How to spot a phishing email β the tells to check
A phishing email pretends to be from a bank, a delivery firm, your workplace, or some other organisation you trust, and tries to get you to hand over a password, a payment, or access to an account. Most give themselves away through the same handful of signs, once you know where to look. These checks apply whatever you read your email in β Gmail, Outlook, Apple Mail, or any other app.
What you'll need: The suspicious email open in front of you. Nothing needs installing, and don't click anything in the email while you work through this.
Check the sender's actual email address, not just the display name
Email apps show a display name β "PayPal", "HMRC", "Your Bank" β rather than the address it was sent from. Tap or click on the sender's name to reveal the full address underneath. A message claiming to be from PayPal but sent from [email protected] is not from PayPal. Look closely at the domain (the part after the @): scammers often swap a letter for a similar one, add extra words, or use a completely unrelated domain.
Look for urgency or a threat
Phishing emails push you to act before you've had time to think: "your account will be suspended in 24 hours", "unusual sign-in detected β verify now", "final notice: payment overdue". Genuine organisations occasionally do send time-sensitive messages, but a demand for immediate action combined with a request for personal details or a payment is one of the strongest signs of a fake.
Check whether the greeting and details match you
A message from an organisation that actually holds your details usually addresses you by name and can reference something specific β an order number, the last four digits of an account. A generic "Dear Customer" or "Dear User" from a company that should know your name is worth treating with suspicion, especially alongside anything from the earlier steps.
Hover over links before clicking β don't tap them on mobile
On a computer, rest your mouse pointer over any link without clicking. The real destination appears in a small preview, usually in the bottom corner of the browser or email app window. If the text says "Sign in to your account" but the preview shows an unfamiliar domain, that's where clicking would actually take you.
Be wary of unexpected attachments
An invoice, delivery notice, or document you weren't expecting β particularly a compressed file (.zip) or one that asks you to "enable content" or "enable macros" to view it β is a common way to install malware. If you weren't expecting a file from that sender, don't open it. Confirm it's genuine with the sender through a different channel first.
Look for spelling, grammar, and design inconsistencies
Not every phishing email is badly written β some are convincing β but many still carry small signs: odd phrasing, a logo that's slightly the wrong size or colour, inconsistent fonts, or formatting that doesn't quite match the organisation's usual emails. None of these alone proves anything, but several together are a reason to slow down.
Verify through a separate channel
If the email claims to be from your bank, your workplace, or a service you use, don't reply to it or use any phone number or link it provides. Instead, go directly to the organisation's website by typing the address yourself, or call the number printed on your card or a previous genuine statement. Ask them directly whether the message is real.
Variations
The same tells apply to text messages claiming to be from a delivery company, bank, or government department. A text is harder to inspect than an email β there's no sender address to check, only a phone number or short name β so treat any text with a link asking you to "confirm", "verify", or "pay a fee" with the same caution, and go to the organisation's website directly rather than tapping the link.
A caller claiming to be from your bank's fraud team, HMRC, or tech support, asking you to move money, read out a one-time passcode, or install remote-access software, is using the same pressure tactics by voice. Hang up and call the organisation back on a number you already know to be genuine β never one the caller gives you.
Most phishing goes out to thousands of addresses at once and relies on generic bait. A targeted version uses details a scammer has found about you β your employer, your job title, a colleague's name β to seem far more credible. It often looks like an urgent request from a manager or supplier. The sender address and verification steps above still apply; targeted attacks just make step 3's "does this match what they'd know about me" check less reliable on its own.
Troubleshooting
Change the password for that account immediately, from a device you trust, and turn on two-factor authentication if it isn't already on. If you entered card details, contact your bank to have the card blocked and reissued. If you reused that password anywhere else, change it there too.
Email accounts and contact lists get compromised. If a message from a known contact feels off β an unusual request for money or gift cards, a link with no explanation, wording that doesn't sound like them β confirm with them directly through a phone call or a different messaging app before acting on it.
When every visible sign checks out, the sender address is still the most reliable single check β a scammer can copy a logo perfectly but has to send from a domain they control. If it still doesn't feel right after that, contact the organisation directly using details you already have, rather than anything in the email, and ask.
Need a calculator rather than a guide? Try Simplicalcs β