How to Spot a Phishing Email: The Checks That Still Work in 2026
Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

The message says a delivery failed. It has your name, the right carrier, and a reference number in the format that carrier actually uses. You are late, and the link is right there, and the email is written in perfect English with no awkward phrasing anywhere in it.
That last detail is the one that retired the old advice. "Look for typos" was useful for about fifteen years, and it is close to useless now. Which is fine, because the checks that do work are more mechanical than that — you are not judging the writing, you are reading an address and a destination. Both are learnable in about five minutes.
Editor’s take: Three things this guide doesn't cover but you should know: (1) document your actual workflow before buying; (2) ask the vendor for a 30-day pilot, not a 14-day trial; (3) set a hard review date — six months is the magic window. Tackle those after you finish the steps above.
Editor's Take
The checks that still work are boring ones: read the actual sender address, hover the link before touching it, and be suspicious of urgency. The reason they survive AI-generated phishing is that they do not depend on spotting bad grammar or a wrong logo — those signals are gone. Build the habit around the envelope, not the writing, because the writing will keep getting better.
Read the sender address, not the sender name
Your mail client shows you a display name by default, and the display name is a field the sender sets to whatever they want. Anyone can put "Microsoft Security Team" or your finance director's name in it. The address behind it is the part that matters.
On desktop, hover or click the name to expand the full address. On a phone, tap the name once. Then read the part after the @ — and read all of it. [email protected], [email protected] and [email protected] all look right in a hurry, and none of them belongs to PayPal.
Also check the Reply-To header if your client offers it. A message can arrive from one address and route your reply somewhere else entirely, which is the standard trick in "reply to this thread" phishing where the original mail was real and the response goes to an attacker.
Find out where the link goes before you touch it
This single habit catches most of what gets through. On a desktop, hover the mouse over the link — do not click, just hover — and read the destination in the status bar at the bottom of the window. On a phone, press and hold the link until the preview appears.
Then read the address properly, which means right to left rather than left to right:
- Find the first single slash after the start of the domain. Everything before it is the domain; everything after it is a path the domain owner controls.
- The name that matters is the one immediately to the left of that slash, plus what follows the final dot. Brand words appearing anywhere earlier are decoration.
- In https://login.microsoftonline.com.verify-account.net/signin, the owner is verify-account.net. The "microsoftonline.com" in the middle is a subdomain the attacker chose, and it is there to be read quickly by someone going the wrong direction.
- Shortened links hide the destination by design. A link shortener in a message from a bank, a carrier or a colleague is a reason to stop, not a convenience.
- Lookalike characters exist. A letter swapped for a near-identical character from another alphabet produces a domain that is visually right and technically different. If a domain looks slightly off in a way you cannot name, treat that as a signal rather than dismissing it.
And the rule that overrides all of it: a link in an unsolicited message is the attack. You do not need to decide whether it is safe, because you have a better route to the same place. Type the address yourself.
Attachments: the types that should stop you cold
An invoice you were not expecting is a common shape, and guessing at file types is how people get hurt. Some categories should simply never be opened from an unsolicited message:
- Archives and disc images — ZIP, RAR, ISO, IMG. They exist to get past content scanning, and what is inside is not what the icon suggests.
- Scripts and shortcuts — anything ending in a script or executable extension. On Windows, turn on file extensions in Explorer; the default hides them, which is how a file called Invoice.pdf.exe displays as Invoice.pdf.
- Office files that ask you to enable something. A real invoice is readable immediately. A document that opens with a banner asking you to enable content, enable editing, or allow macros is asking you to run code.
- Password-protected attachments with the password in the email body. The protection is not for you; it is there to stop the scanner.
- Embedded HTML files that open a "sign in to view" page in your browser.
If a file is genuinely expected, open it through the shared drive or the portal where it was supposed to be, not from the mail.
The urgency script, and why it works on people who know better
Phishing does not defeat your judgement; it removes the time to use it. The recurring lines — access expires in 24 hours, payment failed, unusual sign-in detected, this is the final notice, your boss needs this before the meeting — all do the same job of compressing your decision from minutes into seconds.
Recognise the shape and you get your time back. Any message that couples a consequence with a deadline should be handled through a channel you opened, not the one it arrived in. Real organisations with real problems give you a reference number and a phone number you can find independently, and they do not mind being checked.
Worth naming too: flattery and curiosity work the same way as fear. "You're featured in this report," "is this you in this photo," "your package is waiting." Different emotion, same compression.
The tells that stopped being tells
Some advice still circulating is actively misleading, and relying on it makes you less safe because it gives you false confidence:
- Spelling and grammar. Generated mail is fluent now. A well-written message is not evidence of legitimacy.
- "Dear Customer." Plenty of legitimate automated mail uses it. And a message built from breach data will use your real name and your real order number, which proves only that the data leaked.
- The padlock icon. It means the connection is encrypted, not that the site is honest. Phishing sites get certificates like everyone else.
- Logos and branding. Copying an image is trivial.
- The message landing in your inbox. Filtering is probabilistic. Something getting through tells you nothing; something getting caught is also not proof either way.
When you genuinely cannot find anything wrong
This is the case that catches experienced people, and it deserves its own procedure rather than a shrug. Perfectly built phishing mail exists, aimed at exactly the person it reached. If you have checked the address, checked the destination, and found no flaw you can name — and you still feel the pull of it — do this:
- Do not use anything inside the message. Not the link, not the phone number, not the reply button.
- Open a new tab and navigate yourself. Type the address you already know, or open the app already installed on your phone. If the notice is real, it will be there too.
- If it claims to be from a person, contact them out of band. Use a number you already had, or walk over. Never the number in the email. A two-second call that feels slightly awkward is cheaper than the alternative, and no legitimate colleague is offended by it.
- If it involves money, add a second human. Any request to change bank details, add a new supplier, or approve an unusual transfer gets verified by voice with someone already known to you. This one control defeats most business email fraud regardless of how good the email is.
- Report it and delete it. Reporting trains the filter for everyone behind you.
The principle underneath all five steps: you are never verifying by looking harder at the message. You are verifying by leaving it.
The versions that are not email
Every signal above has a parallel somewhere else, and attackers go where the checking is weaker.
Phone calls — someone from "your bank's fraud team" who needs a code you just received. Hang up and call the number on the back of the card. Text messages — shorter, no hover, so the default should be to never tap a link in an unexpected SMS. QR codes — you cannot read the destination at all before scanning, which is precisely why they are used; a QR code in a poster, a parking meter or an unexpected letter deserves suspicion.
None of these require new skills, just the same rule: go to the service yourself.
If you already clicked
Speed matters less than order, and the order is not what most people do.
- If you entered a password, change it from a different device — the one you used may be compromised.
- If you ran a file or approved a prompt, disconnect that machine from the network before anything else.
- Check for persistence, not just the password. In a mailbox: forwarding rules to unknown addresses, new recovery addresses or phone numbers, and apps granted access. A forwarding rule means they keep reading your mail after you reset everything, which is why this step outranks the password change in importance if you only do one.
- Tell whoever administers your email, especially at work. One compromised mailbox is how the next person gets a message that references a real thread.
Codes from an app or a text message are not a guarantee here — a real-time proxy can relay them along with your password as you type. Hardware security keys and passkeys are tied to the genuine domain and fail closed on a fake one, which is why they are worth the small setup cost. Our two-factor guide explains the difference, and the BigBear MFA bypass write-up shows what that attack looks like in practice.
Beyond that: unique passwords in a password manager mean one mistake costs one account instead of every account, and our phishing protection guide covers filtering and the organisational side. If your details have already circulated in a breach, monitoring tells you before the email arrives, and the breach response guide covers the triage. For deciding whether a message is real at all, our encrypted email explainer covers what mail headers do and do not prove.
One Rule Covers Almost Every Case
Never act inside the message. Whatever it claims — a failed payment, a locked account, a request from your manager — close it and open the service yourself. That single habit beats every checklist, because it works even when the email is flawless.
Remove Your Data From Broker Sites
Deleting an account does not remove what brokers already collected. PrivacyHawk files opt-outs on your behalf and keeps monitoring for re-listing.
Get PrivacyHawk Read our PrivacyHawk review