Know Phishing

How to Spot a Phishing Email Before You Click

Phishing emails are designed to make you react before you think. Learn the warning signs that matter most, what to check before clicking a link, and what to do when a message just doesn't feel right.

Phishing emails are fake messages designed to trick you into clicking a dangerous link, opening a harmful attachment, sending money, or giving away information such as your password or credit card number.

The difficult part is that many phishing emails no longer look obviously fake. A message may use a familiar company name, a convincing logo, good spelling, and even information that seems personal to you. Instead of trying to memorize every scam, it is much more useful to develop a few simple habits that help you slow down and check a message before you act.

1. Start with the sender, not the logo

A familiar logo does not prove that an email came from the company shown in the message. Logos and company names are easy for scammers to copy.

Look closely at the actual email address. A scammer may use an address that looks similar to a legitimate one but contains an extra letter, an unusual word, or a different domain ending.

Example: A message may display “Account Support” as the sender name while the actual address belongs to an unrelated domain.

If the sender's address does not match the organization that supposedly sent the message, treat the email as suspicious.

2. Be suspicious when a message creates urgency

Scammers want you to act quickly because careful thinking works against them. Common pressure tactics include warnings that your account will be closed, a payment failed, a package cannot be delivered, or suspicious activity was detected.

Urgency does not automatically mean a message is fraudulent. It does mean you should slow down.

Instead of using the link in the email, open the company's app or type the website address into your browser yourself. If there really is a problem with your account, you can usually see it after signing in normally.

3. Check links before clicking

The words displayed in a link can say one thing while the link itself sends you somewhere completely different.

On a computer, place your mouse pointer over a link without clicking it. Your browser or email program will usually show the destination. On a phone or tablet, be especially cautious with unexpected links because checking the destination can be less obvious.

Look for misspellings, strange domains, shortened addresses, or a website name that does not match the company mentioned in the email.

Safer habit: When an email says you need to check an account, go directly to the company's website or official app instead of following the email link.

4. Treat unexpected attachments carefully

An unexpected invoice, receipt, document, voicemail, shipping notice, or shared file can be used to deliver malware or lead you to a fake sign-in page.

Before opening an attachment, ask yourself three questions:

If the answer to any of those questions is no, verify the message another way before opening the file.

5. Watch for unusual requests

Be cautious when an email unexpectedly asks for a password, verification code, banking information, gift cards, cryptocurrency, wire transfers, or other sensitive information.

A particularly important rule is to never give someone a one-time security code simply because they contacted you and asked for it. Those codes are designed to prove that you are the person signing in.

6. Do not rely only on spelling and grammar

Poor spelling used to be one of the easiest phishing warning signs. It can still be useful, but it is no longer enough.

Modern scammers can create polished messages that sound professional and natural. A perfectly written email can still be fraudulent. Pay more attention to the sender, the request, the destination of links, and whether the message makes sense.

A 30-second phishing check

Before clicking a link, opening an attachment, sending money, or entering a password, quickly check the following:

If something does not add up, do not use the email to investigate the email.

What to do instead

Contact the organization through a method you already trust. Open its official app, type its known website address into your browser, use a phone number printed on your card or statement, or contact the person through a separate message.

If the email really came from them, taking an extra minute to verify it will not hurt. If it is a phishing attempt, that minute may prevent an account takeover, financial loss, or malware infection.

If you already clicked

Clicking a suspicious link does not always mean your account has been compromised, but take the situation seriously. If you entered a password on a suspicious page, change that password using the legitimate website or app. If you reused that password elsewhere, change it on those accounts too.

Turn on multi-factor authentication where it is available. If financial information was involved, contact the bank or card provider using a trusted phone number. Keep an eye on the affected accounts for activity you do not recognize.

The Know Phishing takeaway

The best defense against phishing is not recognizing every possible scam. It is building a habit of verification.

Pause. Check the sender. Avoid unexpected links. Verify important requests another way.

Those few steps can stop many phishing attacks before they ever get started.