That message in your inbox looks official, the logo is familiar, and it says your account will be locked in 24 hours unless you click. Your heart skips, your finger hovers over the link, and that split second is exactly what the scammer is counting on. Phishing emails are built to bypass your judgment by manufacturing panic, and the good news is that almost every one of them carries the same tells once you know where to look. This guide walks you through the checks that security teams at the major mail providers and U.S. cybersecurity authorities all agree on, so you can catch a fake before you ever click.
Why a Slow Second Look Beats a Fast Click
Phishing works on pressure. The attacker wants you reacting with emotion instead of reasoning with evidence, because a calm reader notices the seams. The single most valuable habit you can build is pausing before you act on any email that asks you to do something now.
None of the checks below take more than a few seconds, and you do not need all of them to flag a fake. One clear red flag is usually enough to stop and verify. Run through them as a quick mental checklist whenever an email asks you to click, log in, pay, or download.
Pressure and Threats Are the First Warning Sign
Phishing messages push you to act immediately, demanding that you click, call, or open an attachment right away. They manufacture urgency by claiming a problem with your account, a reward that expires soon, or a penalty if you ignore them.
Microsoft calls this an urgent call to action or threats. CISA describes it as urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately. The FTC frames the defense simply: honest businesses give you time, so resist any pressure to act on the spot.
Check the Sender, Not Just the Display Name
The friendly name shown at the top of an email is easy to fake. What matters is the actual email address behind it, and whether it genuinely matches the organization the message claims to represent. Google advises checking that the email address and the sender name match before you trust anything in the message.
Apple's official guidance lists two specific giveaways. The first is that the sender's email or phone doesn't match the name of the company it claims to be from. The second is that the email or phone they used to contact you is different from the one you originally gave that company.
Look Hard at the Domain
An email claiming to come from a reputable company but sent from an unrelated domain, such as a generic free webmail address or something like microsoftsupport.ru, is probably a scam. Microsoft warns specifically about very subtle misspellings of the legitimate domain name, the kind your eye glides right past.
A common trick is a spoofed domain that swaps or drops a single letter, like amazan.com standing in for a well-known retailer. A single altered letter is all it takes, so read the part after the @ sign character by character when something feels off.
Preview the Link Before You Trust It
The text of a link and where it actually leads are two different things, and a phishing email exploits that gap. Hover your cursor over any link without clicking to preview its true destination. On a phone, press and hold the link to see the same preview.
If the URL that appears doesn't match the link text or the company's real website, it may be leading you to a phishing site. This single check is endorsed by Google, Microsoft, Apple, Yahoo, and CISA alike. Apple frames the warning as a link in a message that looks right, but the URL doesn't match the company's website.
CISA adds one more wrinkle: attackers sometimes use URL shorteners to hide the true destination entirely. If a link is shortened and you cannot see where it actually goes, treat that as a reason to be cautious rather than a reason to click and find out.
Generic Greetings and Sloppy Writing Give Scams Away
A company you actually do business with knows your name. Generic greetings such as "Dear sir or madam," "Dear Valued Customer," or "Sir/Ma'am" are warning signs that the email may not be legitimate. Microsoft, CISA, and the FTC all point to this pattern.
The same logic applies to language quality. Professional companies maintain editorial standards, so obvious spelling or grammatical errors can indicate a scam. Microsoft lists spelling and bad grammar among its core phishing indicators, so let a clumsily written message raise your guard.
Real Companies Don't Ask for Secrets by Email
Legitimate providers do not request passwords, credit card numbers, or other sensitive data through email. This is one of the clearest lines in the sand, and the major providers state it plainly.
Google says Gmail won't ever ask you for personal information, like your password, over email. Yahoo states that it never asks for personal info, such as credit cards or passwords, in emails. Apple lists a message that requests personal information, like a credit card number or account password, as a sign of a scam. If an email asks for any of this, that alone is enough to walk away.
Handle Attachments and First-Time Senders Carefully
Do not open links or attachments in messages you weren't expecting, even if the rest of the email looks plausible. Apple flags messages that are unsolicited and contain an attachment as a warning sign worth taking seriously.
Microsoft points to a related cluster of risks: first time or infrequent senders, senders marked as External, and suspicious links or unexpected attachments. An attachment you didn't ask for from someone you've never heard from deserves extra suspicion, not a curious double-click.
When in Doubt, Verify Through a Channel You Already Trust
Sometimes a message genuinely might be real, and you cannot be sure from the email alone. The safe move is never to use the contact details inside the message itself. Don't click its links or call the phone numbers it provides.
Instead, open a new browser tab and go to the organization's website from a saved bookmark or by typing the address yourself. If you need to call, look up the phone number on the official site rather than the one in the email. The FTC, Microsoft, and CISA all give this same guidance, because it routes you around the trap entirely.
Lock Down Your Accounts Before an Attack Lands
Spotting phishing is one layer; making a stolen password useless is another. Turn on two-factor or multi-factor authentication on your important accounts so that even if a scammer gets your username and password, it is much harder for them to actually get in. Both the FTC and CISA recommend this as a baseline protection.
Think of it as a safety net for the moment your guard slips. No one catches every fake every time, and multi-factor authentication means a single bad click is far less likely to become a compromised account.
Report the Email, Then Get Rid of It
Once you've identified a phishing email, reporting it helps providers and investigators shut the operation down. In Gmail, open the message, click "More" next to Reply, then click "Report phishing."
You can also forward phishing emails to the Anti-Phishing Working Group at [email protected], and in the U.S. report to the FTC at ReportFraud.ftc.gov. Apple takes reports of suspicious emails at [email protected]. Reporting endpoints can change over time, so if an address bounces, check the provider's current help page for where to send reports. After you've reported the message, delete it so you don't accidentally interact with it later.
Frequently Asked Questions
Is it safe to just open a suspicious email without clicking anything?
The risk in phishing comes from acting on the message: clicking links, opening attachments, or replying with personal information. The safest approach is to avoid opening links or attachments you weren't expecting, verify anything questionable through a channel you already trust, and report and delete messages you've confirmed are phishing.
What is the fastest way to confirm a sender is fake?
Check that the actual email address matches the company it claims to be from, and read the domain after the @ sign for subtle misspellings, such as a swapped letter standing in for a legitimate name. Then hover over any link to preview its real destination. If the address, the domain, or the link doesn't line up with the real company, treat the message as a scam.
My email provider has a spam filter, so won't it catch phishing for me?
Filters help, but you should not rely on them to catch everything. Attackers actively work to evade detection, so a phishing message can still reach your inbox without any warning attached. Running through the manual checks in this guide is what protects you when an automated filter misses one.
A message asked for my password and looked official. What should I do?
Do not provide it. Legitimate providers like Google, Yahoo, and Apple state that they never ask for passwords or credit card numbers by email, so any request for that information is a red flag on its own. Don't use the links or numbers in the message; instead go to the company's website yourself from a bookmark or by typing the address, and report the email afterward.
Does turning on multi-factor authentication mean I can stop worrying about phishing?
No, but it adds an important safety net. Multi-factor authentication makes it harder for a scammer to get into your account even if they obtain your username and password, which is why the FTC and CISA recommend it. You should still watch for the warning signs, since the goal is to avoid handing over your information in the first place.