How to spot a phishing email
A phishing email pretends to be someone you trust so you will click a link, open a file, or hand over a password. The good ones look real. The trick is not to judge how polished it is, but to check a few specific things that a scammer cannot easily fake.
1. Look at the actual sending address, not the display name
The name at the top of an email is just a label. Anyone can set it to "IT Helpdesk" or "PayPal". What matters is the address it was really sent from.
Tap or hover on the sender to see the true address. A look-alike (paypal-secure-login.com) or a free inbox (paypalsupport@gmail.com) sending you "PayPal" business is a forgery, and once the address is fake you can treat everything else in the email as a story.
Do not expect the domain to always match the brand exactly, though. Real companies send from subdomains (email.paypal.com), from a parent company (ChatGPT's email comes from openai.com), or through a mailing service on their behalf. So the question is not "does this match the brand name?" but "is this the address I would expect from this sender?" A domain you did not expect is a reason to slow down and check another way. It is not proof of a scam, and a familiar-looking one is not proof of safety.
2. Notice when it rushes you
"Your account will be closed in 24 hours." "Confirm now to avoid a fee." Manufactured urgency is the single most common ingredient in a scam, because pressure makes people skip the checks they would normally do.
A real company is happy to wait while you verify. If a message is pushing you to act right now, that pressure is the red flag, not the deadline.
3. Do not trust a link because the page looks right
Scammers copy real sign-in pages closely enough that you cannot tell by looking. "It looks legitimate" proves nothing, because the fake is a copy of the legitimate one. The trap is the link itself, not the page it opens.
Never sign in through a link in a message. If an email says there is a problem with your account, open the app yourself or type the website address in by hand, and check there.
4. Be wary of unexpected attachments
An invoice you were not expecting, a "voicemail" as a file, a shared document from someone you do not deal with. Attachments are a common way malware gets in.
If you did not expect the file, confirm with the sender through a channel you already trust before you open it.
5. Watch for a generic greeting or a slightly-off tone
"Dear Customer" or "Dear User" often means the message was blasted to thousands of people who could not be named. But flip it too: a message that does use your name is not automatically safe, because targeted scams look you up first.
Judge the request, not the greeting. Odd phrasing, a signature that does not match, or a colleague suddenly writing in a way they never would are all worth a second look.
6. Question any request for money, gift cards, or a password
The whole point of most phishing is to get one of three things: a payment sent somewhere new, gift-card codes, or your login. No legitimate manager needs you to buy gift cards and send the codes. No bank asks for your password by email.
When the ask itself is unusual, verify with the person or company directly, on a number or address you already have, before you do anything.
7. When something feels off, report it
You do not need to be certain. If a message rings false, forward it to your IT or security team (or, at home, delete it and contact the company directly on a number you trust). Reporting one real phish can protect everyone else who got the same one.
The skill worth building is not reporting every email, it is telling a genuine message from a forged one, so the alarms you do raise are worth answering.
The short version
- Check the real sending address, not the display name, and ask whether it is the one you would expect from that sender.
- Urgency is a pressure tactic, not a reason to hurry.
- Never sign in through a link in a message. Go to the site yourself.
- Unusual money, gift-card, or password requests get verified on a channel you already trust.
Build the reflex, not just the knowledge.
BadgerQuest is a two-minute daily game that keeps this instinct sharp. Free for individuals, no card.
Play a round free →Training a team instead? See pricing · Phishing training for a small team
Common questions
What is the most common sign of a phishing email?
Manufactured urgency. A threat or a countdown ("act within 24 hours or your account is closed") is designed to make you act before you check. A real organization is fine with you taking a moment to verify.
Is it safe to open a phishing email?
Opening an email to read it is generally safe on a modern, updated mail app. The danger is what you do next: clicking a link, opening an attachment, or entering a password. If you suspect phishing, do none of those, and report it.
What should I do if I already clicked a phishing link?
If you entered a password, change it immediately (and anywhere you reused it), turn on multi-factor authentication, and tell your IT or security team right away. Speed limits the damage.