You can spot most phishing emails with six checks that take under a minute: verify the sender's real address, not the display name; hover every link before clicking; distrust unexpected urgency; treat attachments from unknown senders as hostile; compare against how the real company writes to you; and when in doubt, navigate to the site yourself instead of using the email's links. None of these requires technical skill — phishers exploit inattention far more than technology, counting on you acting before reading.
What is phishing, and what do attackers want?
Phishing is a social-engineering attack delivered as a message — email most often, but the same mechanics drive smishing by SMS and vishing by phone call. The FBI's Internet Crime Complaint Center consistently ranks phishing among the costliest crime categories it tracks, with hundreds of thousands of complaints annually. The goals split into three buckets: credential theft (a fake login page harvesting your password and one-time code), malware delivery (a poisoned attachment or document macro), and payment fraud (invoice changes, gift-card requests, wire redirects). Business email compromise — phishing aimed at staff with payment authority — causes the largest direct losses per incident of any IC3 category.
Check one: read the actual sender address
Display names are free — anyone can set an email client to show "Microsoft Support" or your CEO's name. The address behind it is harder to fake. On desktop, click or hover the sender to expand the full address; on mobile, tap the name to open the contact card. Look at the domain after the @: legitimate enterprise mail comes from the company's real domain. Watch for lookalikes — rn for m, extra hyphens, or a real brand name in a subdomain like paypal.com.secure-login.example.net, where only the last two segments matter. A message from a lookalike domain is disqualifying on its own.
Check two: hover before you click
Link text is decoration; the URL underneath is the fact. On desktop, rest your pointer on any link and read the preview that appears in the corner of the window — that is where the click goes. On mobile, press and hold to see the URL before the menu offers to open it. If the link's destination is a shortened URL, a random domain, or a mismatch with the brand shown in the text, do not open it. And for password-adjacent emails — banks, Microsoft 365, iCloud, PayPal — abandon the email entirely, open a new tab, and type the address or use your bookmark. The link's legitimacy stops mattering because you never needed it.
Check three: decode the urgency
Manufactured pressure is the oldest tool in the kit: your account will be closed today, a delivery failed and fees accrue hourly, the boss needs wire confirmation before a meeting. Urgency works because it converts a two-second pause into a perceived luxury. Build a personal rule with teeth: any message that demands action inside an hour gets treated as suspicious by default, whatever the brand on it. Real institutions rarely operate on those clocks, and the few that do — a genuine bank fraud call, for instance — will survive you calling back through the number on your card.
Check four: interrogate attachments
Attachments carry the worst outcomes. Be maximally skeptical of documents that ask you to Enable Content or Enable Macros — no legitimate routine document needs that, and that click is exactly what runs the malware. Treat archives (.zip, .7z) and disk images from unknown senders as hostile, and be suspicious of HTML attachments, which are phishing pages smuggled past spam filters. Invoice-themed lures aimed at finance and HR staff remain the most common workplace pattern: an unexpected PDF or spreadsheet about a payment is worth a direct verification through a known channel before opening.
Check five: compare with real mail from the same sender
Fake mail fails pattern-matching against the real thing. Check the greeting — mass phishes say Dear Customer where your bank uses your name; the signature — vague titles, missing contact details; and the request itself — your bank will never email asking for a full password, and no platform asks for payment in gift cards. Generic greetings plus a request for credentials or money is the profile of a phish.
Check six: when in doubt, verify out of band
The final check is a habit, not an inspection: verify important requests through a second channel. The boss emails about an urgent wire? Confirm by calling their known number. The IT team wants your password? Contact helpdesk directly. A message about your account? Open the app or site yourself. Attackers control the conversation inside the email; out-of-band verification moves it to ground they do not control — which is why it defeats even the tailored spearphish that passes the first five checks.
What if you already clicked?
Act fast and in order: if you entered credentials on a fake page, change that password immediately, then everywhere else it was reused; revoke active sessions in the account's security settings; if you approved a multi-factor prompt you did not initiate, treat the account as compromised and check recovery details for changes; if you opened an attachment, disconnect from the network and run a full antivirus scan. Then report the email — the Report Phishing button in most mail clients, and, for fraud attempts, the FBI's IC3. Reporting trains filters for everyone else; silence leaves the next recipient unprotected.
For more context, read How to shop online safely: card hygiene, fake shops, and the checkout checklist.
For more context, read personal security checklist.
For more context, read How to set up sign-in alerts on the accounts that matter.

