How to spot a phishing email in 30 seconds

You do not need to be technical to catch most phishing emails. Five questions, asked in order, cover the tricks that work most often.

Updated 24 September 2026 · 5 min read

The short version

  • Check the sender's real address, not the display name.
  • Pressure plus a request (sign in, pay, open, reply with details) is the pattern to stop on.
  • Unexpected attachments are a bigger risk than links.
  • Verify through a channel you already trust, never through the email itself.

Five questions to ask

  1. Who really sent it?

    Click or tap the sender name to see the full address. A display name of Northbank Support can sit on any address. Also check the reply-to address: replies going somewhere else is a warning sign.

  2. Is it pushing you to act now?

    Account suspended, payment failed, final notice, only 24 hours left. Real organisations rarely threaten you with a deadline in an email.

  3. Where do the links really go?

    Hover or press and hold each link before clicking, and read the domain as described in How to check a link before you click.

  4. Did you expect this attachment?

    Invoices, delivery notes, voicemails and scanned documents you did not ask for are the classic delivery route for malware. Be most careful with .html, .zip, .iso and .exe files, documents that ask you to enable editing or macros, and PDFs with a QR code or a single big button.

  5. What does it want from you?

    A password, a one-time code, a payment, gift cards, new bank details for a supplier or your personal documents. Any of these, arriving by email, deserves a check through another channel.

Why a clean-looking email can still be fake

Email checks such as SPF, DKIM and DMARC confirm that a message really came from the domain it claims. A scammer who registers a lookalike domain passes those checks for their own domain. A pass tells you who sent it, not whether you should trust them.

At work, the costliest version is a real-looking message from a supplier or a manager asking to change bank details or pay urgently. Always confirm payment changes by calling a number you already have on file.

What to do with a suspicious email

  • Do not reply, click, or open attachments.
  • Check the claim yourself: open the company's app or type its address, or call a number you already know.
  • Report it: at work, use your report-phishing button or tell IT; in personal email, use your provider's report as phishing option.
  • Scan any link you are unsure about, using the box below.
  • If you already clicked or typed something, follow I clicked a phishing link: what to do now.

Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.

Live product launcher
Paste a suspicious URL or domain, then continue in the live platform

Questions people ask

The email has my name and real details in it. Does that make it genuine?
No. Names, addresses and even order numbers leak in data breaches and are reused in phishing to look convincing.
Is it dangerous just to open a phishing email?
Reading it in an up-to-date mail app is generally low risk. The danger is in clicking links, opening attachments, replying with information, or acting on what it asks.