A phishing email is a message that impersonates a trusted sender to steal your credentials, money, or data - and you spot one by checking three things in order: does the sender's actual domain match who they claim to be, does the link's real destination match its visible text, and does the message pressure you to act immediately. If any one of those three fails, treat the email as a scam until proven otherwise.
- Check the sender's actual domain, not just the display name - lookalike and typosquatted domains are the most common trick.
- Hover over links before clicking to see where they actually lead, not just what the visible text says.
- Manufactured urgency ("act within 24 hours," "account suspended") is designed to make you skip the first two checks.
- No single red flag proves an email is phishing - a correct sender domain doesn't guarantee safety, since compromised accounts can send from real addresses too.
- Several independent red flags together are far more reliable than any one signal on its own.
- When in doubt, open the service directly in your browser instead of clicking the email's link.
What is a phishing email, exactly
A phishing email is a fraudulent message built to look like it came from someone you trust - a bank, a delivery company, your email provider, a coworker - with the sole purpose of getting you to click a link, open an attachment, or reply with information you'd never otherwise hand over. The word comes from "fishing": the attacker casts a wide net of near-identical messages and only needs a small percentage of recipients to bite. Phishing is a form of social engineering, not a technical exploit - it targets human judgment, not a software vulnerability. Email is only one delivery channel among several; our guide on what phishing is and its main types covers spear phishing, business email compromise, smishing, and vishing in full.
We built Email Scam Checker specifically because most people can spot an obvious phishing email but miss the well-crafted ones - and the well-crafted ones are the only kind that still work at scale. Every red flag below is one we run as an automated check across Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail, so this isn't theoretical advice; it's the same list our detection logic looks for.
Why phishing still works, at scale, every single quarter
Phishing isn't a fringe threat. The FBI's 2025 Internet Crime Report recorded phishing/spoofing as the most frequently reported cybercrime category, with 192,000 complaints - more than double the next most-reported category - while business email compromise alone accounted for $3.05 billion in reported losses that year. The Anti-Phishing Working Group recorded 971,181 unique phishing attacks in Q1 2026 alone. Attackers don't need a high success rate when the volume is that large - they need you to be the one recipient out of a thousand who's in a hurry.
Sender and domain red flags
The single highest-value check is also the one most people skip: does the sender's actual domain - not the display name - match who they claim to be? A message can display "PayPal Support" while the underlying address is something unrelated entirely, and most mail clients hide the real address behind the display name by default.
Watch for three specific domain tricks. A suspicious domain uses a real brand name inside a domain that isn't the brand's own, like "paypal-secure-alert.com." A typosquatted domain is a near-miss misspelling - "paypa1.com" or "netflx.com" - one or two characters off from the real thing. A homoglyph domain swaps in a visually identical character from another alphabet, like a Cyrillic "а" standing in for a Latin "a," so the domain looks correct at a glance but isn't.
A correct sender domain is a strong signal, but it isn't a guarantee - a compromised legitimate mailbox can send phishing from a completely genuine address, which is exactly how many business email compromise attacks work. Treat a clean sender check as necessary, not sufficient, and weigh it alongside the link and language checks below. Email providers also run sender-authentication checks like SPF, DKIM, and DMARC behind the scenes, but these confirm the technical sending path is legitimate, not that the sender's intent is - a correctly authenticated account can still be compromised, so authentication passing is reassuring, not conclusive.
Link red flags
The second check is whether a link's visible text matches where it actually goes. Hover over any link (don't click) and compare the destination shown in your browser's status bar to what the text claims. A link labeled "Sign in to your account" that resolves to a domain with no relation to the sender is one of the most common patterns in real phishing emails.
Beyond a simple text mismatch, look for URL shorteners (bit.ly, tinyurl) or redirect wrappers hiding the real destination, links pointing to a raw IP address instead of a domain, and high-risk domain endings like .xyz, .top, or .shop, which Interisle Consulting's annual phishing landscape research has repeatedly found disproportionately abused for phishing. A TLD alone is never proof of anything, though - treat it only as a weak supporting signal alongside the others. Watch too for a particularly sneaky trick where a real brand's domain is embedded inside an unrelated one - "paypal.com.phishing.xyz" - to look legitimate inside a crowded address bar.
Language and psychological red flags
Phishing emails lean on urgency because urgency short-circuits careful reading. Phrases like "your account has been suspended," "verify now," or "action required within 24 hours" are designed to get you clicking before you check anything else. Combine that with a generic greeting ("Dear Customer" instead of your actual name), multiple grammar mistakes, or a request to "sign in to verify your identity" via a link, and you're looking at a strong cluster of red flags rather than one weak signal - even though legitimate services do occasionally send verification links, so that request alone isn't proof either way.
One phrase worth knowing: unusually formal wording like "kindly send the payment" shows up often in scam templates. It's not a reliable signal on its own - "kindly" is standard business English in India, Nigeria, and several other regions - so treat it only as a minor supporting clue when it appears alongside sender, payment, or urgency red flags, never as proof by itself.
These wording checks are built primarily for English-language emails, since scam phrasing patterns don't translate literally between languages. The highest-value ones - urgency language, credential-harvesting requests, and financial-scam wording - also recognize common Russian-language scam phrasing, which matters if you correspond in more than one language and get targeted in both.
Financial scam and manipulation red flags
Beyond generic urgency, a distinct cluster of red flags targets your money directly, and business email compromise is the version that costs victims the most. It rarely includes a malicious link at all - just a convincing request from someone posing as your boss or a vendor, asking for a wire transfer, gift cards, or a change to invoice payment details. Watch for the same pattern in gift-card requests ("buy five $100 cards and send the codes"), sudden inheritance or lottery windfalls, and sextortion emails claiming to have compromising footage - all rely on the same mix of urgency and authority pressure rather than a technical exploit.
A related trick worth knowing: an email that repeatedly mentions a well-known brand in the body but is sent from a domain that has nothing to do with that brand - a classic sign the sender is borrowing the brand's credibility without actually being them. (This doesn't apply when a company legitimately invites you to "follow us on X" or "join our Discord" inside its own newsletter - mentioning a social platform isn't impersonation.)
Two more technical tells that most guides skip entirely. A Reply-To mismatch is when an email displays as coming from "support@yourbank.com" but hitting reply would actually send your response to a completely unrelated address - visible in the header if you check it, and something Gmail surfaces reliably. A generic action-link mismatch is when a button labeled something vague like "Click Here" or "Verify Now" - rather than spelling out a URL in the visible text - points somewhere unrelated to the sender's own domain. It's an especially effective phishing-link pattern, precisely because it doesn't require the attacker to show you a suspicious address at all.
Attachment and hidden-content red flags
Executable file types disguised as documents - .exe, .scr, or .js files with a document-style name - are a hard stop; no legitimate invoice or shipping notice needs to run code on your machine. A subtler trick is content hidden with CSS (invisible or zero-size text) that isn't visible in the rendered email at all, used specifically to slip scam phrasing past keyword-based filters while showing you something entirely different on screen.
A realistic phishing email example, annotated
Here's a pattern we see constantly: an email claiming to be from Coinbase, subject line "Your account has been suspended - verify immediately," sent from a domain like "coinbase-secure-verify.com" rather than coinbase.com. The body greets you with "Dear Valued Customer," includes a "Verify Now" button whose underlying link points to a URL shortener, and closes with a 24-hour deadline before "permanent account closure."
Every element in that message is a red flag on its own - a suspicious lookalike domain, a generic greeting, a shortened link, and manufactured urgency - and together they're unambiguous. This is also exactly the kind of message where an anti-phishing code check earns its keep: if you'd configured your real Coinbase security phrase in advance, its absence (or a wrong code) from this email would be a critical, immediate tell, independent of everything else.
Legitimate email vs phishing email at a glance
| Signal | Lower-risk pattern | Higher-risk pattern |
|---|---|---|
| Sender domain | Matches the company's real domain exactly | Lookalike, typosquatted, or unrelated free-mail domain |
| Greeting | Uses your actual name (though a generic greeting alone isn't proof of anything) | "Dear Customer" or "Dear User" combined with other red flags |
| Links | Visible text matches destination domain | Visible text and destination don't match |
| Tone | Informational, no artificial deadline | Urgent, threatens account loss or legal action |
| Footer | Unsubscribe link and physical address present (expected for marketing email; not required for personal or transactional mail) | No way to verify the sender's identity through any channel |
When a legitimate email sets off false alarms
Not every email that trips one of these red flags is actually a scam. Genuine marketing emails from platforms like HubSpot, Mailchimp, or SendGrid sometimes use urgency language ("Sale ends tonight") that superficially resembles phishing pressure tactics - the difference is context, a working unsubscribe link, and a real physical address in the footer, all of which are positive signals that offset a single borderline red flag. A message from a company's legitimate support team can also look like impersonation if it uses a generic "Support" or "Team" identity - that's normal, not a red flag, as long as the underlying domain still matches.
Once you can tell a genuine false alarm from a real one, the next step is knowing exactly what to do in each case.
What to do the moment you spot a phishing email
Don't click any link or open any attachment, even "just to see." Report it - most webmail providers have a "Report phishing" option in the message menu, distinct from marking it as ordinary spam, and reporting trains your provider's filters more effectively than deleting it silently. You can also forward the message to the Anti-Phishing Working Group at reportphishing@apwg.org, which aggregates reports for its quarterly trends research, or follow the reporting steps in CISA's Recognize and Report Phishing guidance. If the email impersonates a service you actually use, log in by typing the address directly into your browser - never through the email's link - and check your account activity from there.
How to cut down on how many you get
You can't fully stop phishing emails from arriving - attackers buy scraped address lists and don't ask permission - but a few habits reduce the volume. Report messages as phishing rather than just deleting them, since that feedback improves your provider's spam model over time. Avoid posting your email address in plain text on public forums or social profiles, where scraping bots harvest it automatically. And be cautious with newsletter sign-ups on unfamiliar sites - consider using a separate address or an alias for public sign-ups, so a leak or resale of that list doesn't expose the inbox you actually rely on.
How automated tools catch what a quick read misses
Reading through this checklist manually for every email you get is not realistic, which is the entire reason detection tools exist. We run 28 independent heuristic checks against every email opened in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail - covering every red flag category above, from sender mismatch to hidden CSS content - and combine the results into a single risk score from 0 to 100, with a colored badge (green, yellow, red) so you don't have to hover over every link yourself. For emails that pass the rule-based checks but still feel off, an on-device AI model provides a second opinion; our guide on AI phishing detection, on-device vs cloud explains exactly how that second layer works and why where the model runs matters for your privacy.
If you're choosing between detection approaches - manual review, browser-native warnings, or a dedicated extension - our best phishing protection comparison lines them up side by side.
Final verdict - how to spot a phishing email
Spotting a phishing email comes down to three checks, in order: sender domain, link destination, and manufactured urgency. Any one mismatch is a reason to pause and verify independently; multiple mismatches together make it far more likely you're looking at a scam, and that's when deleting and reporting without clicking anything is the right call. Since no one has time to run that checklist manually on every email, automated heuristic and AI checks exist to do it instantly, on every message, without you having to think about it.