Modern phishing emails rarely have the obvious typos and broken formatting of a decade ago — many are polished enough to pass a casual glance. The good news is that a handful of specific checks catch the overwhelming majority of them, and they take less time to run than it takes to read this sentence twice.

Advertisement

1. Check the actual sender address, not just the display name

Email clients show a friendly display name ("PayPal Support") that the sender controls completely and that has no relationship to the actual sending address. Tap or hover on the sender name to reveal the real email address underneath. A message claiming to be from your bank sent from a Gmail address, or from a domain that's almost-but-not-quite right (like "paypa1.com" or "amazon-security.net" instead of "amazon.com"), is the single most reliable tell.

2. Hover before you click — check where the link actually goes

The visible text of a link ("Verify your account") can say anything regardless of where it actually points. On desktop, hovering over a link (without clicking) shows the real destination URL, usually in the bottom corner of the browser or email client. On mobile, a long-press typically shows a preview of the URL before opening it. Look specifically at the domain right before the first single slash — that's what actually matters, not subdomains or path text stuffed with a familiar brand name to look convincing.

3. Notice manufactured urgency

"Your account will be suspended in 24 hours," "Unusual sign-in detected — verify now," "Payment failed — update your card immediately." Urgency is a deliberate tactic: it's designed to make you act before you think carefully. Legitimate account or security issues from real companies practically never require you to click an emailed link within a strict deadline — you can always navigate to the company's site directly and check your account status there instead.

Advertisement

4. Be suspicious of unexpected attachments, especially with unusual file extensions

An invoice, shipping label, or "voicemail" attachment you weren't expecting — particularly a .zip, .exe, .js, or a Word/Excel file prompting you to "enable macros" — is a very common malware delivery method. Legitimate invoices and shipping confirmations from services you actually use typically don't require enabling macros to view.

5. Check for a generic greeting on a message that claims to know you

"Dear Customer" or "Dear User" from a company that supposedly has your account details, order history, or personal information is a mismatch worth noticing — real account-related emails from services you use typically address you by name, because they actually have that information on file.

What to do if you're still not sure

The fastest single check: Hover over the sender's name to reveal the actual email address. A mismatched or unfamiliar domain is, by itself, enough reason to stop and verify independently before doing anything else in the email.

This guide covers common patterns as of 2026; phishing techniques evolve, so treat this as a starting checklist rather than an exhaustive one. See our Disclaimer.