allglossary.xyz
← Blog

How to spot a phishing email

A step-by-step check for suspicious emails, what to do if you already clicked, and why reporting fast matters more than never being fooled.

Phishing is a fake message designed to make you do something unsafe: type your password into a fake page, open a harmful file, or pay a fake invoice. It's one of the most common ways attacks begin, because it goes after people rather than software. Fooling one busy person is easier than breaking into a well-run server.

Good phishing fools experienced people too. The aim isn't to become impossible to trick. It's to build a habit of pausing, checking a few things, and reporting anything odd.

The 30-second check

When an email asks you to act, run through these five questions before you click anything.

1. Is it rushing you or scaring you?

"Your account will be closed today." "Payment failed: update now." "The CEO needs this before the meeting." Urgency and fear are the core of social engineering, because a hurried person skips the checks. A real bank or employer can wait ten minutes while you check.

2. Who actually sent it?

The display name can say anything, so look at the actual address. Watch for lookalike domain names: a letter swapped, an extra word, or a different ending, such as "paypa1.com", "microsoft-support-team.com", or "yourcompany.co" instead of "yourcompany.com". A real company's email doesn't come from a free webmail address.

3. Where does the link really go?

Before clicking, hover over the link on a computer, or press and hold it on a phone, to see the real URL. Find the first "/" after "https://", then read the domain name just before it from the right. In "https://login.example.com.evil.net/reset", the domain ends in evil.net, so that's the site you'd land on, however familiar the start looks.

A padlock or HTTPS proves nothing here. It only means the connection is encrypted, and phishing sites have padlocks too.

4. Is it asking for something unusual?

Real services don't ask for your password by email. Be wary of anything that asks you to sign in through a link, confirm card details, buy gift cards, change bank details for a supplier, or approve a sign-in you didn't start. Requests that skip normal process ("keep this between us", "don't call, I'm in meetings") are a warning sign by themselves.

5. Does the attachment make sense?

Unexpected attachments are a common way to deliver malware. Be especially careful with files that ask you to "enable content" or "enable macros", compressed archives you didn't expect, and anything that wants you to sign in to view a document.

Check another way

If a message might be real, don't use anything in it to check. Open the website by typing its address yourself, or use the app you already have. Call the person on a number you already know, not the one in the email. A real request survives this. A fake one falls apart.

If you already clicked

It happens to careful people. What matters now is speed.

  • If you typed a password, change it straight away on the real site, along with any other account that uses the same password.
  • Turn on multi-factor authentication if it isn't on already. It means a stolen password alone usually isn't enough to get in.
  • If you opened a file, disconnect from the network if you can, and contact your IT team.
  • If you entered card details, call your bank on the number printed on your card and ask them to block it.
  • Report it at once, even if you feel silly. At work, that starts incident response: the team can block the sender, find everyone else who got the same email, and reset accounts before anything spreads.

Report it even if you didn't click

Most phishing is sent to many people at once. When you report a message, the security team can pull it from everyone else's inbox before someone less careful clicks. Many email apps have a "Report phishing" button, and workplaces usually have a reporting address.

This is the real point of security awareness training: not shaming people who get fooled, but making reporting fast and normal. An organization where people report a mistake within five minutes is far safer than one where people hide mistakes for fear of blame.

Habits that do most of the work

  • Use a password manager. It fills in your password only on the real site, so a lookalike page gets nothing. That makes it one of the best phishing defenses there is.
  • Turn on MFA everywhere, preferably with an app or a security key rather than text messages.
  • Slow down on anything urgent. The more a message pushes you to act now, the more reason to check first.
  • Keep software updated, so a harmful attachment has fewer weaknesses to use.

Phishing works by making you act before you think. Every check above has the same purpose: to buy back those few seconds.