Spotting Phishing Emails Before They Cause Trouble

Why Phishing Still Catches People Out
Phishing emails are nothing new, yet they still work — otherwise the criminals behind them would have moved on long ago. The reason is simple: they are no longer clumsy notes full of broken English. Modern attempts copy the layout, colours and wording of genuine messages from banks, delivery firms, energy suppliers and software providers so closely that even careful people pause. Add a busy morning, a phone screen, and a line saying your account will be closed within two hours, and it is easy to click before thinking.
The good news is that most phishing emails give themselves away if you know where to look. You do not need specialist software or a technical background — just a handful of habits you can apply in under a minute.
Start With the Sender Address, Not the Name
The display name at the top of an email is almost meaningless. Anyone can set it to "Your Bank Security Team" or "Delivery Updates" in seconds. What matters is the actual address hiding behind it.
- On a phone, tap the sender name to reveal the full email address. On a computer, hover over it or click the small arrow.
- Look at the domain — the part after the @ symbol. Genuine messages come from the organisation's own domain, not from a free webmail account or a random string of letters.
- Watch for lookalike domains: a letter swapped for a number, an extra hyphen, or a word spelled almost but not quite right.
- Be wary when the reply-to address differs from the sender. That is a classic sign that your reply will go straight to the criminal.
If the address looks wrong, stop there. You do not need to read the rest of the message.
Hover Before You Click
Links are where phishing does its damage. Text that reads like a familiar web address can point anywhere at all.
On a computer, rest your mouse over the link without clicking and the real destination appears in the bottom corner of the window. On a touchscreen, press and hold the link to see a preview — or simply avoid tapping altogether and visit the organisation's website by typing its address yourself. That last habit is the safest of all.
- Check the domain just before the first single slash. That is the site you will actually land on.
- Treat shortened links and long strings of numbers with suspicion, especially in messages you were not expecting.
- Never log in to an account by following a link in an email. Open your browser, type the address you know, and sign in there.
- Be especially careful with links asking you to confirm payment details, reset a password, or verify a card.
Urgency and Secrecy Are Warning Signs
Genuine organisations rarely demand instant action by email. Phishing relies on pressure, because a panicking person does not stop to check details.
Be suspicious of messages that threaten account closure within hours, unpaid fines, cancelled deliveries or a suspended licence. The same goes for anything that asks you to keep quiet — a "confidential" payment, a "private" transfer, a request not to mention it to family or colleagues. Real businesses and government departments simply do not operate that way.
Other details worth noticing:
- Generic greetings such as "Dear Customer" instead of your actual name.
- Spelling, grammar or spacing that feels slightly off, though plenty of scams are now well written.
- A sudden change of bank details on an invoice, or a request to pay by bank transfer, gift card or cryptocurrency only.
- Attachments you were not expecting, particularly invoices, receipts or "secure" documents.
Requests for Passwords or Payment Details
No legitimate bank, broadband provider, energy company, tax office or IT department will ask you to confirm your password, your full card number, your PIN or a one-time security code by email. Not ever, and not "for security purposes".
If someone contacts you out of the blue and asks for any of that, treat it as a scam regardless of how professional the message looks. If you are worried it might be genuine, hold back and check through a channel you have chosen yourself — the phone number on your statement, your bill, or the company's official website. Do not use the contact details printed in the email.
It also helps to switch on two-factor authentication for your important accounts. Even if a password is stolen, a code sent to your phone or an authenticator app will usually stop the criminal getting in.
If You Think You Have Been Caught
Act quickly, and do not be embarrassed — these messages are built by people who do this for a living, and they catch smart, busy people every day. If you have entered a password, change it straight away on that account and anywhere else you have reused it. If you have handed over card details, ring your bank using the number on the back of your card and explain what happened.
Report the suspicious email to your email provider and to the National Cyber Security Centre's reporting service, then delete it. If a work account is involved, tell your IT support immediately — the sooner they know, the less damage a compromised mailbox can do.
Above all, slow down. A few seconds spent checking the sender address, hovering over a link and asking "did I actually expect this?" will stop the vast majority of phishing attacks from ever reaching your passwords or your money.
Joeby Ragpa
This template is so awesome. I didn’t expect so many features inside. E-commerce pages are very useful, you can launch your online store in few seconds. I will rate 5 stars.
ReplyAlexander Samokhin
This template is so awesome. I didn’t expect so many features inside. E-commerce pages are very useful, you can launch your online store in few seconds. I will rate 5 stars.
ReplyChris Root
This template is so awesome. I didn’t expect so many features inside. E-commerce pages are very useful, you can launch your online store in few seconds. I will rate 5 stars.
Reply