How to Spot a Phishing Email: 10 Red Flags With a Worked Example

Phishing emails pretend to come from someone you trust so that you hand over a password, a payment or access to your device. They no longer arrive full of spelling mistakes. Many are polished copies of real messages. The good news is that they almost always share a handful of tells, and once you know them you can check any suspicious email in under a minute.
A worked example
Here is a message of the kind that lands in inboxes every day. It is invented, but every detail is taken from real campaigns.
Now take it apart:
- The display name is a lookalike. "PayPaI" ends in a capital i, not a lowercase L. In many fonts they are identical.
- The real sender address is not PayPal's. Whatever the display name says, the address is at
paypal-accountreview.co, a domain anyone can register for a few dollars. - The greeting is generic. Companies that hold your account know your name. "Dear Customer" is a sign the sender does not.
- There is a scary reason and a deadline. A sign-in from a far-away place plus "24 hours" or "permanently suspended" is designed to make you act before you think.
- The link is a trick. The domain in a web address is read from the right, just before the first single slash.
paypal.com.secure-login.accountreview.cobelongs toaccountreview.co. "paypal.com" at the start is just a label the scammer chose.
A real PayPal alert would name you, and you could check it by opening the app or typing the address yourself, without touching the email at all.
Ten red flags
- Urgency or threats. Account closure, legal action, missed delivery, a payment "on hold".
- A mismatch between display name and address. Tap or hover on the sender name to see the real address.
- Links whose real destination differs from the text. On a computer, hover over the link and read the address shown at the bottom of the window before clicking.
- Requests for credentials, codes or card numbers. Legitimate companies do not ask you to confirm your password or one-time code by email.
- Unexpected attachments, especially invoices, zip files, or documents that ask you to "enable content" or "enable macros".
- A request to move to another channel, such as "reply on WhatsApp" or "call this number", which takes the conversation away from the company's official contact points.
- Payment changes. "Our bank details have changed, please pay this invoice to the new account" is the classic business email compromise scam.
- Gift cards. No real employer, tax office or tech support team asks to be paid in gift cards.
- Too good to be true. Prizes you did not enter, refunds you did not expect, crypto giveaways.
- Something just feels off. A message from a colleague who never writes like that, at an odd hour, asking for something unusual. Trust that instinct and check through another channel.
Why phishing works: social engineering
Phishing is a technical delivery method for a psychological trick. The trick is called social engineering: getting people to do something by exploiting normal human reactions rather than by breaking software. The same few levers appear again and again:
- Authority: the message claims to come from a bank, a government agency, IT support or your boss.
- Fear and urgency: something bad will happen unless you act right now.
- Helpfulness: a colleague needs a favour, quickly and quietly.
- Curiosity and greed: a parcel, a prize, a salary document, a shared photo.
Attackers also do their homework. A message that mentions your real manager's name or a supplier your company really uses (often gathered from social media, company websites or earlier data breaches) is called spear phishing, and it is far more convincing than a mass mailing.
How to check a suspicious email safely
- Do not click, reply or open attachments while you check.
- Go to the source yourself. Open the company's app or type its web address into your browser. If there is really a problem with your account, you will see it there.
- Call using a number you already trust, such as the one on the back of your card, never the number in the email.
- Look at the full headers if you want certainty. Our guide to reading email headers shows how to see whether the message really came from the domain it claims.
If you already clicked
Act quickly, and do not feel embarrassed: these messages are designed by professionals to fool careful people.
- If you entered a password, change it immediately on the real site, plus anywhere else you used the same password. Then turn on two-factor authentication.
- If you entered card or bank details, call your bank using the number on your card and ask them to block the card and watch for fraud.
- If you opened an attachment or installed something, disconnect the device from the internet and run a full security scan. At work, tell your IT team straight away; the sooner they know, the less damage an attacker can do.
- Check your email account for new forwarding rules or filters you did not create. Attackers often add them to keep reading your mail after you change your password.
Reporting phishing
Reporting helps get fake sites taken down. In the United States, forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org and report scams to the Federal Trade Commission at ReportFraud.ftc.gov. In the United Kingdom, forward them to report@phishing.gov.uk. Most email apps also have a "Report phishing" button that trains their filters.
How temporary email helps
Every site that holds your real address is another place it can leak from, and leaked address lists are exactly what phishing crews buy. Using a temporary address for throwaway sign-ups keeps your real address off those lists in the first place, so fewer scams reach you at all.
