Most phishing emails give themselves away within the first ten seconds — if you know exactly where to look. The trouble is most people were trained to look in the wrong place: at how the message reads, rather than at what it’s actually asking you to do and where its links really go. This is the practical checklist. For the bigger picture on why these messages have gotten so much harder to eyeball at a glance, see our companion piece on AI phishing — this guide is the concrete, checkable version you can run on any message that lands in your inbox.
The checklist: run through these in order
1. Check the actual sender address — not the display name
Display names are free to fake. An email can say “Netflix Support” or “Your Bank” while the address behind it is nothing of the sort. Tap the sender’s name on mobile or hover over it on desktop to expand the real address, and read it carefully. What you’re looking for:
- An extra word or phrase tacked onto the real domain (
security-alerts.yourbank-support.cominstead of your bank’s actual domain). - A hyphen, number substitution, or slightly different ending (
.netor.cowhere the real company uses.com). - A free consumer email address (Gmail, Outlook) claiming to be a company that would never send official mail from one.
This single check catches a large share of phishing attempts before you need to read another word of the message.
2. Read for manufactured urgency
“Your account will be suspended in 24 hours.” “Unusual sign-in — verify now.” “This payment must be sent today.” Pressure is the universal phishing ingredient because it’s designed to make you act before you’d normally stop and check. Real organizations rarely demand speed; scammers almost always do, because urgency is what stops you from doing steps 1 and 5 on this list.
3. Watch for requests you should never get
No legitimate company will ask you to:
- Email or type your password into a message.
- Read a one-time verification code out loud or paste it somewhere.
- Pay an invoice, fee, or “fine” using gift cards or cryptocurrency.
- “Confirm” your full card number or government ID by replying.
If a message asks for any of these, the checklist is already over — it’s phishing.
4. Notice a generic greeting on a message that claims to be personal
“Dear Customer” or “Dear Valued User” from a company that supposedly has your account details and knows your name is a mismatch worth pausing on. It’s not a guarantee either way (some legitimate mail is genuinely generic, and some phishing is now personalized with real scraped details), but paired with any other flag on this list, it adds up.
5. Hover over links before clicking
This is the check most people skip, and it’s one of the most reliable. On a computer, hover your mouse over any link without clicking — most email clients and browsers show the actual destination address in a small preview at the bottom of the window. On a phone, press and hold the link to see the same preview. Compare that real destination to what the link text claims and to the company the message says it’s from. A “Verify your account” button that resolves to some unrelated domain is the whole story right there.
6. Treat unexpected attachments as suspect
An invoice, shipping notice, or “important document” you weren’t expecting — particularly paired with an urgent subject line — is one of the most common ways malware actually gets onto a device. Don’t open it. If it might be genuine (a vendor you do business with, say), verify with that sender through a separate channel — a phone number you already have, not one in the email — before opening anything.
7. Question anything too good to be true
A surprise refund, an unclaimed prize, or a deal so good it doesn’t make sense — arriving without you having done anything to trigger it — is bait. Legitimate windfalls are rare and don’t usually require you to click a link and log in to claim them.
8. Verify independently, then report or delete
If a message trips one or more of the flags above: don’t click anything in it, don’t reply, and don’t call any phone number it provides. Instead, go to the company the way you normally would — a saved bookmark, the app on your phone, or a number you already have on file — and check there directly. If something’s genuinely wrong, it’ll be waiting for you. Once you’ve confirmed it’s phishing, use your email provider’s “report phishing” option and delete the message.
What to do if you already clicked or entered something
Clicking a link by itself usually isn’t the dangerous part — what you do on the page it opens is. If you clicked but didn’t type anything in, close the tab and move on; run a security scan if you also downloaded a file. If you entered a password, a code, or any personal details on that page, treat it as a real exposure and act quickly: change the password on the genuine site immediately, change it anywhere else you reused it, and check the account for sessions or changes you didn’t make. We walk through that recovery process in full, in order, in what to do if your data was leaked — and our afternoon account-security plan covers building the defenses (password manager, two-factor, passkeys) so a single mistake like this can’t cascade into your whole digital life.
How a password manager backs you up when you miss something
Even careful people get fooled occasionally — the good fakes are built by professionals. This is where a password manager earns its keep beyond convenience: it autofills your saved login only on the exact domain it was saved for. On a lookalike phishing page, even one that looks pixel-perfect to your eyes, the manager simply won’t offer to fill anything, because the domain doesn’t match. That silence is a real, structural warning worth heeding — if your manager stays quiet on a page you expected it to fill, stop and check the address bar before typing your password anywhere.
1Password
Autofill that refuses to work on fake domains is a genuine anti-phishing backstop, not just a convenience — worth having before you need it.
Locking down your email account matters just as much, since it’s the account phishing recovery ultimately runs through — a privacy-first provider with strong account security is worth considering if you’re rebuilding your setup after a scare.
Proton
Encrypted email from a provider that isn't built around scanning your inbox for ad targeting — a solid foundation if you're tightening things up after a phishing attempt.
A note on grammar and “looking sketchy”
Older advice leaned hard on bad grammar, typos, and clumsy formatting as tells. Those still show up occasionally, but AI writing tools have made fluent, polished phishing messages cheap to produce, so a clean, professional-looking email is no longer evidence of anything either way. Don’t drop this check entirely, but don’t rely on it — the sender address, the links, and what the message is asking you to do are the checks that still work regardless of how well-written the bait is. Our companion guide on AI phishing covers why that shift happened and what’s changed in more depth.
Common mistakes
- Trusting the display name. It’s the easiest part of an email to fake and the first thing scammers get right — always expand the actual address.
- Clicking to “check” if a link is legitimate. Hover or long-press instead; clicking is exactly the action the message wants from you.
- Assuming a well-written message must be real. Polish stopped being a reliable signal once AI made fluent writing free.
- Replying to ask “is this real?” — this confirms your address is active to a scammer. Verify independently instead, through a channel you already trust.
- Delaying the password change after a mistake. If you entered credentials on a fake page, change that password immediately — every minute of delay is a minute an attacker can use it.
The bottom line
Phishing hasn’t changed what it needs from you — a password, a code, a payment, or a click — it’s only gotten better at asking. Run the checklist: the real sender address, urgency language, the ask itself, the greeting, and where the links actually go. Verify independently before you ever act inside the message, and let a password manager’s silence on a fake domain catch what your eyes might miss.
This checklist is part of our Privacy & Security Kit. For the deeper “why” behind these tactics, read AI phishing; if you’re rebuilding your defenses from scratch, start with the afternoon account-security plan; and if a breach or phishing attempt already happened, what to do if your data was leaked covers recovery in full. The whole toolkit — password manager, email, and more — is bundled in the Digital Lockdown Kit.