How to Spot a Phishing Email: The Checks That Still Work in 2026

Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Phishing Protection Published August 9, 2026 · 9 min read · By Yongrui SunUpdated September 10, 2026
How to Spot a Phishing Email: The Checks That Still Work in 2026
How to Spot a Phishing Email: The Checks That Still Work in 2026

The message says a delivery failed. It has your name, the right carrier, and a reference number in the format that carrier actually uses. You are late, and the link is right there, and the email is written in perfect English with no awkward phrasing anywhere in it.

That last detail is the one that retired the old advice. "Look for typos" was useful for about fifteen years, and it is close to useless now. Which is fine, because the checks that do work are more mechanical than that — you are not judging the writing, you are reading an address and a destination. Both are learnable in about five minutes.

Editor’s take: Three things this guide doesn't cover but you should know: (1) document your actual workflow before buying; (2) ask the vendor for a 30-day pilot, not a 14-day trial; (3) set a hard review date — six months is the magic window. Tackle those after you finish the steps above.

Editor's Take

The checks that still work are boring ones: read the actual sender address, hover the link before touching it, and be suspicious of urgency. The reason they survive AI-generated phishing is that they do not depend on spotting bad grammar or a wrong logo — those signals are gone. Build the habit around the envelope, not the writing, because the writing will keep getting better.

Read the sender address, not the sender name

Your mail client shows you a display name by default, and the display name is a field the sender sets to whatever they want. Anyone can put "Microsoft Security Team" or your finance director's name in it. The address behind it is the part that matters.

On desktop, hover or click the name to expand the full address. On a phone, tap the name once. Then read the part after the @ — and read all of it. [email protected], [email protected] and [email protected] all look right in a hurry, and none of them belongs to PayPal.

Also check the Reply-To header if your client offers it. A message can arrive from one address and route your reply somewhere else entirely, which is the standard trick in "reply to this thread" phishing where the original mail was real and the response goes to an attacker.

Find out where the link goes before you touch it

This single habit catches most of what gets through. On a desktop, hover the mouse over the link — do not click, just hover — and read the destination in the status bar at the bottom of the window. On a phone, press and hold the link until the preview appears.

Then read the address properly, which means right to left rather than left to right:

And the rule that overrides all of it: a link in an unsolicited message is the attack. You do not need to decide whether it is safe, because you have a better route to the same place. Type the address yourself.

Attachments: the types that should stop you cold

An invoice you were not expecting is a common shape, and guessing at file types is how people get hurt. Some categories should simply never be opened from an unsolicited message:

If a file is genuinely expected, open it through the shared drive or the portal where it was supposed to be, not from the mail.

The urgency script, and why it works on people who know better

Phishing does not defeat your judgement; it removes the time to use it. The recurring lines — access expires in 24 hours, payment failed, unusual sign-in detected, this is the final notice, your boss needs this before the meeting — all do the same job of compressing your decision from minutes into seconds.

Recognise the shape and you get your time back. Any message that couples a consequence with a deadline should be handled through a channel you opened, not the one it arrived in. Real organisations with real problems give you a reference number and a phone number you can find independently, and they do not mind being checked.

Worth naming too: flattery and curiosity work the same way as fear. "You're featured in this report," "is this you in this photo," "your package is waiting." Different emotion, same compression.

The tells that stopped being tells

Some advice still circulating is actively misleading, and relying on it makes you less safe because it gives you false confidence:

When you genuinely cannot find anything wrong

This is the case that catches experienced people, and it deserves its own procedure rather than a shrug. Perfectly built phishing mail exists, aimed at exactly the person it reached. If you have checked the address, checked the destination, and found no flaw you can name — and you still feel the pull of it — do this:

  1. Do not use anything inside the message. Not the link, not the phone number, not the reply button.
  2. Open a new tab and navigate yourself. Type the address you already know, or open the app already installed on your phone. If the notice is real, it will be there too.
  3. If it claims to be from a person, contact them out of band. Use a number you already had, or walk over. Never the number in the email. A two-second call that feels slightly awkward is cheaper than the alternative, and no legitimate colleague is offended by it.
  4. If it involves money, add a second human. Any request to change bank details, add a new supplier, or approve an unusual transfer gets verified by voice with someone already known to you. This one control defeats most business email fraud regardless of how good the email is.
  5. Report it and delete it. Reporting trains the filter for everyone behind you.

The principle underneath all five steps: you are never verifying by looking harder at the message. You are verifying by leaving it.

The versions that are not email

Every signal above has a parallel somewhere else, and attackers go where the checking is weaker.

Phone calls — someone from "your bank's fraud team" who needs a code you just received. Hang up and call the number on the back of the card. Text messages — shorter, no hover, so the default should be to never tap a link in an unexpected SMS. QR codes — you cannot read the destination at all before scanning, which is precisely why they are used; a QR code in a poster, a parking meter or an unexpected letter deserves suspicion.

None of these require new skills, just the same rule: go to the service yourself.

If you already clicked

Speed matters less than order, and the order is not what most people do.

Codes from an app or a text message are not a guarantee here — a real-time proxy can relay them along with your password as you type. Hardware security keys and passkeys are tied to the genuine domain and fail closed on a fake one, which is why they are worth the small setup cost. Our two-factor guide explains the difference, and the BigBear MFA bypass write-up shows what that attack looks like in practice.

Beyond that: unique passwords in a password manager mean one mistake costs one account instead of every account, and our phishing protection guide covers filtering and the organisational side. If your details have already circulated in a breach, monitoring tells you before the email arrives, and the breach response guide covers the triage. For deciding whether a message is real at all, our encrypted email explainer covers what mail headers do and do not prove.

One Rule Covers Almost Every Case

Never act inside the message. Whatever it claims — a failed payment, a locked account, a request from your manager — close it and open the service yourself. That single habit beats every checklist, because it works even when the email is flawless.

Phishing protection: the full guide

Remove Your Data From Broker Sites

Deleting an account does not remove what brokers already collected. PrivacyHawk files opt-outs on your behalf and keeps monitoring for re-listing.

Get PrivacyHawk Read our PrivacyHawk review
YS
Founder & Editor

CyberPicks is published by Yongrui Sun. Every comparison is built from vendor documentation, published pricing, aggregated user reviews from G2, Capterra and TrustRadius, and published independent-lab results. We do not run hands-on lab tests, and where a figure comes from a vendor or an independent testing lab we say which on the page.

Where these checks come from

These are checks that still hold up against current phishing kits. We do not run phishing simulations against real inboxes to test them.

Frequently asked questions

How can I check where a link really goes without clicking it?

Hover the link on a desktop computer, or press and hold it on a phone, and read the destination that appears in the status bar before you touch anything. Read the address from right to left: find the first single slash after the domain part, and the real owner is the name immediately to the left of it, not any brand word appearing earlier in the string.

Why is checking for spelling mistakes no longer enough?

Generated phishing mail is now written in clean, fluent English, and messages scraped from a real breach can include your actual order details or colleague names. A well-written email tells you nothing about who sent it, so the checks have to move to the address and the destination instead of the prose.

What should I do if an email looks completely legitimate?

Do not use anything in the message. Close it, open a new browser tab and type the address of the organisation yourself, or use the app you already have installed, and check for the same notice there. If it claims to be from a colleague, contact that person on a number you already had.

Which email attachments should I never open?

Treat archive files, disc images, script files, shortcut files, and anything ending in a script or executable extension as hostile by default. Word and Excel files that immediately ask you to enable content or editing are in the same category, since a legitimate invoice does not need you to switch anything on to be read.

Does two-factor authentication protect me if I fall for a phishing page?

Not always. A real-time proxy site can relay your password and your one-time code to the genuine service at the same moment you type them, which is why hardware security keys and passkeys tied to the real domain are considerably stronger than codes you retype from an app or a text message.

I already clicked the link. What is the order of operations?

Disconnect the device from the network if you entered credentials or ran a file, then change the password from a different device, and check for anything the attacker may have added such as a forwarding rule or a new recovery address. Tell whoever administers your email, because a silent forwarding rule is worse than the password.

How to Spot a Phishing Email: The Checks That Still Work in 2026 — comparison snapshot
How to Spot a Phishing Email: The Checks That Still Work in 2026 — comparison snapshot