Security, Privacy & Scams
How to Spot a Phishing Email Before It Tricks You
Phishing emails look real and try to make you panic. The good news: they almost always give themselves away if you know the five signs to check before you click.
How to Spot a Phishing Email Before It Tricks You
Phishing emails look real and try to make you panic. The good news: they almost always give themselves away if you know the five signs to check before you click.
Short answer: Slow down, check the sender address, watch for urgency and threats, never click a link or open an attachment you did not expect, and verify through a separate trusted path.
A phishing email pretends to be from a bank, store, or service you use and tries to scare or tempt you into clicking a link, opening an attachment, or typing your password on a fake sign-in page. One click can hand your account to a stranger. These emails are common, but they follow predictable patterns you can learn to recognize.
What you need
1. Your email inbox
2. A separate, trusted way to check the real account (the official app or website you typed in yourself)
Warnings
1. Do not click links or open attachments in a suspicious email to “check.”
2. Do not call phone numbers listed in the email — use the number from the real company website.
3. If you already clicked and signed in, change that password immediately and turn on two-factor authentication.
Diagnostics
1. Check the sender’s full email address, not just the display name.
2. Hover over any link (without clicking) to see where it actually goes.
Steps
1. Check the sender address. A real message from a bank comes from the bank’s domain; a fake one often uses a look-alike or random address. → You can confirm whether the address matches the real organization.
2. Look for urgency or threats — “your account will be closed in 24 hours” is a classic pressure tactic designed to make you act before thinking. → You recognize the pressure as a warning sign, not a reason to rush.
3. Hover over links (do not click) and read the real address in the preview. A link that says “bank.com” but points somewhere else is a trap. → You see the true destination of each link.
4. Watch for generic greetings, spelling mistakes, and requests for passwords or payment — real services do not ask for passwords by email. → You spot one or more classic phishing tells.
5. If you are unsure, do not use the email. Open the official app or type the website address yourself and check there. → You verify the situation through a path you trust, separate from the email.
Confirm it worked
1. You did not click any link or open any attachment from the suspicious email.
2. You confirmed the real account status through the official app or website.
If it didn't work
1. If you already clicked and signed in on a fake page, change that password right now and enable two-factor authentication.
2. If you entered payment details, contact your bank or card issuer and report the fraud.
How to undo
1. There is nothing to undo if you did not click — just delete or report the email as phishing.
2. If you did click, the undo is changing the password and turning on 2FA immediately.
Phishing works by hijacking trust and urgency. The email imitates a brand you recognize and adds a deadline so you act on emotion instead of checking. The single most effective defense is to slow down and verify through a separate channel — the real app or a website you typed yourself — rather than following the email’s links.
Sender addresses and link destinations are the two facts the scammer cannot fully hide, which is why checking those first catches most phishing emails.
Sources
1. Cybersecurity guidance on phishing recognition from government and industry sources, accessed September 2026.
Return to Gorge Computers