ToolboxKit

How to Spot Phishing Emails and Texts: 6 Warning Signs That Work

Phishing is one of the oldest tricks on the internet, and it still works because it targets people rather than software. A message arrives that looks like it came from your bank, a delivery company, your employer, or a streaming service. It asks you to click a link, open an attachment, or "confirm" some details. The goal is almost always the same: steal a password, a payment card number, or access to an account.

The good news is that you do not need to be a security expert to catch most of these. You just need a few habits and the patience to pause for ten seconds before acting.

1. Urgency and Pressure

Scammers want you to act before you think. Phrases like "your account will be closed in 24 hours," "unusual activity detected," or "final notice" are designed to trigger panic. Legitimate organizations do sometimes send time-sensitive messages, but they rarely threaten you with immediate consequences through an unexpected link.

The more urgent a message feels, the slower you should go.

2. A Sender Address That Is Slightly Off

The display name can say anything, such as "Your Bank Support." What matters is the actual address behind it. Look for misspelled domains (an extra letter or a swapped character), free email addresses used by supposedly large companies, and unrelated domains that merely start with a familiar brand name.

On a phone, tap the sender's name to reveal the full address.

3. Links That Do Not Match Their Text

A link can read "yourbank.com" while pointing somewhere else entirely. On a computer, hover over the link without clicking and look at the address shown at the bottom of the window. On a phone, press and hold to preview it. If the destination looks unfamiliar or is a shortened link you cannot verify, do not open it.

4. Requests for Sensitive Information

Reputable companies generally do not ask you to send passwords, full card numbers, one-time codes, or security answers by email or text. If a message asks for any of these, treat it as suspicious, no matter how professional it looks. One-time verification codes in particular should never be read out to someone who contacted you.

5. Unexpected Attachments

Invoices, "voicemails," shipping labels, and "documents shared with you" are common disguises for malware. If you were not expecting a file, do not open it. Even a known sender may have been hacked, so confirm through another channel.

6. Contact That Moves to a Different Channel

Scammers often start with an email and then push you to a messaging app, a phone call, or a remote-access program. Be especially cautious if someone asks you to install software so they can "help" you with a problem you did not report.

What to Do When You Are Not Sure

Build a simple routine and use it every time:

  1. Stop. Do not click, reply, or call any number in the message.
  2. Go directly to the source. Open the official website by typing the address yourself, or use the company's official app. Check for notifications there.
  3. Use a trusted contact method. Look up the phone number on your card, a recent statement, or the official site, not in the message.
  4. Report it. Most email providers have a "report phishing" option, and many organizations accept forwarded scam messages. Then delete the message.

If You Already Clicked

Change the password on the real site (and anywhere you reused it), turn on two-factor authentication, call your bank on an official number if you shared card details, and watch your accounts for unfamiliar activity.

Make Phishing Less Damaging in Advance

You cannot prevent every scam message from arriving, but you can reduce the harm if one succeeds. Using a unique password for every account means one stolen password does not unlock everything. A password manager helps you keep track of them, and a generator makes it easy to create long random ones. If you need one, you can try our Password Generator, which runs in your browser.

The Short Version

Be wary of urgency, check the real sender and link, never share codes or passwords on request, and verify through a channel you found yourself.