Reviewed by the Foxmole editorial team · 2026-07-29
- Key takeaways
- 1. It pushes urgency or fear
- 2. The sender address doesn’t match the brand
- 3. Links don’t go where they claim
- 4. It asks for credentials, codes, or payment details
- 5. Generic greeting where a real one is expected
- 6. Small errors that a real brand wouldn’t ship
- 7. Unexpected attachments
- 8. The channel is unusual
- What to do instead of clicking
- A browser layer catches some of these before you do
Key takeaways
- The one rule: never act from the message, go to the site yourself.
- Urgency plus a link is the most common tell.
- No real bank or service asks for your password or codes by email.
Phishing was the most-reported cybercrime in the FBI’s 2024 IC3 data (193,407 complaints), so the odds you’ll be targeted are real. The good news: most attempts share the same tells. Learn these eight and you’ll catch the large majority.
1. It pushes urgency or fear
“Your account will be suspended in 24 hours.” Pressure is designed to make you act before you think. Legitimate organizations rarely threaten immediate consequences over email.
2. The sender address doesn’t match the brand
Look at the actual email address, not the display name. [email protected] is not PayPal. On mobile, tap the sender name to reveal the real address.
3. Links don’t go where they claim
Hover over a link (or long-press on mobile) to preview the real destination. If the visible text says one thing and the URL says another, don’t click.
4. It asks for credentials, codes, or payment details
No legitimate bank, tax authority, or major service will ask you to confirm your password or a one-time code by email or text. That request itself is the red flag.
5. Generic greeting where a real one is expected
“Dear Customer” from a service that knows your name can be a sign, though skilled attackers now personalize, so treat this as supporting evidence, not proof.
6. Small errors that a real brand wouldn’t ship
Odd grammar, off-brand logos, or slightly wrong colors. AI has made phishing text cleaner than it used to be, so this tell is weaker than before, but obvious errors still count.
7. Unexpected attachments
Invoices, “delivery” files, or documents you didn’t request. Don’t open them; verify with the supposed sender through a channel you already trust.
8. The channel is unusual
A “bank” texting you a link, a “colleague” DMing you a gift-card request. Match the message to how that person or company normally contacts you.
What to do instead of clicking
- Navigate to the site yourself using a bookmark or by typing the address.
- Contact the company through a number or app you already have.
- Report the message (most email apps have a “report phishing” option) and delete it.
- If you already clicked and entered details: change that password immediately, turn on two-factor authentication, and change it anywhere you reused it.
A browser layer catches some of these before you do
A reputation-checking extension can flag a known phishing or lookalike site as the page loads, a useful backstop for the moments you’re tired or rushed. See our guide on browser security extensions.
Source
- FBI IC3 2024 Internet Crime Report, fbi.gov