How to Recognize Phishing Emails Before You Click

Phishing emails are designed to steal passwords, payment details, or personal information by creating fear, urgency, or curiosity. This guide explains how to inspect the sender, links, attachments, language, and login requests before deciding whether a message is legitimate.

Phishing emails often look convincing.

They may copy the logo of a bank, delivery company, online store, cloud service, or government agency. Some messages even include your name, order details, or the name of a company you regularly use.

The safest approach is not to judge an email by its appearance. Instead, inspect how the message asks you to act.

1. Check the Full Sender Address

The sender’s display name can be easily changed.

An email may appear to come from:

Microsoft Security Team

But the real address may be:

security-alert@example-mail-service.com

Expand the sender details and inspect the complete email address.

Look for:

  • Misspelled company names
  • Extra words or numbers
  • Unfamiliar domains
  • Free email services used for official business
  • Characters that resemble other letters

A company name in the display field does not prove that the message came from that company.

2. Be Suspicious of Urgency

Phishing messages often try to prevent careful thinking.

Common warnings include:

  • Your account will be closed today
  • A payment failed
  • Your password expires immediately
  • Suspicious activity was detected
  • A package cannot be delivered
  • You must verify your identity now

Legitimate companies may send urgent notifications, but you should still verify them independently.

Open the company’s official app or type its website address directly into your browser instead of using the email link.

3. Inspect Links Before Clicking

On a computer, move the cursor over a link without clicking it. The real destination should appear near the bottom of the browser or email window.

On a phone, press and hold the link to preview it.

Check whether:

  • The domain belongs to the real company
  • The spelling is correct
  • Unnecessary words appear before or after the company name
  • The address uses an unrelated URL-shortening service
  • The link leads to a file rather than a normal webpage

For example:

accounts.google.com may be legitimate.

google-account-security.example.com is controlled by example.com, not Google.

Read domains from right to left. The important registered domain is usually the part directly before .com, .org, .net, or another domain ending.

4. Do Not Trust the Lock Icon Alone

A lock icon means the connection to the website is encrypted.

It does not mean the website is honest.

Phishing websites can also use HTTPS and display a lock icon.

Always confirm the domain name before entering:

  • Passwords
  • Payment details
  • Recovery codes
  • Personal identification
  • Security answers

Encryption protects the connection, not the intentions of the website owner.

5. Be Careful With Attachments

Unexpected attachments can contain malicious software.

Common risky file types include:

  • Executable files
  • Compressed archives
  • Script files
  • Documents requesting macros
  • Password-protected archives
  • Files with double extensions

A file named:

Invoice.pdf.exe

is not a PDF. It is an executable program.

Even familiar document formats can be dangerous if they ask you to enable editing, activate macros, or install additional software.

Before opening an attachment, confirm with the sender through another communication channel.

6. Look for Unusual Requests

Be suspicious when an email asks you to:

  • Share a password
  • Send a verification code
  • Purchase gift cards
  • Transfer money urgently
  • Change payment details
  • Install remote-access software
  • Scan a QR code to log in
  • Download a security certificate
  • Provide personal documents

Legitimate support staff should not ask for your full password or multi-factor authentication code.

A verification code is intended to prove that you control the account. Anyone asking you to send it may be attempting to log in as you.

7. Notice Changes in Normal Business Procedures

Business phishing often imitates managers, suppliers, or finance departments.

The message may request:

  • A new bank account for payments
  • An urgent invoice
  • Confidential employee information
  • A large transfer
  • A change to payroll details

Do not approve unusual financial requests based only on email.

Verify the request using:

  • A known phone number
  • An internal messaging platform
  • An existing supplier contact
  • A face-to-face conversation
  • A formal approval process

Do not use the phone number included in the suspicious email.

8. Review the Language and Formatting

Poor grammar is no longer a reliable way to identify phishing. Modern scam emails may be professionally written.

However, warning signs can still include:

  • Unusual greetings
  • Inconsistent branding
  • Different fonts
  • Low-quality logos
  • Unexpected tone
  • Strange punctuation
  • Language that does not match previous messages
  • A signature that lacks normal contact details

The strongest signal is often not one mistake but several unusual details appearing together.

9. Be Careful With QR Codes

Some phishing emails use QR codes instead of clickable links.

The code may lead to a fake login page designed for mobile users.

Before scanning:

  • Ask why a QR code is necessary
  • Verify the sender
  • Preview the destination when possible
  • Avoid entering credentials on the opened page
  • Use the official app instead

QR codes hide the destination more effectively than visible links, which makes them attractive to scammers.

10. Use a Password Manager

A password manager can reduce phishing risk because it normally fills credentials only on the correct domain.

If the password manager does not recognize a login page, stop and inspect the address.

Do not manually copy the password into an unfamiliar page simply because autofill did not work.

Use a unique password for every important account. Password reuse allows one stolen password to compromise several services.

11. Enable Multi-Factor Authentication

Multi-factor authentication adds protection after the password.

Strong options include:

  • Authentication apps
  • Hardware security keys
  • Passkeys
  • Device-based confirmations

Text-message codes are generally better than using only a password, although they may be less secure than other methods.

Never approve a login request you did not initiate.

Repeated unexpected authentication prompts may mean someone already knows your password.

12. Verify Through an Independent Channel

When a message seems suspicious, do not reply directly.

Instead:

  1. Open the official app.
  2. Visit the website through a saved bookmark.
  3. Call a verified customer-service number.
  4. Contact the sender using an existing conversation.
  5. Ask your company’s security team.

This separates the verification process from the suspicious message.

13. What to Do After Clicking

Clicking a phishing link does not always mean your account has been compromised.

The next steps depend on what happened.

If You Only Opened the Page

Close it and run a security scan if the page downloaded anything.

If You Entered a Password

Change the password immediately from a trusted device.

Also change it anywhere else you reused it.

If You Shared a Verification Code

Sign out of other sessions, change the password, and review account activity.

If You Entered Payment Details

Contact the bank or card provider immediately.

If You Installed Software

Disconnect the device from the internet and seek technical support.

Act quickly. Delaying gives attackers more time to use the information.

14. Report the Message

Reporting phishing helps email providers and organizations block similar attacks.

Use the email service’s:

  • Report phishing
  • Mark as spam
  • Report suspicious message

Employees should also forward suspicious messages to their internal security team using the company’s approved reporting method.

Do not forward dangerous attachments casually to coworkers.

A Simple Phishing Checklist

Before clicking, ask:

  • Is the sender address correct?
  • Was I expecting this message?
  • Is it creating unnecessary urgency?
  • Does the link use the official domain?
  • Is the attachment expected?
  • Is it asking for passwords or codes?
  • Is the request different from normal procedure?
  • Can I verify it independently?

When several answers raise concern, stop interacting with the message.

Final Thoughts

Phishing succeeds because people are rushed, distracted, or worried.

The most reliable defense is to slow down.

Check the full sender address, inspect links, avoid unexpected attachments, and verify urgent requests through another channel.

A message that is genuinely important will still be important after you spend two minutes confirming that it is real.