All guides

How to Spot Phishing Emails Before It's Too Late

A few seconds of scrutiny can save your accounts, your money, and your identity.

August 1, 2026

Check the sender, not just the display name

The name shown in your inbox can say anything β€” 'PayPal', 'Your Bank', 'Support'. What matters is the actual email address behind it. Hover over or tap the sender name and look at the domain: notifications@paypa1.com or support@bank.com.secure.net are red flags.

When in doubt, ignore the message and go to the website yourself by typing the address into your browser.

Beware urgency and threats

Phishing works by panic. 'Your account will be closed in 24 hours', 'Unusual login detected', 'Confirm immediately or you will lose access'. Legitimate companies rarely threaten you over email, and they never demand instant action to avoid losing everything.

Take a breath. Open the real website and check whether the message even makes sense.

Inspect every link before clicking

Hover over any button or link to preview the real destination without clicking. Look carefully: the visible text can say a trusted name while the link points somewhere else entirely. Shortened links and misspelled domains (amaz0n.com, paypa1.com) are common tricks.

Do not click links for account issues. Type the official address directly into your browser or use a bookmark.

Treat attachments with suspicion

Unexpected invoices, PDFs, or archive files (.zip, .rar) are a favourite way to deliver malware. A phishing email often pretends to be an order confirmation or a voicemail notification to make you open a harmful file.

If you were not expecting a file from that sender, do not open it. Confirm with the sender through another channel first.

What to do if you already clicked

If you entered a password on a fake page, change it immediately on the real website and enable two-factor authentication. If you shared payment details, contact your bank or card issuer right away. If you opened an attachment, run a security scan and consider a fresh password for your email account.

Report the message to your provider as phishing and delete it. The faster you act, the less damage a phishing attempt can do.