Skip to content
Last updated: July 13, 2026
🕑 3 min read

Phishing remains the most common way accounts get hijacked, not because it is sophisticated, but because it only needs to work once. Modern phishing emails are no longer full of spelling mistakes and strange fonts; many are pixel-perfect copies of real messages from banks, delivery companies and streaming services. The good news: almost every phishing email still gives itself away in at least one of the following ten ways.

1. The sender address does not match the sender name

🔧 Free tool: Password Strength Checker — How long would yours survive? Test it privately.

The display name says “PayPal Support” but the actual address is something like service-paypal@mail-notify-eu.com. On a phone, the address is usually hidden – tap the sender name to reveal it. A real company writes from its own domain, full stop.

2. Urgency and threats

“Your account will be suspended in 24 hours.” “Unusual sign-in detected – act now.” Manufactured time pressure is the oldest trick in social engineering, because people who hurry do not inspect. Real companies rarely threaten immediate account closure by email, and never demand you fix it through a link in that same email.

3. A link that does not go where it claims

Hover over any link before clicking (on a phone, press and hold to preview). If the text says netflix.com but the preview shows netflix.account-billing-update.info, you have your answer. Attackers rely on the fact that most people read the first word of a URL and stop. The part that matters is the domain right before the first single slash.

4. A generic greeting

“Dear customer”, “Dear user”, or your email address used as a name. Your bank knows your name. A scammer who bought a list of two million addresses does not.

5. Unexpected attachments

An invoice you never expected, a “voicemail” as an HTML file, a ZIP called scan_document. Attachments are the delivery van of malware. Unless you specifically expected a file from this exact person, do not open it – especially HTML, ZIP, ISO and Office files asking you to “enable macros”.

6. Requests for credentials, codes or card details

No legitimate service asks you to reply with your password, send your 2FA code, or “verify” your card number by email. The moment a message asks for secrets, it has identified itself as hostile.

7. Slightly wrong branding and layout

An old logo, oddly compressed images, a footer that mentions the wrong country, buttons that render as plain blue text. Companies obsess over their templates; scammers copy whatever version they found last year.

8. You did not initiate anything

A password reset you never requested, an order confirmation for something you never bought, a “your payment failed” notice from a service you do not use. Scammers send these hoping curiosity or alarm makes you click “cancel this order” – which leads to a credential-harvesting page.

9. Reply-to address differs from the sender

The email appears to come from a colleague or supplier, but replies are routed to an outside address. This is the backbone of invoice fraud against small businesses. If a message about money looks even slightly off, phone the person on a number you already have.

10. It arrived through an unusual channel

Your “bank” contacting you via a personal Gmail address, a government agency messaging you on WhatsApp, a CEO asking for gift cards over SMS. Institutions are boringly consistent about their channels. Novelty is a warning.

The one habit that beats every phishing email

Never act through the message itself. If an email says there is a problem with your account, close it, open your browser, type the company address yourself (or use your bookmarked link or official app), and log in there. If the problem is real, it will be waiting in your account. If nothing is wrong, you have just watched a phishing attempt die quietly. This single habit works even against perfect fakes, because it removes the attacker’s only asset: their link.

If you already clicked

Do not panic, and do not wait. Change the password of the affected account immediately, enable two-factor authentication if it was off, and check the account’s active sessions and forwarding rules. If you entered card details, contact your bank and ask them to block the card. Acting within the first hour closes most of the damage window.

Keep reading

Computer Multiverse app

Get the Computer Multiverse app

Password & scam checkers, plain-English security help — straight from your home screen. No app store needed.