loading...
Every year over 191.000 complaints about a phishing email are filed. We show you in easy steps on how to spot a phishing email.
Learn the telltale signs of a phishing email — suspicious sender addresses, urgency tactics, and fake links — before you or someone you love clicks something dangerous.
The clever part of a good phishing email is how little it changes. It copies the real layout, the real colours, the real tone of a company you actually use. Then it alters one small thing that most people never look at, and that one thing is where your login or your card number goes.
Spoofing is how it stays convincing. A phishing email disguises the sender name, the address behind it, or the link it points to, often by changing a single letter, symbol, or number so the fake reads as the real thing (FBI, 2020). Fake versions of trusted sites, including impersonators of official government pages, tend to work exactly the way, by tweaking the domain spelling or swapping the ending so the address looks almost identical to the genuine one (FBI IC3, 2025).
From: NorthPeak Bank <security-northpeakbank.verify-account.net>
Subject: Urgent: Your account access will be suspended
Dear Valued Customer, We detected unusual activity on your account. Your access will be suspended within 24 hours unless you confirm your details. Update your payment information now to avoid interruption.
Verify My Account
Red flags: Real bank name, fake domain — The display name says NorthPeak Bank, but the address behind it is security-northpeakbank.verify-account.net; Generic greeting — Says 'Dear Valued Customer' instead of your real name; Fake deadline — Claims access will be suspended within 24 hours to rush you; Link goes to wrong site — The Verify My Account button leads to the scammer's domain, not the real bank
Spot it: Real bank name, fake domain behind it; generic greeting; fake deadline to rush you; link goes to the wrong site
Avoid it: Clicking the Verify My Account button; trusting the sender display name without checking the address
Knowing how to spot a phishing email comes down to one habit: slow down and check who sent it before you click anything. Every step below is a different way to do that check, and each takes a few seconds on a phone.
Start by looking past the name at the top to find the actual email address it came from. On a phone, press and hold the sender name, or tap it once, and the full address appears. The display name is the easy part to fake, so a message can say NorthPeak Bank at the top and still come from an address that has nothing to do with the bank. Read the part after the @ symbol carefully. The real company's domain is hard to copy exactly, so scammers settle for something close, like a real name stuck in front of a random web address. If the domain looks stitched together or doesn't match the company's real website, treat the whole message as a fake.
A phishing email often starts with a generic greeting like Dear Customer instead of your name, then invents a billing problem to make the account sound at risk, and finishes by inviting you to click a link to update your payment details. A real company that already has your account knows your name and rarely demands money inside a 24-hour window. The greeting tells you they don't actually know you. The invented problem plus the deadline tells you they need you moving before you think. When both show up in one message, you are almost certainly looking at a fake.
If the email looks like it's from a company you do have an account with, contact that company using a phone number or website you already know is important. Never use the link or number printed inside the message. The contact details in a phishing email lead back to the scammer, so calling the number confirms nothing. Type the company's website in yourself, or open its app, and check your account there. If there's a genuine problem, it will show up in your real account. If nothing's wrong, the email was the problem.
A phishing email is after one of three things: your money, your login, or enough of your identity to sell or reuse elsewhere. The account-closing story exists to get you to a fake login page, where the password you type lands in someone else's hands. The billing story exists to get your card number. Either way, the polish is there to make you act before you check, because a message that gives you time to think usually loses.
Your Money Billing stories designed to capture your card number or payment details through urgent fake invoices or account warnings.
Your Login Account-closing tales that push you to a fake login page, where your password goes straight into a scammer's hands.
Your Identity Personal information harvested to sell or reuse elsewhere, building profiles for future fraud or identity theft.
In 2025, phishing and spoofing losses reported to the FBI came to about $216 million across roughly 192,000 complaints.
The same basic trick shows up through more than one channel, and it's worth knowing the names because the defence is identical across all of them. Phishing lands in email, by phone call, by text message, or through code that redirects your device (FBI, 2020). Here are the ones you're most likely to encounter.
Vishing Phishing delivered by voice. Your phone rings with a calm recorded or live voice claiming to be your bank's fraud team, asking you to confirm your card number or read back a code. Hang up, find the bank's number on the back of your card or in its app, and call that instead. A real fraud team is happy to have you call back on a number you trust.
Smishing Phishing squeezed into an SMS. It usually claims a package is held, a toll is unpaid, or your account is locked, with a short link to fix it. Texts feel more personal and urgent than email, and the tiny screen makes the fake link harder to read. Don't tap the link. If you're expecting a package or owe a toll, open the courier's or agency's own app or website and check there.
Pharming A redirect that skips the click entirely. Instead of tricking you into tapping a bad link, it uses malicious code to send your device to a fake site even when you type the real address yourself. Watch for a login page that looks slightly off or asks for more than usual. If a familiar site suddenly wants details it never asked for before, stop and check on another device.
AI has broken the oldest phishing tip there is. For years the advice was to look for typos and clumsy grammar, and that tell is fading fast, because AI now writes clean, fluent, personalised messages at scale. The same tools let scammers spin up fake profiles, clone a familiar voice, and produce convincing fake documents or videos to add pressure (FBI, 2025). The badly written email is on its way out.
Acting quickly limits the damage, and most of this is fixable. How far the message got determines what you do next, so find your situation below and take that one action first.
Clicked the link but typed nothing Close the tab and run a security scan on your device, since some links try to install harmful software on their own.
Entered a password Change that password now on the real site, and turn on the extra login code the account can text you so a stolen password alone isn't enough.
Entered card details Call your bank using the number on the back of your card, report the card as compromised, and ask them to watch for or freeze charges.
Shared your Social Security number, bank, or card information Go to IdentityTheft.gov, which builds a step-by-step recovery plan based on exactly what was exposed (FTC, 2024).
Sent money Contact your bank or the payment service right away and ask whether the transfer can be stopped or reversed.
If the message posed as a company you have an account with, reach that company on a number or website you already know is real, not the one from the email, and check your account directly (FTC, 2024). For a fuller walk-through, see what to do if you clicked a phishing link.
Reporting takes a few minutes and helps the email provider to identify scam emails quickly.
1. Report to the FTC The fastest official route and the one that feeds federal fraud tracking (FTC, 2025). (reportfraud.ftc.gov)
2. File with the FBI's Internet Crime Complaint Center Essential if money or personal information was involved (FTC, 2025). (ic3.gov)
3. Forward to the Anti-Phishing Working Group A coalition of internet providers, banks, security firms and law enforcement (FTC, 2025). (reportphishing@apwg.org)
4. Flag text messages to your carrier If it arrived as a text, forward the message to 7726 (that spells SPAM).
5. Report to the impersonated company Tell the real company the scam impersonated, using the abuse or fraud contact on its actual website, and report it to the bank or platform where anything happened.
6. Talk it through with a person Call the AARP Fraud Watch Helpline at 877-908-3360.
For the full walk-through, see how to report a phishing email.
Sometimes they can tell an email was opened, through a tiny invisible image called a tracking pixel that loads when you open the message. Opening the email doesn't put you at risk on its own; it just tells them the address is live, which can bring more spam. Most phone mail apps block these images by default, and you can leave image loading off in your settings to shut it down. The real danger starts only if you tap a link or open an attachment.
Blocking one email address doesn't stop a scammer, because they send from a fresh address every time and often spoof the sender name so it only looks like the same person. That block filters the one address into a folder or bin, but the next message comes from a new one. This is normal and doesn't mean the block failed. Rather than chasing each address, mark the messages as spam so your mail provider learns the pattern, and report the phishing ones using the steps above.
Replying to a phishing email is not the safe move, even to tell them to stop, because any reply confirms your address is real and being read. A confirmed, active address is worth more to a scammer, so a reply usually brings more messages, not fewer. Avoid responding at all. Mark it as spam, report it if you want to, and delete it. Silence is what actually makes your address less valuable to them.
The better move is to report it first, then delete it, since reporting takes only a minute. Deleting protects you, but reporting helps the FTC and FBI track the campaign and warn others, and forwarding it to your carrier or the Anti-Phishing Working Group feeds the filters that catch the next wave. If you're short on time, forwarding a scam text to 7726 or the email to reportphishing@apwg.org is quick and worth doing. Then delete it.
Most likely your address turned up in a data breach at a company you'd used, and it was later sold or traded in bulk, which is how one address ends up on many scam lists. Addresses also get scraped from public web pages, guessed from common name patterns, or passed along after you replied to an earlier scam. There's usually no single leak to trace. More important is that a scammer having your address doesn't put you at risk by itself; only clicking or replying does.
Clicking a phishing link on an iPhone is lower risk than on a computer, because iPhones limit what a website can install without your permission, but it isn't a free pass. The real danger is the page the link opens, which is often a fake login built to capture whatever you type. If you clicked but entered nothing, you're likely fine; close the tab. If you typed a password or card number, change that password and call your bank now. See what to do if you clicked a phishing link for the full steps.
That account-closing email at the top of this page? Now you know where to look first, which is the address behind the name, not the logo above it. Next time one lands, do that one check before anything else. It takes ten seconds, and it's the whole game.