How to Tell If an Email Is a Phishing Attempt (October 2026)

To tell if an email is a phishing attempt, slow down and check the sender address, the real destination of every link, the request it makes, and whether you were expecting it. If one of those fails, verify through a channel you already trust before you touch anything else.

There is no single test that proves an email is fake. A perfect logo, clean spelling and a real-looking domain all mean very little in 2026, because attackers copy those from the real organisation. What usually gives them away is a mismatch between the message and your reality: you did not expect it, the links point somewhere you would not expect, and the sender wants something valuable before a deadline you never knew existed.

Phishing works because it targets behaviour rather than software. The message invents a believable situation — a held parcel, a failed payment, a shared document, a locked account — and attaches pressure so you act before you think. Once you have a repeatable inspection routine, you stop relying on a gut feeling that attackers are very good at triggering.

Table of Contents

What You Need to Check an Email for Phishing

What You Need to Check an Email for Phishing

You need very little to inspect a suspicious message, but you need it before you start clicking. Gathering these first prevents the most common mistake, which is investigating on the attacker’s terms.

  • The original email, unopened. Do not open links or attachments. Reading the plain text of the message is enough for most checks.
  • A device you trust with security software that is up to date. Personal devices are often missing the filters your work laptop has.
  • A modern web browser on a desktop, where you can hover a link and see the destination without tapping it. Phones hide previews until you press and hold, and some apps hide them completely.
  • A way to report the message — the report-phishing button in your mail provider, your organisation’s IT or abuse address, or in the US the FTC at ReportFraud.gov.
  • Known contact details you already had: the official phone number on your statement, the support address in your browser history, the colleague’s number from your own contacts.

One rule matters more than the rest: never use any contact detail, link or phone number contained inside the suspicious message itself. That number is controlled by the person who sent it.

Step-by-Step: How to Tell If an Email Is a Phishing Attempt

Work through these eight checks in order. Each one is fast on its own, and most real phishing trips two or three of them before you even reach the end.

Check the Sender and Display Name

Read the full address under the display name, not the name itself. A display name is free text anyone can set, so “Microsoft Support” tells you nothing.

Then read the domain left to right and slowly. Lookalike domains are the most reliable signal in this whole process: rnicrosoft.com with an n, paypaI.com with a capital I, or amaz0n.co replacing the o with a zero. Attackers register thousands of these near-misses, and a genuine employee address on a genuine domain is a much rarer sight.

Know that a real address is not proof of anything either. If a colleague’s account is compromised, the message genuinely comes from them, with a correct domain and a thread history that looks normal. Practitioners on r/sysadmin put context above any visual clue for exactly this reason: the question that matters is whether you expected this, from this person, about this thing.

On desktop, hover over a link and read the status bar or the small preview that appears. The visible text is decoration; the destination is the fact.

Watch for the classic swaps. A link reading “microsoft.com/account/verify” pointing somewhere with a completely different host, or a legitimate domain buried mid-string as in paypal.com.secure-login-check.ru, where the part before the first single slash is what your browser actually goes to. Long URLs are not automatically bad, and shorteners hide the destination rather than prove danger, so treat both as a reason to verify rather than a verdict.

Never click the link to “see where it goes”, and never paste it into a link scanner you found by searching the same suspicious message. On mobile there is no hover at all, which is a good reason to verify these on a computer or by phone.

Treat Urgency, Pressure, and Unexpected Requests Carefully

Artificial deadlines are the biggest red flag in a phishing email. Messages threaten suspension, demand payment within hours, or push you to act before anyone can check.

Watch for the specific shapes it takes: an account will be closed unless you re-enter credentials, a payment bounced and needs resubmitting, a boss asks you to buy gift cards, a supplier changes bank details, an urgent shared document waits for your login. Requests for passwords, one-time codes, card numbers or remote-access software are almost never legitimate, whatever the branding says.

Urgency on its own does not prove phishing — real invoices do have deadlines. What matters is that urgency plus an unusual request plus a link you did not expect is a pattern worth stopping for.

Examine the Message for Context and Reasoning Problems

Ask the question that catches most real attacks: did I expect this, from this person, about this thing? Sysadmins describe the successful attacks as the ones that matched a genuine recent event — a real ticket number, a real colleague’s name, a real shipment.

Then read for reasoning problems rather than typos. A package that needs a customs fee is odd if you never ordered one. An invoice for software you do not use is odd. A recruiter who asks for your bank details before an interview is odd. Generic greetings such as “Dear Customer” or “Dear User” are weak signals now, but a message that starts with your actual name and still makes no logical sense is worse, not better.

Handle Attachments Safely

Treat every unexpected attachment as hostile until verified, even when it arrives from someone you know. A compromised colleague’s account is a documented route to convincing messages with a real attachment.

Executables, scripts, installers and macro-enabled Office documents carry the most risk. Archives and disk images are next, because they hide whatever is inside. One further trick: a fake login page embedded in an HTML file or PDF, which can look like a sign-in prompt and hand over your credentials the moment you type.

If the file is compressed, or it opens a window asking for your password, close it and verify through a channel you already have. For a normal document you genuinely expected, check with the sender by phone before opening anything.

Look for Authentication and Header Clues

SPF, DKIM and DMARC are the standards that let a domain vouch for its own email. When a message passes them, the sending servers are authorised. When they fail, something about the origin could not be confirmed.

Viewing the header takes a few clicks in most clients. In Gmail, open the message and click the three dots, then “Show original”. In Outlook on the web, expand the arrow beside Reply. In Outlook on Windows, open the message and go to the Message tab, then the Reading pane arrow. In Apple Mail, go to View, then Message, then All Headers.

Once you have it, read the “Authentication-Results” line first. Then compare “Reply-To” with the sending address, a mismatch between the two is a strong signal. Skim the “Received” chain to see which server handled the message last, and check that “Return-Path” matches the domain you expect. A failed DMARC result is a warning worth taking seriously, not proof on its own, since forwarding and mailing lists break authentication legitimately all the time.

Verify Through a Trusted Channel

This is the only objective test available to you, and it is the step people skip. Open a new tab and go to the organisation’s site yourself, or call a number you already had, and ask whether they sent it.

The reasoning is simple. No single visual clue is reliable, which is the consensus across the Spiceworks and Security StackExchange threads on this topic, so any combination of red flags should be enough to make you verify out of band. Using a channel you found yourself removes the attacker from the conversation entirely.

For developers and administrators, the same rule covers the alerts that arrive with real events attached: a GitHub or package registry notice, a CI failure, a cloud console alert, a recruiter with your exact job title. Navigate to the console or repository directly instead of following the link in the message.

Report, Delete, and Protect the Account

Report before you delete. Reporting is what protects the next person, and in most organisations it is also what protects you.

Use the report-phishing button in Gmail, Outlook or Apple Mail, which sends the message to your provider’s filtering systems. At work, forward it to your IT or security team, keeping it as an attachment rather than pasting the body. In the US, individuals can file at ReportFraud.gov, and material losses can go to the FBI’s IC3. Once reported, delete it and empty the folder.

If you ever entered credentials or approved a sign-in prompt, change the password from a trusted device right away, revoke active sessions, and turn on multi-factor authentication. A password manager helps here too, since it will only autofill on the genuine site and will stay silent on the fake one.

Legitimate vs Phishing Email: Side by Side

SignalWhat a genuine email looks likeWhat phishing usually looks like
GreetingYour name or a known colleague’s“Dear Customer”, “Dear User”, or your name in a message that makes no sense
Sender addressExact domain you normally receive fromLookalike domain, or a display name hiding a different address
Reply-ToMatches the sending addressPoints at an unrelated domain
Link destinationMatches the visible text after hoveringReal brand domain buried mid-string, or a shortener
The requestSomething you initiated or expectedCredentials, a code, a payment change, gift cards, remote access
TimingNormal business paceA deadline counted in hours, often paired with a threat
AttachmentA file you were expecting, from a known senderArchive, executable, or a document that opens a login prompt

No row on its own settles the question. A phishing attempt that copies a real thread, greets you by name and arrives attached to a genuine work event can pass several of these at once, which is why the last two checks matter more than the first six.

What to Do If You Already Clicked or Entered Details

Work out which of the three states you are in, because the response time differs by hours.

  1. You clicked the link but typed nothing. Close the tab, do not download anything, and clear your browser downloads and cookies. Watch for a fake login page that harvested credentials silently, so change the password for that account anyway if one appeared.
  2. You entered a password or approved a one-time code. Change that password from a different device, ideally a different network, and change it everywhere the same password was reused. Revoke active sessions, then turn on multi-factor authentication. Tell your IT team the same day if the account is a work one.
  3. You downloaded a file or ran an installer. Disconnect from the network and contact IT or your security provider. Scan with updated software, and be ready to change passwords from a clean machine. Credentials, browser profiles and cloud tokens may all be exposed, so revoke sessions rather than trusting a scan alone.

Report the message either way. Opening an email alone rarely infects anything, since images and text load safely, but preview panes, remote images that confirm your address is live, and crafted links that trigger a browser bug are the exceptions that justify caution.

Common Mistakes When Checking for Phishing

Common Mistakes When Checking for Phishing

Most people get phished by trusting a clue that has stopped carrying information.

  • Judging by spelling. Correct the idea, not the habit: AI-written phishing in 2026 is fluent, so a clean email proves nothing. Check the domain and the request instead.
  • Trusting the display name. Open the address details before you read anything else.
  • Clicking the link to inspect it. Hover on desktop, and verify out of band on mobile where hover does not exist.
  • Replying to ask if it is genuine. Replying confirms your address works and hands the attacker a conversation.
  • Forwarding to colleagues “in case”.strong> They may open it, and your IT team loses the original headers.
  • Deleting before reporting. Delete first and the message is gone; report first and it gets filtered for everyone.
  • Trusting a familiar logo or a colleague’s signature. Both are stolen and reused constantly.

Frequently Asked Questions

Can a legitimate email address still send phishing?

Yes. A real colleague’s account can be compromised and used to send genuine-looking messages to their contacts, with the correct domain and real signature. Shared or forwarded mail can also carry a spoofed name. Verify unusual requests from a colleague by phone using a number you already had, not one supplied in the message.

Hovering only reveals the link destination, it does not follow the link, so it is safe on desktop. On phones there is no hover, so press-and-hold copies the address instead. Neither method catches a shortener or redirect chain, and neither proves safety. If anything looks wrong, verify through a channel you already have before acting.

Close the tab, do not download anything, and clear your browser downloads and cookies. Change the password for that account from a different device, revoke active sessions, and report the email through your provider or IT team. If you entered a password or approved a code, treat the account as compromised until you have changed credentials everywhere.

Does bad grammar prove that an email is phishing?

No. Bad grammar is weak evidence now because AI-generated text is fluent and error-free, and many phishing emails read perfectly. A clean email is not a safe email. Focus instead on the sender domain, the real link destination, whether the request makes sense, and whether you expected the message at all.

Should I forward a suspicious email to my IT department?

Yes, and report it before deleting. Forward it as an attachment rather than pasting the body, because the headers carry the authentication results your team needs. Forwarding to colleagues or friends is worth avoiding, since they may open links you have not checked. Outside an organisation, use your provider’s report button or ReportFraud.gov in the US.

What if I entered my password on a fake login page?

Treat that account as compromised right away. Change the password from a different device and network, change it anywhere else you reused it, revoke active sessions, and enable multi-factor authentication. Report the email so your provider can block the page. Do not log out of your real account waiting to see what happens, since that only hides the symptoms.

Conclusion: Verify Before You React

If you take one thing from this, make it the out-of-band check. Open the organisation’s site yourself or call a number you already had, and ask whether the message is real. Every visual clue on this list can be faked, and that one call is the only test that cannot.

When something does not add up, report it before you delete it. That single habit protects the next person who would have received the same message, and it costs about fifteen seconds.

Leave a Comment