How to Spot a Phishing Email
Phishing emails have gotten more convincing, but they still tend to share a handful of tells. Here's what to actually check.
1. Check the sender address, not just the display name
An email can display "Microsoft Support" as the name while the actual address is something unrelated. Tap or hover on the sender name to reveal the real address, and check whether the domain after the @ matches the company exactly (not a lookalike like "micros0ft-support.com").
2. Urgency and threats are a red flag
"Your account will be suspended in 24 hours," "unusual sign-in detected — verify now," and similar language is designed to make you act before thinking. Legitimate companies rarely give you a countdown.
3. Check where links actually go
Before clicking, hover over (or long-press on mobile) a link to preview the actual URL. It should match the company's real domain — not a shortened link or an unrelated domain with the company's name buried in the path.
4. Requests for passwords, codes, or payment
5. Unexpected attachments
Be especially cautious of unexpected invoices, "shipping documents," or files with extensions like .zip, .exe, or macro-enabled Office documents (.docm, .xlsm) — even if the sender looks familiar, since compromised accounts are often used to spread malware to their real contacts.
6. Generic greetings for something that should be personal
"Dear Customer" on a message claiming to be about your specific account or order can be a sign it's a mass-sent scam rather than something your bank or provider actually sent.
If you're not sure
- Don't click any links or download attachments.
- Go directly to the company's website by typing the address yourself (not from the email), and check your account status there.
- If the message claims to be from someone you know, contact them a different way (text, call) to confirm before acting.
Already clicked something?
See what to do if your email account is hacked for immediate next steps.