Skip to content
Home
How to Spot Phishing Emails: 10 Red Flags

How to Spot Phishing Emails: 10 Red Flags

10 min read

Phishing emails are the most common cybersecurity threat. Over 3.4 billion phishing emails are sent every day, and they account for more than 90% of data breaches. Learning to spot them is one of the most important digital safety skills you can develop.

1. The Sender Address Doesn’t Match

Check the actual email address, not just the display name:

Display name: "PayPal Security Center"
Email address: paypal-secure-2024@ru.randomdomain.xyz
                         ^
                         Not paypal.com

Hover over the sender name before clicking anything. If the domain doesn’t match the company, it is a scam. Attackers spoof display names to look legitimate, but the underlying address always reveals the truth.

Pro tip: In Gmail, click the “Show details” arrow next to the sender name to see the full email address. In Outlook, right-click the message and select “View message details.”

2. Generic Greetings

Legitimate companies use your name:

PhishingLegitimate
“Dear valued customer,”“Dear Sarah Chen,”
“Dear user,”“Dear Mr. Johnson,”
“Hello account holder,”“Hi Alice,”

If an email from a service you use doesn’t address you by name, be suspicious. Companies you do business with have your name on file and use it in their communications. A generic greeting is a strong indicator that the sender does not actually know who you are.

Exception: Some legitimate marketing emails use generic greetings. But if the email claims to be urgent or about your account, a missing name is a major red flag.

3. Urgent or Threatening Language

Phishers create panic to override your judgment:

“Your account will be suspended within 24 hours!” “Unauthorized login detected. Verify immediately.” “You owe $499.99. Payment overdue.”

Legitimate companies don’t threaten you via email. If it creates urgency, it is probably fake. Phishers rely on your fear response — when you panic, you are less likely to check details before clicking.

Real-world example: A common phishing tactic is pretending to be from Netflix claiming your payment failed. The email says your account will be cancelled within 24 hours unless you update your billing information. The link leads to a fake Netflix login page that steals your credentials.

4. Suspicious Links

Hover over links (don’t click) to see the real destination:

Displayed link: https://paypal.com/reset-password
Actual link:    https://phishingsite.ru/steal/password

If the URL doesn’t match the company’s official domain, don’t click. On mobile, press and hold the link to see the preview.

Common URL tricks to watch for:

  • Misspellings: go0gle.com (zero instead of o), paypa1.com (one instead of l)
  • Subdomain tricks: secure-paypal.com.phishing.com
  • Unusual TLDs: .ru, .xyz, .top, .click
  • URL shorteners: bit.ly, tinyurl.com (these hide the real destination)

5. Spelling and Grammar Errors

Phishing emails often contain:

  • Awkward phrasing
  • Missing words
  • Incorrect capitalization
  • Strange formatting

Legitimate companies proofread their emails. Errors are a red flag. However, be aware that some sophisticated phishing attacks now use AI-generated text that is grammatically perfect.

Why the errors? Some phishers deliberately include errors to filter out savvy recipients. If you notice the errors and delete the email, they have saved themselves from having to deal with a skeptical target. The errors are a feature, not a bug.

6. Unexpected Attachments

Email attachments from unknown senders should never be opened:

  • Invoices you didn’t request
  • Shipping notifications for items you didn’t order
  • “Secure messages” in PDF format
  • ZIP or RAR files

Attachments can contain malware that installs keyloggers, ransomware, or remote access tools on your computer. Even PDFs and Office documents can contain malicious macros.

Safe practice: If you receive an unexpected attachment from someone you know, message them through another channel (phone, chat) to verify they sent it. Their account may be compromised.

7. Requests for Personal Information

Legitimate companies never ask for:

  • Your password (in any form)
  • Social Security number
  • Credit card details
  • Bank account numbers
  • Two-factor authentication codes

If an email asks for any of these, it is a phishing attempt. No legitimate organization will email you asking for your password or sensitive financial information.

Two-factor code scam: A newer phishing tactic asks for your 2FA code, claiming the company needs to “verify your identity.” In reality, the scammer is trying to log in to your account and needs the code that was sent to your phone.

8. Too Good to Be True

“You’ve won £5,000,000 in the lottery!” “Your tax refund of $1,200 is ready.” “Exclusive investment opportunity — guaranteed returns!”

If you didn’t enter a contest, you didn’t win. Delete. These emails play on greed and excitement, overriding your critical thinking. If something seems too good to be true, it is.

9. Mismatched Branding

Look closely at logos, colors, and formatting:

  • Blurry or stretched logos
  • Wrong company colors
  • Missing footer information
  • No physical address or unsubscribe link

Companies maintain brand consistency. Poor quality is a giveaway. Compare the suspicious email to a legitimate email you know you have received from the same company.

Real example: A common Amazon phishing email uses a slightly wrong shade of orange and a logo that is pixelated at the edges. These details are easy to miss if you are skimming, but obvious once you look carefully.

Real Examples

PayPal Phishing

From: "PayPal" <secure-notifications@paypal-update.net>
Subject: Your account has been limited

Dear Customer,

We have detected unusual activity on your account.
Your account has been temporarily limited.
Click here to verify your identity immediately.

PayPal Team

Red flags: Wrong domain, generic greeting, urgent language, requests identity verification.

Delivery Phishing

From: "FedEx" <tracking@fedex-delivery-alerts.xyz>
Subject: Package delivery failed

Your package could not be delivered.
Please download the shipping label and take it to your
local post office to reschedule delivery.

[Download Label (ZIP file)]

Red flags: Suspicious domain, unexpected attachment (ZIP).

Microsoft 365 Credential Phishing

From: "Microsoft" <admin@m365-security-alerts.co>
Subject: Action Required: Your password will expire

Dear User,

Your Microsoft 365 password will expire in 48 hours.
Click below to keep your current password:

[Keep Current Password]

Microsoft Security Team

Red flags: Unknown sender domain, threat of service loss, asks you to “verify” by clicking a link.

What to Do If You Receive a Phishing Email

  1. Do not click any links or open attachments
  2. Do not reply
  3. Report it:
    • Gmail: Click “Report spam”
    • Outlook: Click “Report phishing”
    • Forward to the impersonated company’s security team
  4. Delete it

If you clicked a phishing link:

  1. Change your password immediately (on a different device)
  2. Enable two-factor authentication if not already enabled
  3. Run a virus scan using Windows Defender or Malwarebytes
  4. Monitor your accounts for unusual activity for the next 30 days
  5. Contact your bank if financial information was entered
  6. Place a fraud alert on your credit report if sensitive data was involved

How Businesses Can Protect Themselves

For organizations, training employees to spot phishing is essential, but technical controls also matter:

  • DMARC, DKIM, and SPF — email authentication protocols that make it harder to spoof your domain
  • Advanced threat protection — tools that scan attachments and links before delivery
  • Simulated phishing campaigns — test your employees with fake phishing emails to identify who needs additional training
  • Reporting buttons — make it easy for employees to report suspicious emails

Related: Set up two-factor authentication and learn about password managers.

Best Practices and Pro Tips

Over years of experience, practitioners have developed approaches that consistently produce better results. The first is to establish a routine. Consistency matters more than intensity in almost every domain. A modest effort applied regularly outperforms sporadic bursts of intense activity. Set aside dedicated time for your work and protect it from interruptions.

The second best practice is to document everything. Write down what you did, why you did it, what happened, and what you would do differently next time. This documentation becomes invaluable when you encounter similar situations in the future. It also helps you identify patterns in your own work that you might otherwise miss.

The third is to seek feedback early and often. Show your work to others before it is perfect. Early feedback saves enormous rework by catching fundamental issues before you have invested significant effort. It also exposes you to different perspectives and approaches that expand your understanding of the topic.

Building on Your Knowledge

As you become more comfortable with the basics, look for opportunities to deepen your understanding. Teach others what you have learned — teaching forces you to organize your knowledge and identify gaps in your own understanding. Take on projects that stretch your abilities slightly beyond your comfort zone. Challenge yourself to solve problems without immediately looking up the answer.

Connect your new knowledge to related fields. Understanding how different domains relate to each other builds a more complete mental model and reveals insights that isolated study cannot provide. Cross-disciplinary knowledge is increasingly valuable as technology and practices become more interconnected.

FAQ

What equipment do I need to get started with this topic? Start with the basics and upgrade as needed. For most people, the standard tools and resources available at little to no cost provide everything needed to begin learning. As your skills and requirements grow, you can invest in more specialized equipment that matches your specific interests. The key is to avoid buying expensive gear before you know what you actually need.

How much time does it take to see meaningful results? Results vary by individual, but most people see meaningful progress within 2-4 weeks of consistent practice. The key is regular engagement rather than marathon sessions. Even 15-30 minutes daily produces better results than several hours once a week. Set realistic expectations and celebrate small improvements along the way rather than comparing yourself to experts.

What is the single biggest mistake beginners make? The most common mistake is trying to do everything at once. Focus on one technique or skill at a time, master it, and then move on. Beginners also tend to compare themselves to experts rather than focusing on their own progress. Everyone starts somewhere, and the people producing polished work have years of practice behind them. Patience and consistency matter more than natural talent.

Where can I find help if I get stuck on a specific problem? Online communities, forums, and local groups are excellent resources. Search for forums related to your specific topic, join relevant subreddits or Discord servers, and check YouTube for visual tutorials. When asking for help, be specific about what you have tried and what is not working. Most communities are welcoming and eager to help newcomers who show initiative and have done basic research first.

How do I stay motivated over the long term? Set specific, achievable goals and track your progress. Join a community of people with similar interests. Share your work and celebrate milestones. Remember that plateaus are normal — progress is rarely linear. When you feel stuck, try a different aspect of the topic or take a short break. The most successful practitioners are those who maintain consistent effort over years, not those who burn out quickly.

When should I upgrade my tools or equipment? Upgrade only when your current tools limit your progress. Many people fall into the trap of buying expensive equipment before developing the skills to use it effectively. A skilled practitioner with basic tools produces better results than a beginner with professional-grade equipment. Invest in learning before investing in gear. When you consistently find yourself limited by your tools rather than your skills, that is the right time to upgrade.

How do I know if I am making progress? Track specific metrics relevant to your goals. Keep a journal of what you learn and practice. Review your work from one month ago and compare it to your current work. Ask for feedback from more experienced practitioners. Progress is often invisible day to day but becomes obvious when you look back over weeks and months. If you feel stuck, ask a mentor or community member to evaluate your current level and provide guidance on next steps.

#security#phishing#email-security