Reviewed by the Foxmole editorial team · 2026-07-29

Key takeaways

  • The one rule: never act from the message, go to the site yourself.
  • Urgency plus a link is the most common tell.
  • No real bank or service asks for your password or codes by email.

Phishing was the most-reported cybercrime in the FBI’s 2024 IC3 data (193,407 complaints), so the odds you’ll be targeted are real. The good news: most attempts share the same tells. Learn these eight and you’ll catch the large majority.

1. It pushes urgency or fear

“Your account will be suspended in 24 hours.” Pressure is designed to make you act before you think. Legitimate organizations rarely threaten immediate consequences over email.

2. The sender address doesn’t match the brand

Look at the actual email address, not the display name. [email protected] is not PayPal. On mobile, tap the sender name to reveal the real address.

Hover over a link (or long-press on mobile) to preview the real destination. If the visible text says one thing and the URL says another, don’t click.

4. It asks for credentials, codes, or payment details

No legitimate bank, tax authority, or major service will ask you to confirm your password or a one-time code by email or text. That request itself is the red flag.

5. Generic greeting where a real one is expected

“Dear Customer” from a service that knows your name can be a sign, though skilled attackers now personalize, so treat this as supporting evidence, not proof.

6. Small errors that a real brand wouldn’t ship

Odd grammar, off-brand logos, or slightly wrong colors. AI has made phishing text cleaner than it used to be, so this tell is weaker than before, but obvious errors still count.

7. Unexpected attachments

Invoices, “delivery” files, or documents you didn’t request. Don’t open them; verify with the supposed sender through a channel you already trust.

8. The channel is unusual

A “bank” texting you a link, a “colleague” DMing you a gift-card request. Match the message to how that person or company normally contacts you.

What to do instead of clicking

  • Navigate to the site yourself using a bookmark or by typing the address.
  • Contact the company through a number or app you already have.
  • Report the message (most email apps have a “report phishing” option) and delete it.
  • If you already clicked and entered details: change that password immediately, turn on two-factor authentication, and change it anywhere you reused it.

A browser layer catches some of these before you do

A reputation-checking extension can flag a known phishing or lookalike site as the page loads, a useful backstop for the moments you’re tired or rushed. See our guide on browser security extensions.

Source

Related guides

Guide
Do you need a browser security extension?

Guide
Strong passwords without the headache

Guide
Two-factor authentication, explained