Quick Answer: How to Spot Phishing Emails
Phishing emails almost always show multiple red flags at once. The most reliable signal is a mismatch between the claimed sender and the actual sender domain, but phishing emails also share a small set of recurring patterns: urgency, generic greetings, suspicious links, credential requests, and emotional pressure. The fastest spot-check is to hover over any link without clicking, confirm the actual URL matches the visible anchor text, and pause any email that creates time pressure. Verifying through an out-of-band channel (call the sender at a number you already trust) is the single most effective defense against phishing.
Why Phishing Still Works in 2026
Phishing remains the most common initial-access technique for cybercrime. According to the Verizon 2025 Data Breach Investigations Report, phishing was present in roughly 36% of analyzed breaches, and business email compromise (BEC) losses exceeded $2.9 billion in 2024 per FBI IC3 data. Despite better email filters and two-factor authentication, phishing succeeds because it targets people, not technology — and people respond to urgency, authority, and fear.
The good news: phishing has consistent patterns. Once you learn to read those patterns, the vast majority of phishing emails become obvious.
The 15 Red Flags of Phishing Emails
- Mismatched sender domain. The display name says "PayPal Support" but the actual email address is [email protected] or [email protected]. Always check the full address, not just the display name.
- Generic greeting. "Dear Customer" or "Dear User" instead of your name. Legitimate companies that have an account relationship use your name.
- Urgency or threat. "Your account will be closed in 24 hours" or "Failure to verify will result in suspension." Urgency is the most common manipulation tactic — it is also the easiest to defend against by simply pausing.
- Suspicious links. Hover over (or long-press on mobile) to see the actual URL before clicking. If the link text says chase.com but the URL goes elsewhere, it is phishing.
- Credential or payment request. Any email asking you to verify your password, enter a payment card, or confirm a wire transfer is highly suspect. Legitimate companies do not request sensitive information by email.
- Unexpected attachments. Invoices, shipping notices, or resumes you did not request, especially in formats that can run macros (XLS, DOC, HTA). Modern phishing uses HTML smuggling and password-protected ZIPs to bypass filters.
- Emotional manipulation. Phishing preys on fear ("we detected fraud on your account"), curiosity ("see who viewed your profile"), reward ("you have won $500"), or curiosity about bad news.
- Spelling and grammar errors. Modern phishing is often well-written, but errors in context (American spelling in a British bank's email, mid-paragraph language switches) are still common tells.
- Unusual request from a known contact. Your "CEO" emailing you from a personal Gmail asking for gift cards is the textbook BEC pattern. Verify by calling the person at a number you already trust.
- Display-name spoofing. The sender name says your bank but the underlying address is something else. Attackers know people rarely check the actual address.
- Reply-to mismatch. The From address is legitimate-looking but the Reply-To address routes to an attacker-controlled mailbox.
- Embedded images that hide content. Phishing emails increasingly embed the entire body as a single image to evade text-based filters. Hovering reveals nothing; check the sender domain instead.
- Mismatched branding. The company logo looks slightly off, the email design does not match the real company's templates, or the footer contains broken links.
- First-time or infrequent sender. An email from a company you have never interacted with claiming a problem with an account you do not have.
- Links to login pages at unexpected domains. A "login" link that goes to a URL containing the brand name plus a hyphen or extra word (chase-secure-login.com instead of chase.com) is phishing.
Common Phishing Patterns in 2026
| Pattern | Example Subject Line | Red Flag Combination |
|---|---|---|
| Bank account suspension | "URGENT: Your account has been limited" | Urgency + credential request + mismatched sender |
| Package delivery failure | "FedEx: Delivery attempted, action required" | Unexpected attachment + suspicious link + urgency |
| HR/payroll update | "Action required: Verify direct deposit info" | Internal urgency + credential request + unusual timing |
| Microsoft 365 / Google Workspace | "Your password expires in 24 hours" | Urgency + credential request + branded but spoofed domain |
| CEO gift card request | "Quick favor - can you help me out?" | Authority + reply-to mismatch + urgency + emotional manipulation |
| Tax refund / IRS | "Your tax refund of $1,247 is pending" | Reward + credential request + mismatched sender domain |
| DocuSign / e-signature | "Document awaiting your signature" | Unexpected action + HTML smuggling + link to phishing portal |
What To Do If You Clicked a Phishing Link
If you clicked a phishing link or entered credentials on a phishing page, take these steps in order:
- Disconnect from the network immediately if you downloaded anything. Power off Wi-Fi or pull the network cable.
- Change passwords for the affected account from a different device. Use a known-good URL (type it manually, not from the email).
- Enable two-factor authentication on the affected account if not already enabled. Prefer hardware keys or authenticator apps over SMS.
- Run an anti-malware scan with a reputable tool (Malwarebytes, Windows Defender full scan, or vendor-recommended scanner for your OS).
- Audit other accounts that share the compromised password. Attackers test stolen credentials across dozens of services within minutes.
- Watch your financial statements for unauthorized transactions, especially small test charges under $5.
- Place a fraud alert with one of the three US credit bureaus (Equifax, Experian, TransUnion) if financial or SSN data was exposed.
- Report the phishing email — see the FAQ below for the right address.
How to Report a Phishing Email
Three reporting paths to use in parallel:
- Anti-Phishing Working Group: forward to [email protected] (industry-wide collector).
- FTC (US): forward to [email protected] and report at IdentityTheft.gov if you lost money or personal data.
- Impersonated company: forward to the impersonated company's abuse address — most large companies publish one (e.g., [email protected], [email protected]).
Then delete the email from your inbox.
For broader defensive habits, see our 25 cybersecurity tips to protect your data, and our home network security guide. To learn the analyst-side detection skills that catch what filters miss, the TutorsBot Cyber Security Analyst Foundation course covers phishing analysis, email forensics, and incident triage.






