Any · Security

Spot a phishing email before you click

Modern phishing has no spelling mistakes and copies the real branding pixel for pixel. You beat it on process, not on how convincing the message looks.

  • Difficulty Easy
  • Estimated time 10 min
  • Platform Any
  • Last updated
Spot a phishing email before you click — schematic diagram

Before you start

Low risk. This change is reversible — you can return to the previous state without professional help or data loss.

Steps

  1. Read the sender's actual domain rather than the display name — 'Microsoft Support <billing@micros0ft-secure.com>' is the entire tell
  2. Hover a link (long-press on a phone) and read where it truly goes before you click. On mobile that's the only reliable check you have
  3. Treat urgency as the alarm bell: 'account closing in 24 hours', 'unusual sign-in detected', 'payment failed' all exist to stop you thinking
  4. Never act from inside the message. Open a new tab, type the company's address yourself, and check your account there — if it's genuine, the notice will be waiting
  5. Unexpected attachment? Don't open it. .zip, .html and macro-enabled Office documents are the usual carriers

How to verify the fix

You can read the sender's real domain, hover-check a link's destination, and verify notices by typing the address yourself.

If this didn't fix it

You're unsure whether an email is genuine — don't act from inside it; open a new tab, type the site yourself, and check there.

Next stop: the related fixes below, or start a guided diagnosis.