
Quick answer: To spot a phishing email, check the sender's full email address (not just the display name), hover over links to verify the actual URL before clicking, watch for urgent or threatening language, and be suspicious of unexpected requests for credentials or payment. No single sign is definitive — sophisticated phishing emails can appear legitimate, so when in doubt, navigate directly to the organization's website rather than clicking links in the email.
"It Looked Completely Legitimate" — Why Phishing Emails Are Harder to Spot Than They Used to Be
The image of a phishing email as an obviously fake message full of spelling errors and implausible claims is increasingly outdated. While low-quality phishing still exists, many phishing campaigns today use professionally designed emails that closely mimic the branding, tone, and formatting of the organizations they impersonate. Some use personal information gathered from social media or data breaches to make the message appear relevant to the specific recipient. The challenge for recipients is that the visual appearance of an email — how it looks — is not a reliable indicator of whether it is legitimate. The indicators that matter are structural: the sender's actual email address, the actual destination of links, and the nature of what is being requested. This guide covers how to spot a phishing email — the key warning signs, how to inspect sender addresses and links, what spear phishing looks like, and what to do if a phishing link was clicked. Phishing techniques evolve continuously; the indicators described here reflect current common patterns as of mid-2026, but new variants emerge regularly.

Phishing Email Warning Signs — Quick Reference
Warning SignWhat to Look ForWhy It MattersSender address mismatchDisplay name says "PayPal" but address is random@gmail.comDisplay names can be set to anything — the address is what mattersLookalike domainpaypa1.com, paypal.com.verify-account.netAttackers register domains that look like the real oneUrgent / threatening language"Your account will be suspended in 24 hours"Urgency bypasses careful thinking — a deliberate tacticUnexpected credential or payment requestEmail asks to verify login, confirm card details, or pay an invoiceLegitimate services rarely request credentials via emailSuspicious attachment.exe, .zip, or Office file prompting to enable macrosAttachments can deliver malware without clicking a link
1. Check the Sender's Full Email Address
The display name of an email — the name shown in the From field — can be set to anything by the sender. An email can display "PayPal Security Team" as the sender name while the actual sending address is a completely unrelated address. The actual email address is the reliable indicator. To see the full sending address in Gmail: click the sender's name in the From field to expand it and see the full address. In Outlook: hover over the sender's name or click it to see the full address. The domain of the sending address should match the official domain of the organization — an email claiming to be from a bank should come from that bank's official domain, not a free email service or an unrelated domain. Lookalike domains are a common technique: attackers register domains that closely resemble the official domain — substituting characters (paypa1.com instead of paypal.com), adding words (paypal-security.com), or using a subdomain structure that places the familiar name in a non-authoritative position (paypal.com.verify-account.net — the actual domain here is verify-account.net, not paypal.com). Reading the domain carefully from right to left (the top-level domain and the domain name immediately to its left are the authoritative parts) helps identify these lookalike domains.
2. Inspect Links Before Clicking
On desktop, hovering over a link with the mouse cursor shows the actual destination URL in the browser's status bar or a tooltip — before clicking. The displayed link text and the actual URL can be completely different. Check the domain in the URL using the same approach as for sender addresses: read from right to left to identify the actual domain. A URL such as https://paypal.com.account-verify.net/login leads to account-verify.net, not paypal.com. On mobile, pressing and holding a link typically shows the URL before opening it. If the URL is shortened (bit.ly, t.co, or similar), it is not possible to see the destination without clicking — in this case, using a URL expander tool or navigating directly to the organization's website is safer. When in doubt about a link in an email, the safest approach is to navigate directly to the organization's website by typing the URL in the browser, rather than clicking the link. If the email claims there is an issue with an account, logging in directly through the official website will show any genuine alerts or notifications. Legitimate organizations do not require recipients to click a specific link in an email to resolve account issues — they can always be accessed directly through the official website.
3. Recognize Urgency and Authority Tactics
Phishing emails frequently use urgency and authority to pressure recipients into acting quickly without careful consideration. Common urgency tactics include: account suspension threats ("Your account will be closed in 24 hours unless you verify your information"), security alerts ("Unusual sign-in activity detected — verify your identity immediately"), and time-limited offers or penalties. Authority tactics involve impersonating organizations that carry inherent authority — banks, government agencies (IRS, HMRC, Social Security Administration), law enforcement, or senior executives within an organization. The psychological mechanism is the same: create a sense of urgency or authority that prompts the recipient to act before thinking critically. Recognizing this pattern — and deliberately slowing down when an email creates a sense of urgency — is one of the most effective defenses against phishing.
4. Be Cautious of Unexpected Attachments
Phishing emails sometimes deliver malware through attachments rather than links. Common attachment-based attack vectors include: executable files (.exe, .bat, .msi) that install malware when opened; Office documents (.docx, .xlsx) that prompt the recipient to "Enable Macros" or "Enable Editing" — macros can execute malicious code; PDF files with embedded malicious links or scripts; and compressed archives (.zip, .rar) containing malicious executables. The general guidance is to be cautious of unexpected attachments, particularly from senders who do not normally send attachments, and to never enable macros in Office documents received via email unless the source is verified and the need is understood. Modern versions of Microsoft Office open documents from email in Protected View by default, which disables macros — this is a deliberate security feature and should not be bypassed without a clear reason.
5. Understand Spear Phishing and Business Email Compromise
⚠️ Spear phishing is significantly harder to detect than generic phishing — and causes disproportionate harm: Spear phishing uses personal information about the recipient to craft a targeted, convincing message. The attacker may know the recipient's name, employer, role, manager's name, or recent activities — information gathered from LinkedIn, company websites, social media, or data breaches. A spear phishing email might appear to come from a colleague, a vendor, or a senior executive, and may reference a real project or relationship. Business email compromise (BEC) is a form of spear phishing where attackers impersonate executives or vendors to request wire transfers, gift card purchases, or sensitive data. BEC attacks have caused substantial financial losses globally — the FBI's IC3 reports BEC as one of the costliest cybercrime categories. For any unexpected request involving financial transactions or sensitive data, verifying through a separate communication channel (a phone call to a known number, not a number provided in the email) before acting is strongly recommended.
Step-by-Step: What to Do When You Receive a Suspicious Email
Step 1: Do Not Click Links or Open Attachments
If an email appears suspicious, do not click any links or open any attachments before verifying its legitimacy. The risk of clicking a link or opening an attachment in a phishing email includes credential theft (if a fake login page is loaded), malware installation (if a malicious file is opened), and drive-by downloads (malicious code that executes when a page is loaded, without any further action). When in doubt, treat the email as suspicious until verified.
Step 2: Inspect the Sender Address and Links
Check the full sending email address (not just the display name) and verify it matches the official domain of the organization. Hover over any links to see the actual destination URL and verify the domain. If the sender address or link destination does not match the official domain, the email is likely phishing. If the email claims to be from a service, navigate directly to that service's official website to check for any genuine alerts or notifications.
Step 3: Verify Through a Separate Channel if Uncertain
For emails requesting action — particularly those involving financial transactions, credential verification, or sensitive data — verify the request through a separate communication channel before acting. For a request apparently from a bank, call the bank's official number (from the bank's official website, not a number in the email). For a request apparently from a colleague or executive, call or message them directly using a known contact method. This step is particularly important for BEC-style requests involving wire transfers or unusual financial requests.
Step 4: Report the Phishing Email
Report phishing emails to the email provider and to relevant authorities. In Gmail: open the email, click the three-dot menu, and select "Report phishing". In Outlook: select the email, click "Report" in the toolbar, and select "Report phishing". Forward phishing emails to reportphishing@apwg.org (the Anti-Phishing Working Group). Report phishing to the FTC at ftc.gov/complaint. If the phishing email impersonates a specific organization, reporting it to that organization's abuse or security team (typically abuse@[domain] or security@[domain]) helps them take action against the phishing campaign.
Step 5: If a Phishing Link Was Clicked, Act Quickly
If a phishing link was clicked and credentials were entered: change the password for the affected account immediately and enable 2FA if not already active. Change the password on any other accounts using the same password. If financial information was entered, contact the relevant financial institution. Run a malware scan on the device. Monitor the affected accounts for unauthorized activity. If a file was downloaded and opened, consider having the device examined by a security professional, as some malware is designed to persist and evade detection.
Frequently Asked Questions — How to Spot a Phishing Email
How do I spot a phishing email?
Check the sender's full email address (not just the display name), hover over links to verify the actual URL, watch for urgent or threatening language, and be suspicious of unexpected requests for credentials or payment. When in doubt, navigate directly to the organization's website rather than clicking links in the email.
What is a phishing email?
A phishing email is a fraudulent message designed to trick the recipient into revealing credentials, clicking a malicious link, or opening a malicious attachment. Phishing emails typically impersonate trusted organizations — banks, email providers, government agencies — to appear legitimate. Spear phishing is a targeted variant that uses personal information to make the message more convincing.
How do I check if a link in an email is safe?
Hover over the link (desktop) or press and hold (mobile) to see the actual URL before clicking. Read the domain from right to left to identify the authoritative domain. If uncertain, navigate directly to the organization's website by typing the URL rather than clicking the link. Free tools such as Google Safe Browsing can also check suspicious URLs.
What is spear phishing?
Spear phishing is targeted phishing that uses personal information about the recipient — name, employer, role, colleagues — to craft a convincing, personalized message. Business email compromise (BEC), where attackers impersonate executives or vendors to request wire transfers or sensitive data, is a form of spear phishing. Verify unexpected financial or sensitive data requests through a separate communication channel.
What should I do if I clicked a phishing link?
Do not enter any information on the page. If credentials were entered, change the password immediately and enable 2FA. Change passwords on other accounts using the same password. If financial information was entered, contact the financial institution. Run a malware scan. Report the phishing email to the provider and to the FTC at ftc.gov/complaint.
Conclusion & My Take
Spotting a phishing email reliably requires focusing on the structural indicators — the actual sending address, the actual link destination, and the nature of what is being requested — rather than the visual appearance of the email. Sophisticated phishing emails can look identical to legitimate communications from the organizations they impersonate. The habit of checking the full sender address and hovering over links before clicking takes a few seconds and catches the majority of phishing attempts. For spear phishing and BEC attacks, where the email may appear to come from a known contact and reference real context, the most reliable defense is verification through a separate channel for any unexpected request involving financial transactions or sensitive data. No email-based indicator is sufficient to verify the legitimacy of a high-stakes request — a phone call to a known number is the appropriate verification method. Reporting phishing emails — to the email provider, to the APWG, and to the FTC — contributes to broader efforts to identify and disrupt phishing campaigns. It takes a few seconds and helps protect other potential recipients of the same campaign.
Sources
FTC Consumer Advice — How to Recognize and Avoid Phishing Scams — ftc.gov
CISA — Phishing Guidance: Stopping the Attack Cycle at Phase One — cisa.gov
FBI IC3 — 2023 Internet Crime Report (BEC statistics) — ic3.gov
APWG — Phishing Activity Trends Reports — apwg.org
Google — Avoid and report phishing emails — support.google.com









