Email Phishing: How to Spot It
Email phishing tricks you into clicking a link, opening an attachment, or replying with information by impersonating people and companies you trust — an overview of the tells.
Think a message like this reached you? You can check it right now.
What this scam is
Phishing emails impersonate banks, tech companies, retailers, government, colleagues, or executives to get you to click a malicious link, open a harmful attachment, log in on a fake page, or reply with sensitive information or a payment. Targeted versions ('spear phishing') use real details about you or your company. Whatever the pretext — a security alert, an invoice, a shared document, a prize — the tells are similar: mismatched addresses, urgency, unexpected attachments, and requests for credentials or money.
What it usually looks like
- An unexpected email urging you to click, open, or reply.
- A sender/reply-to address that's subtly wrong.
- Urgency, threats, or an enticing offer.
- A login page or attachment you're pushed to use.
Common warning signs
- Links whose real address doesn't match the brand.
- Unexpected attachments.
- Requests for logins, payment, or sensitive data.
- Urgency and generic greetings.
Example wording scammers use
“Security alert: verify your account now — [link].”
“Invoice attached, please review and pay.”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- Your credentials, data, or a payment.
- To install malware via attachments/links.
- To exploit trust in known senders.
What to do
- Don't click links or open attachments in unexpected emails; verify via official channels.
- Hover to check link addresses; log in by typing the real site.
- Never reply with credentials, card details, or wire funds on an email request.
- Report phishing to your provider/IT and delete it.
What to do if you already responded
- Change any password entered and enable 2FA; scan your device if you opened an attachment.
- Contact your bank if you shared payment info.
- Report at reportfraud.ftc.gov.