Skip to the article
Mail, box and post

What Is a Phishing Email (and How to Spot One)?

Filed
Length
4 min
In this page (6)
  1. Common forms of phishing
  2. The warning signs
  3. Real message or phishing? A comparison
  4. A safe habit that beats most tricks
  5. What to do if you have already clicked
  6. Making yourself a harder target

A phishing email is a message designed to look as if it comes from a trusted sender, such as a bank, a delivery company, a colleague or a familiar online service, so that you take an action that benefits the attacker. That action might be typing a password into a fake page, opening an infected attachment, paying a bogus invoice or simply replying with information that helps a later scam.

The name comes from "fishing": the sender casts a lure and waits to see who bites. Some campaigns go out to huge lists at once; others are carefully tailored to one person or one company.

Common forms of phishing

  • Mass phishing — generic messages about locked accounts, failed deliveries or prize wins, sent to as many addresses as possible.
  • Spear phishing — messages aimed at a specific person, using details such as their job title, colleagues' names or recent projects to seem genuine.
  • Business email compromise — an email that appears to come from a manager, supplier or client and asks for an urgent payment or a change of bank details.
  • Credential harvesting — a link to a convincing copy of a login page that records whatever you type.
  • Malicious attachments — documents, archives or invoices that try to install unwanted software when opened.

The same tricks increasingly arrive by text message, chat apps and phone calls, but email remains a favourite because it is cheap and easy to disguise.

The warning signs

The sender does not quite match

Display names are easy to fake. Check the actual address behind the name. Look for misspelled company names, extra words or numbers, or a free email service used for something that claims to be official. Remember that a genuine address can still be abused if an account has been taken over, so a correct sender is not proof on its own.

The message pushes you to hurry

"Your account will be closed today." "Payment overdue, act now." Pressure is the most reliable signal of all, because it is designed to stop you thinking. Genuine organisations rarely demand action within minutes.

The link goes somewhere unexpected

On a computer, hover over a link without clicking to see where it really points. On a phone, press and hold. Watch for addresses that look close to a real one but are not, or that place the familiar brand name inside a longer, unrelated domain.

It asks for something unusual

Requests for passwords, verification codes, gift cards, remote access or a change of bank details deserve suspicion every single time. A real bank or employer will not ask you to read out a one-time code that was sent to you.

The details feel slightly off

Odd greetings, a logo that looks stretched, an invoice for something you never ordered, or a tone that does not match how a colleague normally writes. Polished messages exist too, so do not rely on spelling mistakes alone.

Real message or phishing? A comparison

Usually genuineOften phishing
Addresses you by name and refers to something you expectGeneric greeting or unexpected subject
Tells you to log in through the app or the address you already useAsks you to click a link to "verify" or "unlock"
Gives you time to respondSets a short deadline or threatens consequences
Never asks for passwords or codesRequests credentials, codes or payment changes

A safe habit that beats most tricks

When an email asks you to do something important, do not use anything inside the message to do it. Open the app or type the website address yourself. If a colleague or supplier asks for a payment change, call them on a number you already have, not one in the email. This single step defeats the majority of phishing attempts, however convincing they look.

What to do if you have already clicked

  1. Do not panic, but act quickly. Close the page and do not enter anything further.
  2. Change the password for the account involved, and anywhere else you used the same one.
  3. Turn on two-step verification if it was not already active, and sign out of other sessions.
  4. Tell your IT team or employer straight away if it happened on a work device or account.
  5. Contact your bank using the number on your card if any payment details were shared.
  6. Report the message using your email provider's report option so others are protected.

Making yourself a harder target

Phishing works best against accounts with reused passwords and no second sign-in step. The broader habits in our guide to protecting your privacy online reduce the damage even if a lure does slip past you. For a look at how similar tricks appear around streaming services and apps, see our piece on security challenges in IPTV streaming.

Above all, give yourself permission to slow down. A few seconds of doubt costs nothing; a rushed click can cost a great deal.

Other pages in Technology