How to Spot a Phishing Email Before You Click

An email arrives saying there’s a problem with your bank account.

Another claims a parcel couldn’t be delivered.

Perhaps you’re told your streaming subscription has expired, you’ve received an unexpected refund, or someone has tried to log into your account.

How to Spot a Phishing Email Before You Click

How to Spot a Phishing Email Before You Click

There’s a button underneath:

VERIFY NOW

Would you click it?

That moment is exactly what phishing criminals are hoping for.

Phishing messages are designed to make you act before you have time to question whether the message is genuine.

Modern phishing emails can also look remarkably convincing. Good spelling, professional logos and realistic-looking websites are no longer proof that a message is legitimate.

So how can you spot a phishing email before clicking anything?

What Is Phishing?

Phishing is a type of scam in which criminals pretend to be a person or organisation you trust.

They may impersonate:

  • Banks
  • Delivery companies
  • Government departments
  • Online retailers
  • Streaming services
  • Social-media platforms
  • Employers
  • Friends or colleagues

The message usually tries to persuade you to take some action.

That might be clicking a link, opening an attachment, scanning a QR code, entering a password or providing financial information.

The ultimate goal could be stealing money, passwords or personal information, or getting malicious software onto a device. The UK’s National Cyber Security Centre (NCSC) describes phishing in similar terms.

Why Do Phishing Emails Work?

Phishing attacks target people as much as computers.

Instead of trying to defeat sophisticated security technology directly, a criminal may try to persuade you to give them what they want.

A message might say:

Your account will be suspended today.

Unusual activity has been detected.

Your parcel cannot be delivered.

You’re entitled to a refund.

Payment failed—update your details immediately.

The objective is to create an emotional response.

If you’re worried, excited, curious or rushed, you may react before examining the message carefully.

The NCSC specifically warns that scammers commonly exploit authority, urgency and emotion to pressure people into acting.

1. Check the Actual Sender Address

The name displayed at the top of an email isn’t necessarily the sender’s real email address.

An inbox might show:

Your Bank

But expanding the sender information could reveal an unrelated address.

For example, a suspicious address might look something like:

security-bank@example-random-domain.com

The visible name is easy to imitate.

Always examine the actual email address, particularly when a message asks you to sign in, make a payment or provide personal information.

2. Look for Slightly Misspelled Domains

Phishing domains are sometimes designed to resemble legitimate ones.

Imagine the real address were:

examplebank.co.uk

A criminal might try something visually similar, such as:

example-bank-security.com

or use subtle character changes that are difficult to notice quickly.

Don’t judge an address simply because it contains the company’s name somewhere.

The important question is whether it uses the organisation’s real domain.

3. Be Suspicious of Unnecessary Urgency

Urgency is one of the strongest phishing warning signs.

A criminal doesn’t want you spending ten minutes investigating the message.

They want you clicking now.

Be cautious of phrases such as:

ACT IMMEDIATELY

Your account will be closed

Payment required today

You have 24 hours

Verify your identity now

A legitimate organisation can sometimes send genuinely urgent communications, so urgency alone doesn’t prove something is fraudulent.

But it should make you slow down rather than speed up.

4. Don’t Trust an Email Just Because It Looks Professional

Years ago, many phishing emails were relatively easy to identify.

They might contain poor spelling, strange formatting or obviously fake graphics.

That is no longer a safe assumption.

The NCSC warns that scams are becoming more sophisticated and can sometimes fool experienced users.

A modern phishing email can contain:

A convincing logo

Professional formatting

Correct spelling

A realistic signature

Your name

Accurate information about a company

A polished-looking website

Professional appearance should therefore never be your only test.

5. Check Links Before Clicking

Links are one of the most important things to examine.

Text displayed in an email doesn’t necessarily reveal where the link actually leads.

A button could say:

Visit Your Account

while directing you somewhere completely unrelated.

On a computer, hovering your mouse over a link may reveal its destination without opening it.

On mobile devices, checking links can be more difficult and varies by application.

If you’re unsure, don’t use the link at all.

Instead, open the company’s official app or manually navigate to the website you normally use.

That’s often much safer.

6. Don’t Assume HTTPS Means a Website Is Genuine

People sometimes believe a padlock symbol or https means a website must be legitimate.

That’s incorrect.

HTTPS indicates that the connection between your browser and the website is encrypted.

It does not prove that the person operating the website is trustworthy.

A phishing website can use HTTPS too.

So although an encrypted connection is important, it isn’t enough to establish that a website is genuine.

7. Watch for Unexpected Attachments

Be particularly cautious when an unexpected email contains an attachment.

Common file descriptions might include:

Invoice

Receipt

Statement

Delivery information

Tax document

Payment details

The document might be genuine—or it could be part of an attempt to compromise your device or persuade you to follow further instructions.

If you weren’t expecting the attachment, verify the sender through another trusted method before opening it.

The NCSC includes unexpected attachments among the warning signs that can indicate a suspicious email.

8. Be Careful With Login Pages

One of the most common phishing techniques is creating a fake login page.

Suppose an email claims your email account needs verification.

You click a link.

A familiar-looking sign-in page appears.

You enter your email address and password.

The page reports an error.

You may assume you mistyped your password and try again.

But the website may have already captured the credentials you entered.

The safest approach when an email unexpectedly asks you to log in is often to avoid the email link entirely.

Open the official app or type the website address yourself.

9. Be Suspicious of Requests for Passwords

A message asking you to send a password by email should immediately raise concern.

Passwords are supposed to remain secret.

Legitimate services may ask you to authenticate through their official systems, but they shouldn’t need you to reply to an ordinary email with your password.

Never send passwords by email simply because someone claiming to represent a company asks for them.

10. Watch for Requests for Banking Information

Financial information deserves extra caution.

Be suspicious if an unexpected email asks you to:

Enter card details

Provide online-banking credentials

Transfer money

Change payment information

Pay an unexpected invoice

Confirm financial details

If a message appears to come from your bank, don’t rely on contact information supplied in the suspicious message.

Use the bank’s official app, website or another trusted contact method instead.

11. Don’t Trust the Phone Number in a Suspicious Email

A clever phishing email may include a telephone number and tell you to call it.

That doesn’t make the message safe.

If criminals created the email, they can also put their own telephone number in it.

You might then call and speak directly to someone participating in the scam.

If you need to contact the organisation, independently obtain its official contact details.

12. Watch for QR Codes in Emails

QR codes have become another phishing technique.

Instead of giving you a clickable link, an email may tell you to scan a QR code with your phone.

The QR code can direct your phone to a website just like an ordinary link.

The NCSC says criminals are increasingly using QR codes in phishing emails—a technique sometimes called quishing—and recommends exercising caution when an email asks you to scan one.

Treat an unexpected QR code exactly as you would a suspicious link.

13. Check Whether the Message Makes Sense

Sometimes the simplest questions are the most useful.

Ask yourself:

Do I even have an account with this company?

Am I expecting this parcel?

Did I request this password reset?

Did I recently make this purchase?

Why would this person suddenly ask me for money?

A message that doesn’t fit your circumstances deserves extra scrutiny.

14. Don’t Assume Personal Information Makes It Genuine

A phishing email might contain your real name, email address, employer or other information.

That doesn’t necessarily mean the sender is legitimate.

Personal information can sometimes be gathered from public websites, social media, previous data breaches and other sources.

Criminals may use those details to make a message more convincing.

15. Be Careful With Unexpected Invoices

Businesses are particularly vulnerable to fake invoice scams.

A criminal might impersonate:

A supplier

A manager

An accountant

A contractor

A senior executive

The message might ask someone to pay an invoice or change bank-account details.

Any unexpected request to change payment details should be verified using an established contact method—not simply by replying to the email that requested the change.

16. Beware of “CEO” or Boss Impersonation

Imagine receiving an email apparently from your manager:

I’m in a meeting. I need you to make an urgent payment for me.

The sender may deliberately create urgency and discourage you from verifying the request.

This type of social engineering relies on authority.

If an unusual request involves money, sensitive information or account access, verify it independently—even if the message appears to come from someone senior.

17. Don’t Rely Only on Spelling Mistakes

Poor grammar can still be a warning sign.

But correct grammar does not mean an email is safe.

Modern criminals have access to translation tools, templates and AI systems capable of producing convincing text.

So instead of asking only:

“Does this email look badly written?”

Ask:

“Does the request make sense, and can I independently verify it?”

That’s a much stronger test.

The Best Rule: Don’t Use the Message to Verify the Message

This is one of the easiest phishing principles to remember.

Suppose an email says:

There is suspicious activity on your bank account. Click here immediately.

Don’t click the button.

Don’t call the telephone number in the email.

Don’t reply asking whether it’s genuine.

Instead, independently open your bank’s official app or use a trusted contact method.

You’re now checking the claim without relying on information supplied by the potentially fraudulent message.

What Should You Do With a Suspicious Email?

If you think an email may be fraudulent, don’t click its links or open unexpected attachments.

In the UK, suspicious emails can be forwarded to the NCSC’s Suspicious Email Reporting Service.

The NCSC says you can report an email even if you’re not certain that it’s a scam. It can analyse suspicious emails and associated websites and may work to have malicious infrastructure removed.

After reporting it, you can normally delete the suspicious message.

What If You’ve Already Clicked the Link?

Clicking something suspicious doesn’t automatically mean your account has been compromised.

What matters is what happened next.

If you simply opened a page but didn’t enter information, download anything or install software, the NCSC says further action may be unlikely to be necessary, although you should remain alert for suspicious account activity.

If you entered information or installed something, you should take further action.

What If You Entered Your Password?

Change the password for the affected account as soon as possible using the service’s genuine website or app.

If you’ve reused that password on other accounts, those accounts may also be at risk.

Change the reused passwords too.

Read:How to Create a Strong Password You Can Actually Remember

This is exactly why every important account should have a different password.

We can internally link this section to our existing article:

How to Create a Strong Password You Can Actually Remember

What If You Entered Banking Details?

Contact your bank immediately through its official contact method.

Don’t wait to see whether money disappears.

The NCSC recommends contacting your bank if you’ve provided banking details to a scammer.

The faster you respond, the sooner the bank can advise you on appropriate protective steps.

What If You Downloaded Something?

If a suspicious message persuaded you to download a file or install software, take the situation seriously.

The NCSC recommends running a full antivirus scan where appropriate if you’ve opened a suspicious link or followed instructions to install software.

For a work computer or phone, contact your organisation’s IT or security team promptly.

Use Two-Step Verification

Two-step verification—also called two-factor authentication or 2FA—adds another layer of protection to an account.

Even if a criminal obtains your password, an additional authentication requirement may prevent them from signing in.

It isn’t perfect protection against every phishing technique, but it’s an important account-security measure.

Password Managers Can Help Too

Password managers aren’t only useful for remembering passwords.

They can sometimes help reveal phishing attempts because saved credentials are associated with particular websites.

If you’re on a fake website rather than the legitimate domain, a password manager may not automatically offer the saved login you expect.

That unexpected behaviour can be another reason to stop and inspect the website carefully.

A 10-Second Phishing Check

Before acting on an unexpected email, ask yourself:

Who actually sent it?

Was I expecting it?

Is it trying to rush or frighten me?

Where does the link really go?

Is it asking for money, passwords or personal information?

Can I verify the claim through the company’s official app or website instead?

Those few seconds can prevent a much larger problem.

Final Thoughts

The most dangerous phishing emails aren’t necessarily the ones that look obviously fake.

They’re the ones that look almost completely genuine.

A familiar logo, professional design and correct spelling can create a false sense of security.

Instead, pay attention to the request itself.

Unexpected urgency, unusual login requests, suspicious links, attachments, QR codes, payment requests and requests for sensitive information should all make you stop and verify the message independently.

And remember the simplest rule:

If you’re unsure, don’t click. Go directly to the organisation through a method you already trust.


Frequently Asked Questions

What is the easiest way to spot a phishing email?
Look at the actual sender address, consider whether you expected the message, check for unusual urgency and avoid unexpected links, attachments or requests for sensitive information.

Can a phishing email look completely genuine?
Yes. Modern phishing messages can use professional graphics, good grammar and convincing branding. Appearance alone isn’t enough to establish authenticity.

Should I click a link to check whether it’s genuine?
No. If you’re suspicious, independently visit the organisation’s official website or app instead.

Can QR codes be used for phishing?
Yes. QR codes can direct users to malicious websites, and the NCSC has warned about their increasing use in phishing emails.

What should I do if I entered my password on a phishing website?
Change the affected password immediately through the legitimate service. If the same password is used elsewhere, change those accounts as well.

Where can I report a phishing email in the UK?
Suspicious emails can be forwarded to the NCSC’s Suspicious Email Reporting Service at report@phishing.gov.uk

Leave a Comment