Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no dependable writing-style test for AI-generated phishing: polished prose does not prove an email is legitimate, and typos do not prove it is malicious. Judge the sender, the request, whether it fits the situation, and any links or attachments. If something feels unexpected, do not act through the email; verify independently and report it. If you already clicked, shared information, approved a sign-in, or opened a file, contact your IT or security team immediately.

How to tell whether an email may be phishing

AI can make a fraudulent message sound fluent and personal, but the same warning signs matter whether a human or a tool wrote it. Focus on what the message asks you to do and whether the sender and circumstances make sense. A familiar display name, company logo, or convincing tone is not proof of identity.

Examine the request and its context

Pause over requests that involve money, payment-detail changes, passwords, sign-in approvals, sensitive information, unexpected files, or unusual urgency. Ask yourself whether you expected the message, whether the request fits the sender’s normal role, and whether the requested action matches your organization’s usual process. A message can be fraudulent even when it refers to a real project or person.

Check the sender and the destination

Look at the complete sender address and domain, not just the display name. Watch for a lookalike domain or an address that differs subtly from the one you normally use to contact that person or company. If your email program and workplace procedure allow it, inspect a link’s destination without opening it. When in doubt, do not use the link: navigate to the service using a known address or bookmark instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Do not scan a QR code in a suspicious email, open an unexpected attachment, or reply with sensitive information to test whether the sender is genuine. Verify a consequential request using a phone number from an established record or another trusted channel—not contact details provided in the suspicious message. For a work request, ask the colleague or supervisor through a separate known channel.

Do not rely on grammar or an “AI detector”

Awkward wording is not a dependable phishing test, and fluent writing is not a safety signal. The available government guidance does not establish a reliable style-based way to identify AI-written phishing. Language quality alone is weak evidence; assess the request, identity, context, and destination instead.

What to do with a suspicious email

  1. Stop before acting. Do not click, open, scan, reply with sensitive details, or approve a sign-in prompt prompted by the message.
  2. Verify independently. Type a known website address, use an existing bookmark, or contact the supposed sender using a number or channel you already trust. For an unusual business request, confirm it with a colleague or supervisor separately.
  3. Report the original message. Use your organization’s approved report-phishing control or the route provided by IT. Keep the original email available for security staff rather than deleting it; its details can help with tracing and investigation.
  4. Wait for confirmation before proceeding. If the request is legitimate, the sender or your organization can confirm it through the trusted channel. Do not let an urgent deadline in the email override verification.

If you are reporting a suspected scam outside work, the FTC lists reportphishing@apwg.org for forwarding phishing emails and ReportFraud.ftc.gov for reporting fraud. If personal or business data may have been exposed, follow the organization’s incident process and applicable reporting obligations. The FTC advises businesses to alert affected customers when their data was stolen and points affected individuals to IdentityTheft.gov for a recovery plan.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What to do if you clicked, shared information, or opened a file

Tell IT or security promptly, even if you are unsure whether anything happened. Report what you did and when: opened a link, entered a password, approved an MFA prompt, opened an attachment, ran software, sent money, or disclosed information. Include the original message if possible. Quick, factual reporting helps responders determine what systems and accounts may be at risk; it is more useful than waiting to see whether a problem appears.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you entered credentials or approved a sign-in

Tell responders which account was involved and whether you entered a password or approved an authentication request. Follow the organization’s account-recovery instructions to secure the account and change a compromised password. Do not reuse a password that may have been exposed on other services; if it was reused, disclose that to the responders so they can help prioritize affected accounts.

If you opened an attachment or ran a file

Report what you opened and whether you ran or installed anything. If malware may have run, follow your organization’s procedure for isolating the device; the FTC advises disconnecting a device infected with malware. Do not try to investigate or clean a work device on your own if your security team needs to preserve evidence.

Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

If you sent money or disclosed data

Tell your security or incident-response contact what was sent, to whom, and when. For a payment or changed bank details, promptly contact the appropriate finance or payment provider through a known channel and follow your organization’s fraud-response process. If personal or customer information was disclosed, escalate it through the organization’s incident and privacy-reporting procedures.

Small-business response: a practical incident sequence

For a team handling a suspected campaign, assign a responder to coordinate the investigation and keep a record of the message, reports, actions, and timing. Microsoft’s phishing investigation playbook provides a vendor-published sequence; the tools and steps should be adapted to the mail, identity, and endpoint systems your organization actually uses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Preserve and identify the message. Confirm the original email and its Message-ID so responders can distinguish copies and investigate the same message consistently.
  2. Establish scope and delivery. Use the mail system’s trace or equivalent to find when the message arrived, who received it, and whether it was delivered, quarantined, or otherwise handled.
  3. Determine interaction and exposure. Ask affected recipients what they did and when. Establish whether credentials, MFA approvals, devices, payments, or data may be involved.
  4. Check for follow-on activity. Review relevant identity, mailbox, endpoint, and data activity for actions that may have followed the interaction. Microsoft’s anti-phishing tuning guidance also recommends auditing external forwarding rules.
  5. Contain and recover. Remove malicious copies where possible, secure impacted accounts and devices, and follow the organization’s recovery process for any exposed information or payment.
  6. Improve the controls that failed. Review filtering decisions and reporting outcomes, including false positives and false negatives, and adjust detection and prevention controls. In Microsoft environments, investigators can inspect message headers and the Spam Filtering Verdict (SFV) in the X-Forefront-Antispam-Report field to help determine whether filtering was skipped.

Keep the process non-punitive: ask recipients to report exactly what happened, not to conceal a click or delay because they fear blame. A simple reporting route and prompt follow-up make it more likely that the organization can establish scope while the evidence is still useful.

Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What email authentication and filtering can—and cannot—do

SPF and DKIM help check sending infrastructure and message authentication; DMARC checks whether the authenticated address aligns with the visible From address. These controls can help an organization detect spoofing of its own domain, but they do not certify that a request is safe. A lookalike domain can still deceive a recipient, and a message from a compromised legitimate account may come from an address that otherwise appears familiar.

CISA recommends anti-phishing protections and tuning them to the threat. Filtering and authentication are useful layers, but they do not replace independent verification, user reporting, or investigation. For a small business choosing or reviewing mail security tools, compare compatibility with its mail platform, protection against impersonation and malicious links or files, investigation and message-removal workflow, integration with identity and endpoint information, false-positive handling, administrative workload, and whether users have an easy reporting control.

When an AI assistant reads email

This is a separate risk from persuading a human recipient to click. A malicious message may contain instructions aimed at an AI assistant that processes a mailbox, potentially trying to expose mailbox information, distort a summary, misclassify the message, or trigger an unwanted workflow action. Treat assistant access to email as part of the organization’s security design, not as a reason to trust the content the assistant returns.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft documents a prompt-injection detection control in Defender for Office 365. Its guidance, last updated September 8, 2026, describes classification that considers visible and hidden content, forwarded threads, and normalized obfuscated segments alongside existing sender and message signals. Microsoft says detections receive a high-confidence phishing verdict under a prompt-injection detection technology label. It also explicitly cautions that the control is not intended to block every instruction-like phrase or serve as a general-purpose prompt-injection benchmark. This is a product-specific defense-in-depth feature, not a guarantee against malicious instructions.

Microsoft’s Phishing Triage Agent is an AI-assisted analyst tool for reported messages, not a consumer email detector. Its documentation lists Security Copilot capacity, Microsoft Defender for Office 365 Plan 2, and required reporting and role configuration as prerequisites. Analysts can inspect outcomes and provide feedback; classifications should be reviewed rather than treated as infallible. Licensing and availability can change, so organizations should confirm current requirements in Microsoft’s documentation before relying on the feature.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.