Disposable email Guides

How to spot a phishing email: the telltale signs

Updated 23 September 2026

Phishing imitates a trusted organisation to make you click, pay or hand over your login details. The messages are more and more polished, so here are the checks that expose them.

The most common scenarios

PretextWhat you're asked to do
Parcel waiting, unpaid delivery feePay a small amount by card
Bank account suspended, suspicious transactionLog in on a fake bank website
Fine, tax, refundEnter your card details
Mailbox full, password expiredType your email password
Invoice or quote attachedOpen a booby-trapped file
Message from a "colleague" or the bossMake an urgent transfer or buy gift cards

They all share the same mechanics: urgency, an immediate action and a link or attachment.

1. Look at the sender's address, not just the name

The display name ("Bank Customer Service") can be anything. Only the full address counts. Be wary of:

On mobile, tap the sender's name to reveal the real address.

2. Check links before clicking

On a computer, hover over the link without clicking: the destination appears at the bottom of the window. On mobile, a long press shows it. Read the domain just before the first slash: in https://mybank.com.customer-security.net/login, the real site is customer-security.net, not mybank.com.

The padlock in the address bar proves nothing: it means the connection is encrypted, not that the site is honest. Nearly all phishing sites have a valid certificate.

3. Be careful with attachments

The files most used as traps are archives (.zip, .rar, .iso), attached web pages (.html, .htm), Office documents that ask you to "enable macros", and disguised executables (invoice.pdf.exe). An unexpected invoice from a supplier you don't know stays unopened.

4. Spot the psychological pressure

A legitimate organisation never asks by email for your password, card PIN or a code received by text message.

5. Spelling mistakes are no longer enough

Fraudulent messages used to be full of mistakes. With translation and text-generation tools they are now often flawless and copy logos faithfully. So don't judge by the writing quality; rely on the checks above.

The right reflex: use the official channel

When in doubt, don't click the link in the message. Open the bank's, courier's or agency's app yourself, or type their address into the browser. If the alert is real, you'll find it in your account. For a colleague asking for a transfer, call them back on a number you already know.

QR codes and text messages

The same trap exists by text message (smishing) and QR code (quishing): a code stuck on a parking meter or sent in an email leads to a fake payment site. Before confirming anything, read the address your phone displays.

You clicked or entered information

  1. Change the password of the affected account immediately, and of any other account that used the same one.
  2. Turn on two-factor authentication if it isn't already.
  3. Call your bank on its official number if you entered card details: it can block the card.
  4. Scan the device with antivirus software if you opened an attachment.
  5. Report the message: the "Report phishing" button in your email helps the filters. In the UK you can also forward suspicious emails to report@phishing.gov.uk and texts to 7726; in the US, report to the FTC at reportfraud.ftc.gov.

Limit how widely your address circulates

The more your main address circulates, the more phishing it receives. Using a disposable address for one-off sign-ups reduces the number of lists it appears on, and therefore the attempts aimed at you.

Get a disposable address

Frequently asked questions

Is opening a phishing email dangerous?

Reading the message in an up-to-date email app is generally safe. The danger comes from clicking a link, opening an attachment or entering information. Also avoid loading remote images, which can confirm to the sender that your address is active.

Should I reply to or unsubscribe from a fraudulent email?

No. Replying or clicking an unsubscribe link in a fraudulent message confirms your address is read. Report it as phishing, then delete it.

How do I know if an email from my bank is genuine?

Don't trust the message itself. Log in to your bank through its app or by typing its official address: if the alert exists, it will show there. If in doubt, call the number on the back of your card.

Read next