Phishing is a scam that uses email or text to trick you into giving up personal or financial information. Scammers pose as a company you trust and invent a reason to rush you, hoping you act before you think. This guide shows the red flags with plain examples, how to check a message before you click, and what to do if you already clicked — following official guidance from the FTC, CISA, Google, and Microsoft.

What is a phishing email (and why it works)

Phishing is a form of social engineering — an attack on people, not just machines. Attackers pose as a trustworthy organisation to get you to hand over information, making the message look like a site or service you already use.

Phishing vs. spam vs. smishing vs. vishing

These words are often used interchangeably, but they differ:

  • Spam is the broad category of unwanted email — annoying at best, pushing scams or malware at worst.
  • Phishing is one dangerous type inside that umbrella: a deceptive message that tries to steal your information or break into your accounts.
  • Smishing is phishing sent by text message.
  • Vishing is phishing carried out over a voice call.

All phishing is unwanted, but not all unwanted email is phishing — and the difference matters, because phishing is the kind that actively tries to harm you.

Why scammers impersonate brands you trust

Attackers masquerade as trusted sources to steal sensitive information. They borrow a familiar name, colour, and tone, then add false urgency — a blocked account, a missed payment — so you react on emotion instead of thinking. Borrowed trust plus manufactured pressure drives almost every phishing email.

Infographic of four message types — email phishing, smishing by text, vishing by phone, and spam — with warning icons.

8 warning signs of a phishing email (with examples)

One sign alone is not proof, and a missing sign does not make a message safe. Treat each one as a reason to slow down and verify.

1. The sender address doesn’t match the display name

The name beside an email is just a label the sender can type freely. Check the real address behind it. Example: a message from “Acme Bank Alerts” whose actual address is service@acme-bank-support.example.

2. A generic greeting

A company that holds your account usually knows your name. “Dear Valued Customer” is a strong indicator the sender does not. Example: “Dear Customer” instead of “Hi Priya.”

3. Urgency or threats

Phishing relies on making you act without thinking. Example: “Your account will be suspended within 24 hours unless you confirm your details now.”

4. Links that don’t match their text

A link’s visible text and its real destination can differ. Example: the text reads yourbank.com/login while the real address is a look-alike domain. Cybercriminals often swap characters — how easily micros0ft.com (a zero for the “o”) or rnicrosoft.com could pass a quick glance.

5. Unexpected attachments

Attachments are a common way attackers deliver harmful software. Be wary of unsolicited ones even from people you know. Example: an invoice or résumé you never asked for, asking you to “enable editing” or “enable macros.”

Illustration of an email with callouts marking five phishing red flags: sender address, generic greeting, urgency, mismatched link, and attachment.

6. Spelling, grammar, and layout mistakes

Poor spelling is one possible clue — but a weak one, not a test. Many phishing emails are perfectly written, so never let clean grammar convince you a message is safe. Example: a stretched logo and mismatched fonts.

7. A request for personal or financial information

Be sceptical of any email asking for sensitive details. Gmail states it won’t ask for your password by email, and the FTC notes legitimate companies won’t email a link to update your payment information. Example: “Confirm your password and PIN to keep your account active.”

8. Too-good-to-be-true offers

Unexpected refunds, prizes, and coupons are a classic lure. Example: “You’ve won a $500 gift card — claim it within the hour.”

A real-world example you can picture

The FTC shares a widely seen pattern in a fake Netflix email: a generic greeting, a claim that the account is on hold over a billing problem, and a link to “update payment details.” That mix — trusted brand, billing scare, fix-it-now link — is what real phishing looks like. (We describe the pattern rather than copying the company’s image or text.)

How to check a link or sender safely (before you click)

Hover to preview the real URL

On a computer, hover over a link without clicking; most email apps show the real destination. If it doesn’t match the link’s description or the company’s real domain, treat it as spoofed.

Go to the official site directly instead

Instead of clicking inside the email, open a new tab, type the company’s address yourself, and log in. An “urgent” issue that vanishes when you check directly was almost certainly a lure.

Use your email provider’s built-in warnings

Reputable services defend you. Gmail, for example, uses Safe Browsing warnings and labels many suspicious messages. If your provider flags a message, take the warning seriously.

Four-step illustration of responding to a clicked phishing link: change the password, enable two-factor authentication, contact your bank, and run a security scan.

What to do if you clicked a phishing link or replied

Don’t panic — acting quickly limits the damage.

Change the password on the affected account

If you entered a password on a page the email sent you to, change it immediately on the real account — and anywhere else you reused it, since one reused password can unlock many accounts. If you’re unsure whether it has been exposed, you can check whether your password was leaked in a data breach and change anything that shows up.

Turn on two-factor authentication

A second step at sign-in — a code, an app prompt, or a security key — means a stolen password alone is not enough. Turn it on for important accounts, preferring an app or security key over text codes. (A dedicated 2FA setup guide is coming separately.)

Contact your bank and watch for identity theft

If you shared financial details, call your bank or card provider on the number from the back of your card. If you handed over personal information that could be misused, the FTC recommends reporting it at IdentityTheft.gov.

If you opened an attachment, run a security scan

Run a full scan with your device’s security software, and keep it and your operating system set to update automatically. Follow the scan’s instructions before using the device for banking or email again.

How to report a phishing email

Where to send it

Reporting helps protect others and can help shut a campaign down. The FTC recommends:

  • Forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org. (This address belongs to the APWG, not the FTC.)
  • Forward phishing text messages to 7726 (which spells “SPAM” on a phone keypad).
  • Report the attempt to the FTC at ReportFraud.ftc.gov.

Report it inside your email app

In Gmail, use “Report phishing” on the message; most providers offer a similar report or junk button. Reporting also trains the filter to catch similar messages.

How to avoid phishing in the future

Slow down on urgent messages

Urgency is the tool phishing relies on, so make it your cue to pause and verify through an official channel you chose yourself.

Keep your devices updated

Set your operating system, browser, and security software to update automatically — up-to-date software closes the holes attackers use.

Use multi-factor authentication

The best everyday habit is turning on multi-factor authentication across your email, banking, and social accounts, so a stolen password is not enough on its own.

Frequently asked questions

Can you get hacked just by opening an email?

Reading the text of a suspicious email generally won’t hack you. The danger is what you do next: clicking a link, opening an attachment, or replying — even a simple reply confirms your address is active. It is safe to look; just don’t click, open, or reply.

What is the difference between phishing and spam?

Spam is the broad category of unwanted email; phishing is the deceptive type within it that tries to steal information or install malware. They are not the same thing.

Is it safe to click “unsubscribe” on a suspicious email?

For a newsletter you signed up for, unsubscribing is fine. For an unexpected message from an unknown sender, don’t engage — interacting with a scam can confirm your address is live. Report and delete it instead.

How do I know if a link is safe?

Hover to preview the real address before clicking, and check that the domain belongs to the company it claims to be. If in doubt, don’t click — go to the official site directly.

Quick checklist: is this email safe?

  • Does the actual sender address match the display name and the real company domain?
  • Is it addressed to you by name, or just “Dear Customer”?
  • Is it rushing you or threatening a deadline?
  • Does the link text match the real URL when you hover over it?
  • Is there an unexpected attachment you didn’t ask for?
  • Does it ask for a password, PIN, or payment details?
  • Does the offer seem too good to be true?

If any box is ticked: don’t click, open, or reply. Verify by visiting the company’s site directly, then report the message and delete it.