Skip to content
Cyber Security Firms

How to Spot a Phishing Email: 7 Red Flags to Check

A message is open in front of you and something about it is off. This is the check that settles it, in the order that settles it fastest, and it works on a phone.

Beginner13 min readUpdated
How to Spot a Phishing Email: 7 Red Flags to Check

The advice everyone remembers is to look for bad spelling, and that advice retired years ago. Modern lures are clean, correctly branded, addressed to you by name and often sitting inside a thread you recognize. What still gives them away is not how the message reads but what it wants and where it points, and both can be checked in under a minute. If you want the mechanism behind the attack, how a phishing attack works covers it. This page is the check itself.

How to Spot a Phishing Email

Run these in order. Most messages fail at the second or third item, and you never have to reach the rest.

What Are the 7 Red Flags of Phishing?

If you want the list rather than the procedure, these are the seven, drawn from what CISA and the FTC both flag.

  1. Urgent or emotionally loaded language. CISA's wording is messages claiming dire consequences for not responding immediately. Suspension, closure, legal action, a refund about to expire.
  2. A request for personal or financial information. The FTC's list covers most lures: they noticed suspicious activity, there is a problem with your account or payment, confirm your information, here is an invoice you do not recognize, click to make a payment, register for a refund, take a free coupon.
  3. A sender address that does not match the brand. Microsoft's guidance calls out mismatched domains and near-misses such as micros0ft.com, where a zero replaces the letter.
  4. A link that does not go where the text says. Look-alike domains, and shortened URLs that hide the destination completely.
  5. An attachment you did not ask for. Especially an invoice, a receipt, a resume or a shared document from someone you do not normally exchange files with.
  6. A generic greeting, or a request that skips the normal process. "Dear customer" is the old version. The modern version is a real name attached to a request that would normally go through a system, a portal or a ticket.
  7. Anything that moves money. A new bank account on a familiar invoice, a wire that must go today, a gift card purchase. This one is worth its own rule because it is where the losses are.

Grammar and spelling used to sit near the top of this list and no longer belong on it. CISA now says outright that in the era of artificial intelligence some emails will have perfect grammar and spelling, and tells readers to look for the other signs instead. The same is true of logos, formatting and signature blocks, all of which are copied in seconds. Anything that is easy for the attacker to fix is a weak tell. What they cannot fix is the address they send from, the domain they send you to, and the fact that they need you to act now.

Phishing is social engineering delivered by message, so the same tells apply to a text, a phone call or a chat message. The checks below are written for email because that is where most people meet it.

These are the two checks that survive a well-made lure, and both take about five seconds once you know where to look.

The sender. The display name is free text chosen by whoever sent the message. The address is not. On a computer, click the sender name to expand it; on a phone, tap the name or the "from" line. What you are looking for is the domain after the at sign: the organization's real domain, not a look-alike, not a public mailbox provider, not a long string ending somewhere unfamiliar. In Outlook, a banner saying the sender could not be verified is a real signal.

The link. This is where most people go wrong, because a web address is read right to left, not left to right. Find the first single slash after https://. The two labels immediately before it are the actual site. Everything to the left of those is a subdomain the attacker chose freely and can set to anything.

What you seeThe real destinationWhy it works
https://paypal.com.secure-verify.net/loginsecure-verify.netThe brand name is a subdomain, not the site
https://accounts.google.com.signin-alert.co/authsignin-alert.coSame trick, longer runway
https://www.micros0ft-support.com/resetmicros0ft-support.comA zero for an o, at a glance identical
https://bit.ly/4kPq2XmUnknown until it opensA shortener hides everything above

On a computer, hover over the link and read the address in the status bar. On a phone, press and hold the link until a preview appears, then read it and cancel. Doing this on a phone matters more than it used to: the 2026 Verizon Data Breach Investigations Report found mobile social engineering success up 40 percent, and the reason is structural rather than psychological. A small screen truncates the sender address and hides the link destination, so the two checks that work are the two checks a phone makes hardest.

A phone held upright showing a link preview panel above a message

Phishing Email Examples and What Gives Them Away

Three lures you will actually receive, with the line that decides each one.

The billing hold. A streaming service writes that your account is on hold because of a payment problem, with a button to update your card. Everything is branded correctly and the greeting says "Dear customer". What gives it away is not the design; it is that a real billing problem is visible when you open the app yourself, and this message needs you to fix it here, now, through its button. The FTC uses this exact pattern as its worked example.

The password expiry. A message that appears to come from your IT department says your password expires today and links to a sign-in page that looks like your company's. It uses your real name and the right logo. What gives it away is the address it came from, which is external, and the destination domain, which is a look-alike. A genuine password policy runs through a system you already sign in to.

The delivery fee. A text says a package could not be delivered and a small fee is due, with a shortened link. The tell is that a shortener hides the destination, the fee is trivial enough to seem worth paying, and no carrier collects money by text. The amount is deliberately below the level at which people check.

What Happens If You Open a Phishing Email?

Almost nothing, on any modern mail client. Opening a message does not run code, and the fear that it might is the most common misconception about phishing. The risk is entirely in what you do next.

What each action in a phishing email actually costs
  1. You open the messageSafe. Reading it does not run anything on your device
  2. Remote images loadConfirms to the sender that the address is live and the message was read. Nothing worse
  3. You click the linkUsually harmless by itself. A page loads, and a page is just a page until you type into it
  4. You type your passwordThis is the compromise. Assume it is in use within minutes and change it now
  5. You approve the sign-in promptHands over the live session even with two-factor authentication switched on
  6. You open the attachment and enable contentCode runs on the device. Treat the machine as compromised until it is checked
The first three rows are recoverable and the last three are not. Every defense that matters sits between row three and row four.

Replying is worth one line of its own: it confirms a live human reads that address, which raises the price of your address on the lists these campaigns are run from. So does clicking unsubscribe in a message you already suspect. CISA's advice is the simplest version: recognize, resist, delete. Report it, then delete it without replying.

How Can I Tell If an Email Is Real?

The harder half of this skill is clearing the genuine message, and no list of warning signs helps with that. Start by discounting the things that are not evidence of anything:

  • A link in an email. Real organizations send links constantly. A link is not a red flag; an unexpected link to a login page is.
  • An attachment from a colleague. Normal, unless you were not expecting it or the file type is odd.
  • An external sender tag. It means the message came from outside your organization, which describes every customer, vendor and newsletter you deal with.
  • A padlock or an https address. Certificates are free and attackers use them. The padlock says the connection is encrypted, not that the site is honest.
  • Correct logos, formatting and grammar. All copied, all cheap, and cheaper still with generative tools.
  • A message that appears inside an existing thread. Attackers reply into real threads, sometimes from a genuinely compromised account.

Once those are set aside, there is one move that resolves anything left. Go to the organization through a route you chose: type the address yourself, open the app, or call the number on your card or your last statement. Ask whether the message is theirs. It takes a minute and it is the only check that cannot be defeated by a better-made fake, which is why it is also the answer for every other attack in the wider catalog of cyber security threats.

Myth vs reality
What people believe
If the email came from an address I recognize, it is safe.
What actually happens
Sender addresses can be spoofed, and a colleague's account that has already been phished sends real mail from a real address. Recognizing the sender raises confidence; it does not settle the question. What settles it is whether the request itself makes sense and survives being confirmed through a channel you picked.

How to Report a Phishing Email

Reporting is the part everyone skips, and it is what gets the fake site taken down before it reaches the next person.

  1. At work, use the report button first. Outlook has Report phishing in the ribbon, and most other clients have an equivalent. That routes the message to whoever can check whether the same lure hit fifty other mailboxes. If your client has no button, Microsoft asks that you forward the message as an attachment rather than inline to phish@office365.microsoft.com.
  2. For personal email, report it in the client, then forward it. Gmail and Outlook.com both have a report option that trains the filter. The Anti-Phishing Working Group collects samples at reportphishing@apwg.org, which the FTC points consumers to.
  3. Forward suspicious texts to 7726. That is SPAM on a keypad, and it is free on the major US carriers.
  4. File with the FTC at ReportFraud.ftc.gov if you lost money or data. If it cost you money, also file with the FBI at ic3.gov, which is where the national numbers below come from.
  5. Delete it afterward, without replying.

The reason to bother is visible in the FBI's 2025 IC3 Annual Report. Phishing and spoofing was the most reported crime type of the year at 191,561 complaints, slightly down from 193,407 the year before. Reported losses went the other way, from $70,013,036 to $215,843,126. Fewer messages, better ones.

What to Do If You Fell for a Phishing Email

Speed matters more than anything else, because the attacker window is usually minutes rather than days.

If the account that was phished holds personal data, or if the message came out of a leak of your details, what to do after a data breach has the fuller response by data type. Turning on multi-factor authentication is the one change that makes the next one survivable: CISA's position is that any second factor beats none, and that phishing-resistant forms such as passkeys and security keys are the standard to aim for, because they cannot be typed into a copied page.

Key takeaways

  • Check in order: was I expecting it, who really sent it, what does it want, and where does the link really go.
  • The domain immediately before the first single slash is the site you will land on. Read a web address right to left.
  • Grammar, logos and formatting are not tells any more. Urgency plus a request for a password, a code or a payment still is.
  • Opening a phishing email is safe. Typing a password, approving a prompt or enabling content in an attachment is not.
  • Nothing that arrives by message needs to be done through that message. Open the site yourself and do it there.
  • Report it before deleting it, at work and at home. It is what gets the fake page taken down.

Common questions

What are 5 key signs of phishing?

Urgency or a threatened consequence, a request for a password, code or payment, a sender address that does not match the brand, a link pointing at a domain that is not the brand's, and an attachment you did not ask for. Any one of them is enough to stop and verify.

How can I check if an email is phishing?

Expand the sender to read the full address, press and hold or hover the link to read its real destination, and ask whether the request needs you to act inside the message. If it survives all three and you are still unsure, contact the organization through a number or address you already had.

Is it safe to open a phishing email on my phone?

Opening it is safe on both a phone and a computer. The difficulty on a phone is checking: the sender address is truncated and the link destination is hidden until you press and hold. If you cannot complete the check comfortably, leave the message until you are at a computer rather than guessing.

Do phishing emails always have bad spelling or grammar?

No, and treating that as a test is now a liability. CISA states plainly that some phishing emails will have perfect grammar and spelling and tells readers to look for the other signs. Well-resourced attacks have always been clean; generative tools made cheap ones clean too.

Can a phishing email come from someone I know?

Yes, in two ways. The address can be spoofed so it displays as theirs, or their account has genuinely been taken over and the message really is being sent from it. The second is more dangerous because it passes every technical check, so an unexpected request still gets verified by phone.

What is the difference between phishing and spam?

Spam is unwanted bulk mail, usually advertising something real. Phishing is fraud: it impersonates someone you trust to get credentials, money or access. Spam wastes your time and phishing costs you something, so report phishing rather than only marking it as junk.

Should I reply to a phishing email to see if it is real?

No. A reply confirms a live person reads that address, which increases what you are worth to whoever bought the list. If you want to check whether the request is genuine, contact the organization directly through a route you chose rather than by replying to the message.

Can I get a virus from a phishing email attachment?

From opening the message, no. From opening the attachment and allowing it to do something, yes. The usual pattern is a document that displays a prompt asking you to enable content or editing, which is the moment the code runs. Unrequested attachments do not get opened, and prompts to enable anything do not get accepted.

Why do I keep getting phishing emails?

Because your address appeared in a data breach, was scraped from a website, or was confirmed as live when a previous message got a reply or loaded its images. You cannot stop them arriving. You can make them harmless with multi-factor authentication, a password manager that refuses to fill a fake page, and the habit of opening sites yourself.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →