How to Recognize and Avoid a Phishing Email
A phishing email is a fake message designed to look like it’s from a real company — your bank, PayPal, Amazon, or even the IRS — that tries to trick you into clicking a link and entering your password or personal information on a fake website. The safest response is to never click the link in the email itself, and instead go directly to the company’s real website or app by typing the address yourself or using an app you already trust. The signs below help you catch these before you ever click.
Signs an email is phishing
- It creates urgency: “Your account will be suspended,” “Unusual activity detected,” or “Action required within 24 hours”
- It asks you to click a link and “verify,” “confirm,” or “update” your account information
- The sender’s email address doesn’t quite match the real company (for example, “amazon-support123@mail.ru” instead of an official amazon.com address)
- The greeting is generic, like “Dear Customer,” instead of using your actual name
- There are small spelling or grammar mistakes, or the logo and formatting look slightly off
- It asks you to open an unexpected attachment, especially a .zip file or one you weren’t expecting
Real companies rarely ask you to “verify your account” by clicking a link in an unexpected email. If you’re ever unsure, don’t click anything — log in the way you normally would, directly through the company’s app or by typing their website address yourself.
Step 1: Don’t click any links or attachments
Even if the email looks convincing, the safest first move is to leave everything in it untouched. Clicking a link can take you to a fake login page designed to steal your password, and opening an attachment can install unwanted software.
Step 2: Check the sender’s actual email address
- Look at the sender’s full email address, not just the display name (which can be faked to say anything).
- On most phones and computers, tapping or hovering over the sender’s name reveals the real address underneath.
- Compare it closely to the company’s real domain — watch for extra words, misspellings, or a completely different domain after the “@” symbol.
Step 3: Check the link without clicking it
- On a computer, hover your mouse over the link (without clicking) to see the actual web address in the bottom corner of your screen.
- On a phone, press and hold the link briefly to preview the address before it opens.
- If the address doesn’t match the company’s real website, it’s not legitimate.
Step 4: Verify directly through the real company instead
- Open a new browser tab or the company’s official app.
- Type the company’s website address yourself, or use a bookmark you’ve saved previously — never a link from the email.
- Log in normally and check your account for any real alerts or messages, which will also appear there if something genuinely needs attention.
Step 5: Report and delete the email
- Look for a Report phishing or Report spam option in your email app, usually under a three-dot menu next to the message.
- Most email providers use these reports to improve filtering for everyone, not just you.
- Delete the email once reported.
What to do if you already clicked the link
Don’t panic, but act promptly:
- If you entered a password: change that password immediately, and change it on any other account where you reused it.
- If you entered payment card information: contact your card issuer right away to review recent charges and consider requesting a new card number.
- If you opened an attachment: run a scan with your device’s built-in security software (see the “Run a scan” step in our article on pop-up ads and viruses) as a precaution.
Frequently asked questions
How can I tell a fake link from a real one without clicking it?
Hover over the link on a computer, or press and hold it briefly on a phone, to preview the actual web address before it opens. If it doesn't match the real company's website, don't click it.
What if the email mentions a company or bank I actually use?
Scammers intentionally target common banks and services to increase the odds it matches something you actually use. Still avoid the link — log in directly through the company's real app or website instead.
Is it safe to open the email itself, just not the link?
Generally yes, simply opening and reading a suspicious email is safe. The risk comes from clicking links or opening attachments inside it.
Can a phishing email infect my device just by receiving it?
No, receiving the email alone doesn't put your device at risk. The danger comes from clicking a link or opening an attachment within it.
What's the difference between phishing and a fake delivery text?
They use the same tactics — urgency and a fake link — just through different channels. See our article on spotting a fake delivery text or email for the text-message version of this same scam.