How to spot a phishing email

Most phishing gets through not because it is clever but because it is read quickly. Slowing down on four things catches the large majority of it, and none of them need a security team — just a habit.

Read the sender address, not the sender name

The display name on an email is free to set to anything. "IT Support" or a colleague’s name tells you nothing; the address behind it does. Expand it and read the full domain, right to left: the part just before the first single slash or the end is the real one.

Lookalike domains are the common trick — a company name on the wrong domain, an extra word, a swapped letter, or a public mailbox where a corporate one belongs. If the domain is not exactly the organisation’s own, treat everything else in the message as unverified.

Check where a link actually goes before you click

Hover over a link, or press-and-hold it on a phone, and read the address that appears. The visible text and the real destination are independent; a button that says the bank’s name can point anywhere.

Apply the same domain check to the link as to the sender. A message from a plausible address that sends you to an unrelated domain to "confirm" something is the pattern to distrust.

Weigh the request, not the design

Phishing imitates the look of a real notice well, so the logo and layout prove nothing. Judge what is being asked instead. Genuine senders do not ask you to confirm a password by email, to move a payment to a new account on short notice, or to act outside the normal channel because "the usual system is down".

When a request is unusual, verify it through a route you already trust — a saved number, the real site typed by hand, a word with the person — rather than any contact detail the message itself provides.

The pressure is the tell

Urgency, secrecy and a threatened consequence are the engine of nearly every scam: an account closing today, an invoice overdue, a manager who needs this done quietly and now. The pressure exists to stop you doing exactly the checks above.

Treat a sudden deadline or a request for discretion as a reason to slow down, not speed up. A real deadline survives a two-minute verification; a fake one is built to not.

Practise the reflex

Recognising phishing is pattern recognition, and pattern recognition comes from volume. Phishing Hunt deals you genuine and fake messages one after another and tells you, after each, what gave it away — so the checks above become something you do without thinking.

← All guides