# Spotting phishing attempts

> Real examples of fake emails and messages, and the red flags that give them away before you click.

*Source: https://velstech.net/spotting-phishing.hi (Hindi translation of https://velstech.net/spotting-phishing) · Updated: 2026-09-04*

*Markdown version. [Read the interactive guide](https://velstech.net/spotting-phishing.hi). English Markdown: https://velstech.net/spotting-phishing.md.*

---

Phishing लोगों के compromise होने का नंबर एक तरीका है – sophisticated hacks नहीं, बल्कि एक नकली email जो जल्दबाज़ी में किसी को धोखा देने लायक असली लगे। अच्छी खबर: हर phish सुराग छोड़ता है। उन्हें पहचानने का तरीका यहाँ है।

## Phishing क्या है

Phishing आपके भरोसे का नाटक करके आपका password, पैसा या personal data लेना है। यह email, text (smishing), phone (vishing) या नकली websites से आता है। Attacker urgency बनाता है, एक plausible कहानी देता है और एक लापरवाह click का इंतज़ार करता है।

## 7 red flags

अगर किसी message में इनमें से कोई भी हो, तो उसे शक से देखें:

### 1. Urgency या डर

```
"Your account has been locked!"
"Action required within 24 hours!"
"Your payment failed – verify now or you'll lose access!"
```

Legitimate कंपनियाँ आपको तेज़ी से काम करने के लिए धमकाती नहीं हैं। Urgency phishers का #1 हथियार है – यह आपकी judgment को short-circuit कर देता है। जब कुछ आप पर दबाव डाले, तो धीमे हो जाएँ।

### 2. संदिग्ध sender address

असली email address देखें, display name नहीं। Display name कुछ भी कह सकता है; address ही सच है।

```
❌ "paypa1-security@update-now.xyz"
❌ "support@amazon-billing.com"      (not amazon.com)
✅ "no-reply@paypal.com"
✅ "help@github.com"
```

Links पर hover करें (click न करें) और असली URL देखें। Text में "paypal.com" लिखा हो सकता है जबकि link `paypal.verify-account.net` पर जाता है।

### 3. Generic greetings

असली कंपनियाँ आमतौर पर आपका नाम इस्तेमाल करती हैं। "Dear valued customer" या "Hello user" mass-sent phishing की निशानी है – sender नहीं जानता आप कौन हैं।

### 4. Grammar और typos

एक typo का मतलब phishing नहीं, पर खराब grammar, अजीब phrasing या odd formatting scams में आम है। Official mail आमतौर पर clean होती है।

### 5. जानकारी के लिए अनुरोध

**कोई भी legitimate service आपसे email या message में कभी आपका password, PIN या OTP code नहीं माँगेगी**। जो भी माँगे वह scammer है, चाहे वह कुछ भी दावा करे।

### 6. अनपेक्षित attachments

Invoice, "receipt", "report" जो आपने माँगा ही नहीं – attachments malware के आने का तरीका हैं। अगर आप किसी फ़ाइल की उम्मीद नहीं कर रहे, तो उसे न खोलें।

### 7. सच होने से ज़्यादा अच्छा

"आपने gift card जीता!", "unexpected tax refund", "अपना free crypto claim करें"। अगर कुछ सच होने से ज़्यादा अच्छा लगे, तो वह hook है।

## एक वास्तविक उदाहरण, annotated

```
Subject: URGENT - Your Netflix account has been suspended
─────────────────────────────────────────────────────
[🔴] Urgency: "URGENT", "suspended"
Dear customer,                                      [🔴] generic greeting
We have noticed unusual activity on your account.    [🔴] fear + vague
Click below to verify your billing information       [🔴] "verify" = give data
within 24 hours or your account will be cancelled.   [🔴] deadline pressure
Veriy your account now:                              [🔴] typo "Veriy"
  [ http://netflix.account-update.ru ]               [🔴] not netflix.com
─────────────────────────────────────────────────────
Sincerely, Netflix Billing                            [🔴] no name
```

एक ही message में सात red flags। असली Netflix mail में आपका नाम होता है, कोई धमकी नहीं, और links netflix.com पर जाते हैं।

## जब आप पहचान लें तो क्या करें

- कुछ भी click न करें – कोई links, कोई attachments, कोई "unsubscribe" नहीं (वह बस confirm करता है कि आपका address काम करता है)।

- Reply न करें।

- अगर वह किसी service का claim कर रहा है जिसे आप इस्तेमाल करते हैं, तो सीधे service पर जाएँ – नई tab खोलें, असली address type करें और वहाँ अपना account check करें।

- Report करें। ज़्यादातर email providers में "Report phishing" button होता है। Gmail, Outlook और Apple Mail सब में है।

- अगर आपने click किया या data डाल दिया, तो तेज़ी से action लें: password बदलें, 2FA चालू करें और असली कंपनी के support से contact करें।

## Extra protection layers

- 2FA – आपका password leak भी हो जाए तो दूसरा factor account को सुरक्षित रखता है।

- Password manager – यह lookalike domain पर autofill नहीं करेगा, जो खुद एक warning sign है।

- Messages को सीधे check करें – email में links पर click करने के बजाय खुद app या website खोलें।

- फ़ोन पर SMS के साथ extra careful रहें – links वाले "package delivery" texts अभी बहुत बड़ा scam हैं।

## मानसिक आदत

आपको हर red flag याद रखने की ज़रूरत नहीं। एक नियम याद रखें:

> जब कोई message आपको rushed या scared महसूस कराए और click या reply करने को कहे – रुक जाएँ। पहले अलग, known-good channel से verify करें।

Phishing emotion पर काम करता है, logic पर नहीं। धीमे हो जाएँ, और यह हर बार fail हो जाता है।

---

*VelsTech – https://velstech.net/spotting-phishing.hi.md*
