How to spot phishing in emails and texts
Bad grammar is no longer the giveaway. These are the signs that still work – and the one habit that makes the whole category of attack fail.
- Do not tap the link and do not reply.
- Do not open attachments – especially archives or office files.
- Verify through your own channel: open the app or type the address yourself.
- Delete and report the message, then block the sender.
Phishing works because it borrows trust you have already given to someone else – your bank, a delivery company, your employer. The message does not have to be perfect. It only has to be plausible for the three seconds it takes you to tap a link.
What still gives it away
Warning signs that hold up
- An unexpected request for money, login or personal data – the core of every phishing attempt.
- Time pressure: “within 24 hours”, “your account will be closed”, “final notice”.
- A link that does not match the sender – check the real domain before the first single slash.
- A payment demanded through the message rather than through your normal account.
- An attachment you did not expect, particularly a ZIP archive or a file asking you to enable content.
- A sender address that only looks right – a lookalike domain rather than the real one.
- Requests for codes or one-time passwords. No legitimate organization ever asks for these.
Read the link, not the label
The visible text of a link is just a caption. What matters is the actual domain, which sits immediately before the first single slash:
| Address | Real domain | Verdict |
|---|---|---|
https://www.yourbank.com/login | yourbank.com | genuine |
https://yourbank.com.secure-login.top/ | secure-login.top | fake |
https://yourbank-security.com/verify | yourbank-security.com | unrelated domain |
Everything before the real domain can be invented freely. A brand name followed by a dot is not a guarantee – it is just a subdomain someone else controls. The full method is in check a link before you click .
The habit that makes phishing fail
Never act through the message. Always act through a channel you opened yourself. Type the address, or use the app. This single habit defeats every phishing variant at once, no matter how convincing the message is – and it costs you about five seconds.If you already entered something
- Credentials: change the password, then end all active sessions, then enable two-factor authentication – in that order. Full steps in account hacked .
- Card or payment details: contact your bank immediately and have the card blocked.
- An installed app or file: disconnect the device from the network and have it checked before using it again.
- Nothing entered: close the page. Expect more attempts at that address.
Making yourself a harder target
- A password manager only fills credentials on the genuine domain – which makes it a quiet, automatic phishing filter: Password managers explained .
- Two-factor authentication means a stolen password alone is not enough: How to set it up .
- Regular session checks catch a takeover early: Check active sessions .
Frequently asked questions
Aren't phishing emails easy to spot by the bad spelling?
Not any more. Modern scam messages are written fluently, often with correct branding and real details about you taken from data breaches. Judge the request and the link, not the writing style.
I clicked a link but didn't type anything. Am I in trouble?
Usually not. The click mainly confirms that your address is active, so expect more attempts. It becomes serious if you entered credentials or payment details, or installed something.
How can I check whether a message from my bank is real?
Never through the message itself. Open your banking app or type the address you normally use, and look for the same notice there. If it is genuine, it will be waiting for you.