Picture the email that lands at 4:55 on a Friday. Subject line: “Your account will be suspended.” The logo looks right, the tone is stern, and there is a big blue button begging to be clicked. Your weekend is minutes away and your finger hovers.

That is the exact moment phishing is designed for. The people who write these emails are not hoping you read carefully; they are betting you will not. Learn the clues they hope you miss, and that Friday email becomes a two-second delete instead of a stolen password.

Key takeaways

a magnifying glass over an email sender address
The real sender address, not the friendly display name, exposes most fakes.
  • The real sender address, not the display name, reveals most fakes in seconds.
  • Urgency and threats are engineered to stop you from checking; treat them as red flags, not reasons to hurry.
  • Hover over links to preview the true destination before you ever click.
  • When in doubt, go to the website or app yourself instead of using anything in the email.

Check the sender, not the name

The display name on an email is just a label anyone can type. A message can say “PayPal Security” while the actual address is something like [email protected]. That is where the truth hides.

Tap or click the sender name to expand the full email address. Real companies send from their own domain, like [email protected], not from a random string of characters or a public Gmail account. Watch for lookalike tricks too: amazon-support.com and arnazon.com are not Amazon.

A mistake I see constantly is people trusting the logo and greeting while never glancing at the address bar of the sender. The logo is a picture that took ten seconds to copy. The domain is the part scammers cannot fake perfectly.

Read the greeting and the grammar

Legitimate companies usually know your name because you have an account with them. A message that opens with “Dear Customer” or “Dear user” is a small but telling sign, especially from a business that should address you directly.

Odd phrasing, missing words, and clumsy grammar also leak through. Some of this is deliberate, believe it or not. Sloppy wording filters out cautious readers early, leaving scammers with the people most likely to follow through.

Good to know

Grammar alone is no longer a reliable test. Scammers now use the same writing tools everyone else does, so plenty of phishing emails read perfectly. Use the greeting and grammar as supporting clues, but never as your only check.

Hover before you click

The link text you see and the place a link actually goes can be two completely different things. “Verify your account” might point to a web address that has nothing to do with the real company.

On a computer, hover your mouse over any link without clicking, and the true destination appears in the bottom corner of your window. On a phone, press and hold the link to preview it in a pop-up. If the address looks nothing like the company’s real website, do not go there.

The important part of a web address is the piece right before the first single slash. In shop.example.com/orders, the real site is example.com. Scammers pad addresses with trusted-sounding words, so amazon.security-check.ru is owned by security-check.ru, not Amazon. Read from the right to find the true owner.

Watch out

Never open attachments you did not expect, even from names you recognize. A surprise invoice, resume, or “receipt” as a PDF, ZIP, or Word file can carry malware. If you are not sure, contact the sender through a separate channel before opening anything.

Spot the emotional bait

Phishing runs on feelings, not facts. Once you learn the emotional triggers, the manipulation gets almost comically obvious.

The bait How it reads The reality
Fear “Suspicious login, verify now or lose access” Real alerts let you check safely in the app
Urgency “You have 24 hours before permanent closure” Legitimate deadlines are not measured in panic
Greed “You have a refund of 79.99 waiting” Refunds appear in your account, not via a link
Curiosity “See who viewed your profile” Designed purely to earn a click

Any email pushing hard on one of these deserves extra suspicion. The stronger the emotional shove, the more likely someone is trying to skip past your judgment.

The safe move when you are unsure

Sometimes an email might be real. Your bank does occasionally email you. Here is how to check without taking any risk.

Do not click the email’s link or call its number. Instead, open a new tab and type the website address yourself, or open the company’s official app. If there is a genuine issue, it will be waiting for you there. If nothing shows up, the email was a fake.

This habit costs you thirty seconds and neutralizes the entire attack. The scam depends on you using its button. Refuse to, and it collapses. This same principle anchors our wider primer on how to spot scams and phishing as a beginner, because it works across every channel.

Tip

Set up a personal rule: any email asking you to log in, pay, or confirm details gets verified by going to the source directly. Make it automatic and you remove the guesswork on stressful days.

Report it and move on

Deleting a phishing email protects you, but reporting it protects everyone else too. Most email apps have a “Report phishing” or “Report junk” option in the menu beside the message, and using it trains your provider’s filters.

You can also forward phishing emails to the Anti-Phishing Working Group at [email protected], a group that tracks these campaigns. For a fuller walkthrough of where to send different scams, see our guide on how to report phishing and scams the right way.

Email is not the only inbox scammers hit. The same tricks show up in your messages app, often even faster, which is why our piece on recognizing scam texts and smishing is a worthwhile companion read. The tactics rhyme across both.

Microsoft, Google, and Apple all publish clear help pages on reporting phishing from within their apps; Google’s version lives at support.google.com if you use Gmail.

Your afternoon checklist

  • Practice expanding the full sender address on your last few emails so the habit sticks.
  • Learn to hover on desktop and long-press on mobile to preview a link’s real destination.
  • Adopt the rule: never log in or pay through a link in an unexpected email.
  • Turn on two-factor authentication for your email so a stolen password is not enough.
  • Find the “Report phishing” button in your email app so you know where it is.
  • Save [email protected] as a contact for forwarding suspicious messages.
  • Tell one friend the read-the-domain-from-the-right trick this week.

Phishing emails are common, but they are also predictable once you know the tells. Slow down for the ones that try to rush you, check the sender and the link, and you turn a genuine threat into background noise you clear without a second thought.