How to spot a phishing email in 30 seconds
You do not need to be technical to catch most phishing emails. Five questions, asked in order, cover the tricks that work most often.
The short version
- Check the sender's real address, not the display name.
- Pressure plus a request (sign in, pay, open, reply with details) is the pattern to stop on.
- Unexpected attachments are a bigger risk than links.
- Verify through a channel you already trust, never through the email itself.
Five questions to ask
Who really sent it?
Click or tap the sender name to see the full address. A display name of Northbank Support can sit on any address. Also check the reply-to address: replies going somewhere else is a warning sign.
Is it pushing you to act now?
Account suspended, payment failed, final notice, only 24 hours left. Real organisations rarely threaten you with a deadline in an email.
Where do the links really go?
Hover or press and hold each link before clicking, and read the domain as described in How to check a link before you click.
Did you expect this attachment?
Invoices, delivery notes, voicemails and scanned documents you did not ask for are the classic delivery route for malware. Be most careful with .html, .zip, .iso and .exe files, documents that ask you to enable editing or macros, and PDFs with a QR code or a single big button.
What does it want from you?
A password, a one-time code, a payment, gift cards, new bank details for a supplier or your personal documents. Any of these, arriving by email, deserves a check through another channel.
Why a clean-looking email can still be fake
Email checks such as SPF, DKIM and DMARC confirm that a message really came from the domain it claims. A scammer who registers a lookalike domain passes those checks for their own domain. A pass tells you who sent it, not whether you should trust them.
At work, the costliest version is a real-looking message from a supplier or a manager asking to change bank details or pay urgently. Always confirm payment changes by calling a number you already have on file.
What to do with a suspicious email
- Do not reply, click, or open attachments.
- Check the claim yourself: open the company's app or type its address, or call a number you already know.
- Report it: at work, use your report-phishing button or tell IT; in personal email, use your provider's report as phishing option.
- Scan any link you are unsure about, using the box below.
- If you already clicked or typed something, follow I clicked a phishing link: what to do now.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- The email has my name and real details in it. Does that make it genuine?
- No. Names, addresses and even order numbers leak in data breaches and are reused in phishing to look convincing.
- Is it dangerous just to open a phishing email?
- Reading it in an up-to-date mail app is generally low risk. The danger is in clicking links, opening attachments, replying with information, or acting on what it asks.
More guides
Fake sign-in pages for Microsoft 365, Outlook and Google are the most common phishing page. How they work, how to tell, and why two-step sign-in is not always enough.
Eight quick checks to tell a real link from a phishing link: see the real address, read the domain the right way, spot lookalikes, and scan it for free.
Clicked a phishing link or typed your password into a fake page? The steps to take right now, depending on what happened, in the order that limits the damage.