it, and secure accounts if you clicked or shared information.

Technology2 min read

How to Use Facebook

Learn how to use Facebook as a beginner, including profile setup, posting, friends, groups, privacy settings, safety tips, mistakes, and FAQs.

Help us improve this guide

Tell us about an outdated instruction, unclear step, broken link or safety concern. Do not include passwords, account numbers, medical records or other sensitive information.

Email a correction or suggestion