How to Spot a Phishing Email: 10 Red Flags With a Worked Example

By Michael Goldsmith · Updated September 23, 2026

A person fishing for a glowing email envelope, illustrating phishing

Phishing emails pretend to come from someone you trust so that you hand over a password, a payment or access to your device. They no longer arrive full of spelling mistakes. Many are polished copies of real messages. The good news is that they almost always share a handful of tells, and once you know them you can check any suspicious email in under a minute.

A worked example

Here is a message of the kind that lands in inboxes every day. It is invented, but every detail is taken from real campaigns.

From: "PayPaI Account Services" <service@paypal-accountreview.co> Subject: Action required: unusual sign-in detected - account limited Dear Customer, We noticed an unusual sign-in to your account from a new device in another country. For your protection, we have temporarily limited your account. To restore full access, please verify your information within 24 hours. Accounts not verified will be permanently suspended. [ Verify My Account ] -> https://paypal.com.secure-login.accountreview.co/verify Thank you, PayPal Security Team

Now take it apart:

  1. The display name is a lookalike. "PayPaI" ends in a capital i, not a lowercase L. In many fonts they are identical.
  2. The real sender address is not PayPal's. Whatever the display name says, the address is at paypal-accountreview.co, a domain anyone can register for a few dollars.
  3. The greeting is generic. Companies that hold your account know your name. "Dear Customer" is a sign the sender does not.
  4. There is a scary reason and a deadline. A sign-in from a far-away place plus "24 hours" or "permanently suspended" is designed to make you act before you think.
  5. The link is a trick. The domain in a web address is read from the right, just before the first single slash. paypal.com.secure-login.accountreview.co belongs to accountreview.co. "paypal.com" at the start is just a label the scammer chose.

A real PayPal alert would name you, and you could check it by opening the app or typing the address yourself, without touching the email at all.

Ten red flags

  1. Urgency or threats. Account closure, legal action, missed delivery, a payment "on hold".
  2. A mismatch between display name and address. Tap or hover on the sender name to see the real address.
  3. Links whose real destination differs from the text. On a computer, hover over the link and read the address shown at the bottom of the window before clicking.
  4. Requests for credentials, codes or card numbers. Legitimate companies do not ask you to confirm your password or one-time code by email.
  5. Unexpected attachments, especially invoices, zip files, or documents that ask you to "enable content" or "enable macros".
  6. A request to move to another channel, such as "reply on WhatsApp" or "call this number", which takes the conversation away from the company's official contact points.
  7. Payment changes. "Our bank details have changed, please pay this invoice to the new account" is the classic business email compromise scam.
  8. Gift cards. No real employer, tax office or tech support team asks to be paid in gift cards.
  9. Too good to be true. Prizes you did not enter, refunds you did not expect, crypto giveaways.
  10. Something just feels off. A message from a colleague who never writes like that, at an odd hour, asking for something unusual. Trust that instinct and check through another channel.

Why phishing works: social engineering

Phishing is a technical delivery method for a psychological trick. The trick is called social engineering: getting people to do something by exploiting normal human reactions rather than by breaking software. The same few levers appear again and again:

Attackers also do their homework. A message that mentions your real manager's name or a supplier your company really uses (often gathered from social media, company websites or earlier data breaches) is called spear phishing, and it is far more convincing than a mass mailing.

How to check a suspicious email safely

  1. Do not click, reply or open attachments while you check.
  2. Go to the source yourself. Open the company's app or type its web address into your browser. If there is really a problem with your account, you will see it there.
  3. Call using a number you already trust, such as the one on the back of your card, never the number in the email.
  4. Look at the full headers if you want certainty. Our guide to reading email headers shows how to see whether the message really came from the domain it claims.

If you already clicked

Act quickly, and do not feel embarrassed: these messages are designed by professionals to fool careful people.

Reporting phishing

Reporting helps get fake sites taken down. In the United States, forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org and report scams to the Federal Trade Commission at ReportFraud.ftc.gov. In the United Kingdom, forward them to report@phishing.gov.uk. Most email apps also have a "Report phishing" button that trains their filters.

How temporary email helps

Every site that holds your real address is another place it can leak from, and leaked address lists are exactly what phishing crews buy. Using a temporary address for throwaway sign-ups keeps your real address off those lists in the first place, so fewer scams reach you at all.