Online Safety

How to Recognize Phishing Emails and Fake Websites

The patterns that give away fraudulent messages and lookalike sites, with real-world example structures.

What Phishing Actually Is

Phishing is a message — usually an email, but sometimes a text or phone call — designed to trick you into revealing credentials, payment details, or other sensitive information, or into installing malware. It works by impersonating someone or something you trust: a bank, a delivery service, an employer, or even a colleague. The goal is almost always to get you to act quickly, before you've had time to verify whether the request is genuine.

Checking the Sender, Not Just the Name

Email clients display a sender's name prominently, but that name is easy to set to anything at all — it doesn't verify identity. The actual email address behind the display name is far more informative. A message claiming to be from a well-known company but sent from a generic public email domain, or from a domain with extra words or misspellings inserted, is a strong warning sign. Most email apps let you tap or hover over the sender's name to reveal the underlying address.

Urgency and Emotional Pressure

Phishing messages are built around urgency: an account that will be suspended in 24 hours, a package that failed delivery and needs "confirmation," an invoice that's overdue, or an executive requesting an immediate wire transfer. This pressure is deliberate — it's meant to short-circuit the pause where you'd normally double-check something. A useful habit is to treat urgency itself as a signal to slow down rather than speed up.

On a computer, hovering the mouse pointer over a link (without clicking) typically shows the actual destination URL in the corner of the screen or browser. On a phone, a long-press often reveals the same information. Look specifically at the domain name — the part directly before the first single slash after "https://" — since everything after that can be crafted to look reassuring. A link like https://accounts.google.com.secure-verify.example/ is not actually a Google address; the real domain is secure-verify.example, with "accounts.google.com" added only to look familiar.

Unexpected Attachments

Unexpected attachments — particularly ZIP files, disk images, or Office documents that prompt you to "enable macros" or "enable content" — are a common malware delivery method. Legitimate organizations rarely ask you to enable macros to view a routine document. If an attachment is unexpected, verify with the sender through a separate channel before opening it, especially if the surrounding message uses urgent language.

Spotting Lookalike Websites

Fake websites built to harvest login credentials often mimic a real company's design closely. A few checks help: confirm the domain name character by character rather than skimming it, check that the connection uses HTTPS (though note this alone doesn't guarantee legitimacy — attackers can secure fake sites too), and be cautious of sites reached only through a link in an email or text rather than one you navigated to directly or found through a trusted search.

Spear Phishing and Business Email Compromise

Not all phishing is generic. Spear phishing targets a specific person using personal or organizational details — your real name, job title, or a project you're actually working on — gathered from public sources like social media or company websites. Business email compromise takes this further, often impersonating a real executive or vendor to request a wire transfer or gift cards. Because these messages are tailored, they can lack the obvious red flags of mass phishing, which makes verifying unusual requests through a separate channel (a phone call, an in-person check) especially important in a workplace setting.

What to Do If You Suspect Phishing

  • Don't click links or open attachments in the message.
  • Verify the request by contacting the organization directly, using a phone number or website you already know — not one from the message itself.
  • Report the message using your email provider's "report phishing" option, which helps improve spam filtering for others.
  • Delete the message once you've verified it isn't legitimate.

If You've Already Clicked or Entered Details

If you've entered a password on a suspected fake site, change that password immediately on the real site, and on any other account where you reused it. If you've entered payment details, contact your card issuer or bank to discuss next steps. If you've opened an attachment or downloaded a file, run a full scan with your security software and consider disconnecting from the network until the scan completes, since some malware attempts to spread or communicate immediately.

Frequently Asked Questions

Can phishing happen over text message or phone calls, not just email?

Yes. Phishing over text message is often called 'smishing,' and over phone calls, 'vishing.' The same core tactics apply — a false sense of urgency, impersonation of a trusted organization, and a request for credentials, payment, or remote access.

Do phishing emails still contain obvious spelling mistakes?

Some do, but many are now well-written and visually convincing, sometimes copying a real company's branding almost exactly. Because of this, checking the sender's actual email address and the true destination of links matters more than looking for typos alone.

Is it safe to reply to a suspected phishing email to ask if it's real?

It's better not to reply directly, since this confirms your address is active and being read, which can lead to more targeted attempts. Instead, contact the organization through a phone number or website you already know is legitimate — not one provided in the suspicious message.

Advertisement space