Phishing is the number one way people actually get compromised — not sophisticated hacks, but a fake email that looks just real enough to fool someone in a hurry. The good news: every phish leaves clues. Here's how to spot them.

What phishing is

Phishing is pretending to be someone you trust to get your password, money, or personal data. It arrives by email, text (smishing), phone (vishing), or fake websites. The attacker creates urgency, drops a plausible story, and waits for one careless click.

The 7 red flags

If a message hits any of these, treat it with suspicion:

1. Urgency or fear

"Your account has been locked!"
"Action required within 24 hours!"
"Your payment failed — verify now or you'll lose access!"

Legitimate companies don't threaten you into acting fast. Urgency is the #1 tool of phishers — it short-circuits your judgment. When something pressures you, slow down.

2. A suspicious sender address

Check the actual email address, not the display name. The display name can say anything; the address is the truth.

❌ "paypa1-security@update-now.xyz"
❌ "support@amazon-billing.com"      (not amazon.com)
✅ "no-reply@paypal.com"
✅ "help@github.com"

Hover over links (don't click) and look at the real URL. The text may say "paypal.com" while the link goes to paypal.verify-account.net.

3. Generic greetings

Real companies usually use your name. "Dear valued customer" or "Hello user" is a mass-sent phishing tell — the sender doesn't know who you are.

4. Grammar and typos

One typo doesn't mean phishing, but poor grammar, weird phrasing, or odd formatting is common in scams. Official mail is usually clean.

5. Requests for information

No legitimate service will ever ask for your password, PIN, or OTP code in an email or message. Anyone who asks is a scammer, no matter what they claim.

6. Unexpected attachments

An invoice, a "receipt", a "report" you didn't ask for — attachments are how malware gets in. If you weren't expecting a file, don't open it.

7. Too good to be true

"You won a gift card!", "unexpected tax refund", "claim your free crypto". If it sounds too good to be true, it's a hook.

A real-world example, annotated

Subject: URGENT - Your Netflix account has been suspended
─────────────────────────────────────────────────────
[🔴] Urgency: "URGENT", "suspended"
Dear customer,                                      [🔴] generic greeting
We have noticed unusual activity on your account.    [🔴] fear + vague
Click below to verify your billing information       [🔴] "verify" = give data
within 24 hours or your account will be cancelled.   [🔴] deadline pressure
Veriy your account now:                              [🔴] typo "Veriy"
  [ http://netflix.account-update.ru ]               [🔴] not netflix.com
─────────────────────────────────────────────────────
Sincerely, Netflix Billing                            [🔴] no name

That's seven red flags in one message. Real Netflix mail has your name, no threats, and links to netflix.com.

What to do when you spot one

  1. Don't click anything — no links, no attachments, no "unsubscribe" (that just confirms your address works).
  2. Don't reply.
  3. If it claims to be a service you use, go to the service directly — open a new tab, type the real address, and check your account there.
  4. Report it. Most email providers have a "Report phishing" button. Gmail, Outlook, and Apple Mail all do.
  5. If you clicked or entered data, act fast: change the password, enable 2FA, and contact the real company's support.

Extra protection layers

The mental habit

You don't need to memorize every red flag. Remember one rule:

When a message makes you feel rushed or scared and asks you to click or reply — stop. Verify through a separate, known-good channel first.

Phishing works on emotion, not logic. Slow down, and it fails every time.