Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an email asks you to click, pay, sign in, download something, or share personal information, pause and check it first. Unexpected senders, mismatched addresses, pressure, suspicious links, and unusual requests are warning signs—not a score that can prove whether a message is genuine. Verify any real account issue through a website or phone number you already know is legitimate, not through the message.

How can you tell if an email is phishing?

Phishing emails impersonate trusted organizations or people to get information, account access, or money. They can copy familiar names, logos, and polished formatting, so appearance alone is not enough. Check the sender, what the message asks you to do, and where its links go. The clues below draw on overlapping examples from the Federal Trade Commission and Google; they are not an official ranking or a legitimacy test.

Eight phishing red flags to check

1. The message is unexpected

An unexpected email from someone you do not recognize deserves caution, even if it mentions a service or person you know. Scammers may pose as a familiar company, bank, coworker, or contact. Consider whether you were expecting the message and whether its claim makes sense before responding.

2. The sender name and email address do not match

Display names are easy to imitate. Inspect the full email address, not just the name shown beside the message. An address that does not appear to belong to the organization it claims to represent is a warning sign. Where your email service provides message authentication details, those can offer another check, but do not treat a familiar-looking name or address as proof on its own.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. It asks for a password or sensitive information

Treat an unsolicited request for a password, payment details, account number, or identification information as suspicious. Do not enter credentials after following a link in an email. Google advises that if a link asks for a Gmail, Google Account, or other service password, you should go directly to the website you intend to use instead.

4. It uses urgency, threats, or pressure

Claims that an account is locked, suspicious activity has been detected, or a payment problem must be fixed immediately are common pressure tactics. Urgency can push you to act before checking. Pause and verify the claim independently, especially if the message threatens consequences for waiting.

5. A link’s destination does not match its text

A link can display the name of a legitimate company while leading somewhere else. On a computer, hover over the link to preview its destination without clicking; if the address differs from the destination the message claims, do not open it. On other devices, avoid tapping suspicious links and use the organization’s known website or app instead.

6. It includes an unexpected attachment or download

Do not open an attachment or download software from an unexpected or untrusted email. An attachment or download may expose you to malware or lead to credential theft. If the sender says a file is important, confirm with them using a separate contact method you already trust.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. The greeting or story does not fit

A generic greeting or an unexpected billing claim can be a clue, particularly if the message does not fit your relationship with the sender. But neither a personal greeting nor correct-looking grammar proves legitimacy, and spelling or grammar errors alone do not prove fraud. A familiar logo is not proof either; check the sender and request.

8. It tells you to fix an account or payment through its own link

An email that unexpectedly directs you to update payment information or repair an account through its link should be treated with suspicion. The FTC says legitimate companies will not unexpectedly email or text you with a link to update payment information. Go to the company’s website using a saved bookmark or address you know, or call a number you have independently verified.

What to do with a suspicious email

  1. Do not click, reply, download, or pay. Avoid links and attachments in unexpected messages.
  2. Check the claim outside the email. Open the service’s website using a saved bookmark or an address you already know, or call a known-good number. Do not rely on phone numbers, links, or other contact details supplied in the suspicious message. As the FTC puts it, “If you think the message could be legit, contact the company or bank using a phone number, email, or website you know is real.”
  3. Report and delete it. Report suspected fraud to the FTC at ReportFraud.ftc.gov. The FTC also recommends forwarding phishing emails to reportphishing@apwg.org; then delete the message.
  4. Act quickly if you shared information. Visit IdentityTheft.gov for recovery steps tailored to the information exposed. If a link or attachment may have downloaded harmful software, update your security software and run a scan.

Reduce the damage if a password is stolen

Turn on multi-factor authentication (MFA) for accounts that support it. The FTC says MFA makes it harder for scammers to log in even if they obtain your username and password. A physical security key is one possible authentication factor where supported; compatibility depends on the account and device, so it is not a requirement for spotting phishing.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What phishing figures do—and do not—show

The FTC reported in 2025 that email was the top method scammers used to contact people in 2024. That describes contact methods reported for 2024; it is not a current-year rate or the share of all phishing. Google said on October 2, 2024, that Gmail blocks over 99.9% of phishing emails. That is Google’s claim about Gmail’s own protection, not an independent comparison or a measure of all phishing attempts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.