The Advice That Stopped Working
For twenty years the guidance was "look for bad spelling." It was decent advice once. It is now close to useless.
Modern phishing is well written, correctly branded, and often sent from infrastructure with valid security records. The typo-ridden Nigerian prince is not gone, but he is no longer the threat — he is the bottom of the market. The messages that catch competent people look exactly like the real thing.
So the useful question is not "does this look wrong." It is "what is this message trying to make me do, and how fast."
The Only Rule You Really Need
Before the detail, here is the single habit that defeats almost all of it:
Never take action through a link in an email about your account.
If a message says your password expired, your payment failed, your account is suspended, your package is held, your storage is full — close it. Open a new tab. Type the company's address yourself, or use your own bookmark or their app. If the problem is real, it will be there when you log in.
That is it. That one habit means it does not matter how convincing the email was, because you never interacted with it. Everything below is for the cases where you want to understand what you are looking at.
The Signals That Still Work
1. Urgency with a deadline
"Within 24 hours." "Your account will be permanently closed." "Immediate action required."
This is the most reliable signal there is, because it is structural rather than cosmetic. The whole attack depends on you acting before you think. Real companies do occasionally send time-sensitive mail, but they rarely threaten permanent loss on a countdown.
When you feel the small jolt of panic, that is the moment to slow down. The feeling is the payload.
2. The link text does not match the destination
Hover over a link — on a phone, press and hold — and the real destination appears. Compare it to what the text claims.
Watch specifically for the domain immediately before the first single slash. That is the real site. Everything else is decoration:
paypal.com.security-check.info/login— this is security-check.info, not PayPal.secure-appleid.com— not Apple. Apple isapple.com.microsoft-support.help— not Microsoft.
Attackers rely on you reading left to right and stopping at the brand name you recognise.
3. An attachment you did not ask for
Unexpected attachments are one of the strongest signals left. Particular caution for:
.zip,.rar,.7z— used to hide the real file type from scanners.htmlattachments — a fake login page that opens locally, so there is no suspicious URL to inspect- Office documents asking you to "enable macros" or "enable editing to view" — that prompt is the attack
.iso,.img— increasingly common because they bypass some download protections
An invoice from a company you have never bought from is not a mistake. It is bait, and it works because people open it to find out what they are being charged for.
4. It asks for something no company asks for
No legitimate organisation will ever email asking for your password, your full card number, a one-time code, or a photo of your ID sent as a reply.
The one-time code request is worth calling out. A common attack is: the attacker already has your password, triggers a real login, and then messages you pretending to be support asking you to "confirm the code we just sent." The code is genuine. Reading it out hands them the account.
Never share a verification code with anyone, through any channel, for any reason. No exceptions, no matter who they claim to be.
5. Slightly wrong context
The strongest signal, and the hardest to teach, is a small mismatch:
- A shipping notice for something you did not order
- A password reset you did not request
- An invoice from a supplier you do not use
- A file share from a colleague who never shares files that way
- A bank alert from a bank you do not bank with
That last one catches surprisingly many people, because a moment of confusion is enough to make them click "check this".
The Signals That No Longer Work
Believing these gives false confidence, which is worse than no rule at all:
- "It has a padlock, so it's safe." HTTPS certificates are free and automatic. Essentially all phishing sites have one. The padlock means the connection is encrypted, not that the site is honest.
- "The logo looks right." Logos are copied from the real site in seconds. Many phishing pages load images directly from the genuine servers.
- "The sender address looks correct." Display names are freely chosen, and the visible address can be spoofed. Plenty of phishing arrives from genuinely compromised accounts at real companies.
- "It was in my inbox, not spam." Filters are good, not perfect. Targeted phishing is specifically designed to pass them.
- "There were no spelling mistakes." The days when this filtered attacks are over.
Types Worth Recognising
Bulk phishing
Millions of identical messages impersonating a large brand. Low effort, low success rate, enormous volume. Your spam filter catches most of it.
Spear phishing
Targeted at you specifically, using real details — your employer, your manager's name, a project you are on. Often assembled from LinkedIn and a breach. Far more convincing and far more dangerous.
Business email compromise
The costly one. An attacker gets into a real mailbox, watches the conversation for weeks, then sends a genuine-looking payment request at exactly the right moment — usually changed bank details on a real invoice.
The defence is procedural rather than technical: verify any change of payment details by phone, on a number you already had. Never one supplied in the email.
Clone phishing
A copy of a real message you already received, resent with the links swapped. It passes the "have I seen this before" check because you have.
If You Think You Clicked
Act quickly and in this order. Speed matters more than certainty:
- Did you enter a password? Change it now on the real site, and anywhere you reused it. Start with your email account.
- Turn on two-factor authentication if it is not already on. This alone stops most account takeovers, even with a stolen password.
- Check for changes. Look at recovery email, phone number, and forwarding rules. Attackers add a hidden forward so they keep reading your mail after you change the password. This step is skipped constantly and it is the one that leaves them inside.
- Did you enter card details? Call your bank. Ask for the card to be reissued rather than waiting to see if anything happens.
- Did you open an attachment? Run a scan, and if it was a work device, tell your IT team immediately. They would far rather hear early.
- Did you only click, and nothing else? Usually fine. Change the password anyway if you are unsure.
Nobody sensible will judge you for this. Phishing works on careful people — that is the entire point of the industry built around it.
Reducing How Much Reaches You
Phishing needs your address. The fewer places it sits, the less arrives:
- Give your real address to a short list of organisations that genuinely need it.
- Use an alias for shops and services, so a leak from one is traceable and switchable.
- Use a temporary address for one-off signups you will never log back into, so it never joins a list at all.
- Report phishing rather than deleting it. That feeds the filters protecting everyone.
Common Questions
Is it dangerous just to open an email?
Almost never on a modern client. Risk comes from clicking links, opening attachments, or enabling content. One caveat: remote images confirm your address is live, which is why many clients block them by default. Leave that setting alone.
How do they know my name and where I shop?
Data breaches, mostly. When a retailer leaks its customer list, the buyer knows you shopped there. That is why breach-themed phishing arrives shortly after a company is compromised.
Can I get in trouble for reporting a false alarm?
No. Security teams want the false positives. The cost of checking a harmless email is minutes; the cost of an unreported real one can be enormous.
Are text-message and phone versions the same thing?
Yes, and the same rule applies. Do not act on a link in a text. Do not trust caller ID, which is trivially faked. Hang up and call back on a number you already had.
The Short Version
Never act through a link in an email about your account — navigate there yourself. Treat urgency as a warning rather than a reason to hurry. Check the domain before the first single slash. Never share a verification code with anyone. Verify payment changes by phone.
Those five habits cost nothing and defeat nearly everything.
