phishing

How to Spot a Phishing Email Before You Click

The click you can't take back

A phishing email is not trying to convince you over a leisurely read. It is trying to get one reflex out of you — a tap on a link, an opened attachment, a password typed into a box — before the sceptical part of your brain has woken up. That is the whole design. Everything in the message, from the alarming subject line to the countdown to the "verify now" button, exists to shrink the gap between reading and reacting to nothing.

So the skill worth having is not spotting a scam after it has emptied your account. It is recognising one in the ten seconds before you click. The good news is that phishing leaves fingerprints in predictable places: the true sender address, the real destination behind a link, the emotional temperature of the writing, and the specific thing you are being asked to hand over. This article walks through each of those, and finishes with a single habit that catches the messages too polished to fail any of the individual tests.

What a phishing email is really after

Almost every phishing email wants one of three things. It wants your login details, so it sends you to a fake sign-in page that looks exactly like the real one. It wants your money, by persuading you to pay an invoice, a fee or a fine that does not exist. Or it wants to plant something on your device through an attachment or a link, so it can steal more later. Everything else — the branding, the urgency, the plausible story — is scaffolding around one of those goals.

Keeping the goal in mind is a shortcut, because it tells you where to be suspicious. The moment an unexpected email steers you towards typing a password, moving money, or opening a file you did not ask for, you are at the exact point the whole message was built to reach. That is when to slow down, not speed up.

Read the sender, not the name

The friendly name at the top of an email — "Netflix", "HMRC", "IT Support" — is just a label the sender chooses. It proves nothing. Anyone can put "Your Bank" in that field. What matters is the actual address underneath it, and on a phishing email the two rarely survive close inspection together.

Tap or click the sender name to reveal the full address. A genuine message from a large organisation comes from its own domain — the part after the @ is the company's real website. Fraudsters cannot use that, so they improvise: a lookalike domain with an extra word or a swapped character, a public webmail address dressed up with a company name, or a subdomain trick where the real brand appears early but the true domain is something else entirely, as in [email protected]. The brand you trust is planted early as bait; the domain that really owns the address is the rightmost part, the label sitting at the very end — here refunds-uk.net, not the hmrc slipped in to reassure you. This is the same lookalike-domain sleight of hand as the typosquatting used on fake shopfronts, moved into your inbox.

One caution: a sender address that looks perfectly genuine does not clear the message, because addresses can be spoofed to appear real. A right-looking sender is necessary, not sufficient — which is why the link and the ask still need checking.

The seven tells of a phishing email

No single item below is proof on its own, but they cluster. When an unexpected email trips two or three at once, treat it as hostile until you have verified it through a channel that did not come from the email itself.

| Tell | What it looks like | Why it matters | | --- | --- | --- | | Wrong sender domain | Brand name in the label, odd address behind it | The domain is the hardest part to fake convincingly | | Manufactured urgency | "Account closes in 24 hours", "act now" | Panic is meant to stop you checking | | A vague greeting | "Dear Customer", "Dear user" | A firm that holds your account usually knows your name | | A link that hides its destination | Button or text that masks the real address | The visible words and the true target often disagree | | An unexpected attachment | A "receipt", "invoice" or "voucher" you did not request | Attachments carry malware; real firms rarely need them | | A request for secrets | Password, full card number, one-time code | Legitimate organisations do not ask for these by email | | Slightly-off details | Logo subtly wrong, tone stiff, facts that miss | Copies are close, but rarely perfect |

Greetings and details that miss by an inch

Organisations that hold an account for you generally address you by the name on it. A message that opens "Dear Customer" and claims to be about your specific account is worth a second look, because it suggests the sender is mailing thousands of people and does not actually know who you are. In the same spirit, watch for details that are almost right but not quite: a reference number in the wrong format, a branch that is not yours, a service you have never used. Fraudsters work from templates, and templates cannot know the particulars only your real provider would.

The link is where the truth hides

The single most useful move with any suspicious email is to find out where a link actually goes before you follow it. The text you can see — www.yourbank.co.uk, or a tidy "Verify account" button — is only a label, and it can point anywhere.

On a computer, hover your mouse over the link without clicking and read the real address your browser shows at the bottom of the window. On a phone, press and hold the link until a preview of the destination appears, then let go without opening it. In both cases you are looking at the domain — the core website name — and asking one question: is this genuinely the organisation's own address, or a lookalike with extra words bolted on? A padlock or https:// at the front changes nothing here; as the padlock myth explains, encryption travels just as happily to a criminal's server as to a real one.

If the destination is not unmistakably the real domain, do not open it. And if it is a login page of any kind, the safest response is never to reach it through the email at all — more on that below.

When the writing looks perfect

Old advice leaned heavily on spelling and grammar: real companies proofread, scammers do not. There is still truth in it — genuinely clumsy English in a message claiming to be from a major bank remains a warning. But it is a weaker signal than it used to be. Fraudsters now have access to the same writing tools everyone else does, and a modern phishing email can be flawlessly worded, correctly punctuated and perfectly on-brand.

The lesson is not to relax when the prose is clean. It is to stop treating good writing as reassurance. A polished message that still comes from the wrong domain, still hides its link, and still asks for your password is exactly as dangerous as a badly spelled one — arguably more so, because it disarms the readers who were relying on typos to save them.

The one habit that beats them all

Every check above is useful, but you will not run all of them under pressure, and the best phishing emails are built to pass most of them. So here is the habit that works even when the message is flawless: never resolve an email's demand from inside the email.

If a message says there is a problem with your account, do not use its link, its button or its phone number. Close it. Open the organisation yourself the way you always do — a bookmark you saved, the address typed in by hand, or the official app on your phone — and check whether the alleged problem actually exists. If your bank really needs you, it will be waiting for you when you arrive under your own steam. If the "urgent" issue evaporates the moment you go direct, you have your answer. This one move, applied every time, neutralises phishing regardless of how convincing the email was, because it takes the decision out of the attacker's hands and puts it back in yours. It is the same principle behind refusing to trust an inbound call in a bank impersonation scam: verify on a channel the stranger did not choose.

If you do want to warn others, the National Cyber Security Centre operates a reporting address, [email protected], that accepts forwarded phishing emails and uses them to take fraudulent sites down. Forwarding a suspect message there takes seconds and quietly protects the next person it would have reached.

Before you go

If there is a single idea to carry out of this article, it is that an email is never the right place to settle what the email claims. A message can imitate a sender, borrow a logo, spoof an address and write in faultless English — but it cannot follow you to your own bookmark, your own app, your own typed-in address. The instant you make "I'll check this myself, my way" your default answer to any alarming email, the entire craft of phishing stops working on you, because it was only ever betting that you would stay inside the message.

That is a habit no software can install for you, though software can help once you have made the decision to look. The checker being assembled at CheckAScam is meant to be one place to test a suspicious link before you commit to it — it is still being built, and even finished it will weigh where a link leads, not read a stranger's intentions. The judgement to go direct rather than tap through stays yours, and it is the part that matters most. For the wider picture of how signals like a link's destination get weighed, see how we score.

Frequently Asked Questions

How can I tell if an email is really from my bank?

Do not judge it by the logo or the sender's display name, both of which are trivial to copy. Reveal the full email address and confirm the part after the @ is the bank's genuine domain, then check where any link truly points before following it. Even then, the reliable move is to ignore the email's own links entirely and reach your bank the way you normally do — a saved bookmark, the typed-in web address, or the official app — and see whether the message it describes is really waiting for you there. A real bank never needs you to arrive through a link it emailed you.

What should I do if I already clicked a link in a phishing email?

Clicking alone is less serious than what you might have done next, so retrace your steps calmly. If you only opened the page and closed it, you are likely fine, but stay alert. If you typed a password, change it immediately on the real site and anywhere else you reused it, and switch on two-step verification. If you entered card details, contact your card provider to stop the card and watch for unfamiliar transactions. If you downloaded or opened an attachment, run a security scan on your device. Speed limits the damage, so act as soon as you realise rather than hoping it was nothing.

Are phishing emails always full of spelling mistakes?

Not any more. Poor spelling and clumsy grammar used to be a giveaway and still count as a warning when you see them, but modern phishing is often written cleanly and looks entirely professional, because the tools to produce polished text are now widely available. Judging an email purely on how well written it is has become unreliable. Weigh the harder-to-fake signals instead — the true sender domain, where the links actually go, and whether you are being asked for a password, a payment or a one-time code — rather than trusting a message simply because it reads well.

More From CheckAScam

Want more ways to stay safe?

Browse our full library of plain-English guides — how to spot fake shops, safe ways to pay, and how to get your money back if something goes wrong.

Browse the Guides