Skip to main content
CybersecurityArticleBeginner2 min readUpdated

How to Recognize a Phishing Attempt Before You Click

Phishing emails have gotten harder to spot. These are the signals that still give them away.

Written by

Zach Swartz, Business Technology Advisor

Zach Swartz

Business Technology Advisor · Great Falls, Montana

Phishing doesn't look like it used to — the obvious spelling errors and clumsy formatting are mostly gone. A few signals still hold up.

Fabricated example — not a real message

FromIT Support<it-support@yourorg-helpdesk.net>
SubjectAction required: your mailbox will be disabled in 24 hours

Our records show your mailbox has exceeded its storage limit. Verify your account now to avoid interruption of service.

Verify my account→ yourorg-helpdesk.net/verify

mailbox-report.zip

  1. Display name doesn't match the domain

    The name reads like your own IT team; the address is a lookalike domain nobody at your organization owns.

  2. Manufactured urgency

    A deadline measured in hours exists to stop you checking. Real vendors rarely apply this kind of pressure by email.

  3. Link text hides the destination

    Hovering shows where it actually goes. A domain that's almost right is the whole trick.

  4. An attachment you weren't expecting

    Invoices, shipping notices, and "signed documents" are the most common payloads, especially as compressed files.

A fabricated example, marked up. The sender and domain are invented — the four signals are the ones that still hold up.

Urgency is the tell, not the typos

"Your account will be suspended in 24 hours" or "Action required immediately" is designed to make you act before you think. Legitimate organizations rarely create that kind of pressure over email.

Check where a link actually goes

Hovering over a link (without clicking) shows the real destination. A mismatch between the display text and the actual URL — or a domain that's almost, but not quite, right — is a strong warning sign.

Unexpected attachments, especially invoices

An invoice, shipping notice, or "signed document" you weren't expecting is one of the most common phishing payloads, particularly when it arrives as a compressed file.

When in doubt, verify out of band

If an email claims to be from a vendor, your bank, or a coworker asking for something unusual, confirm through a different channel — a phone call or a separate message — before acting.

The goal isn't to be suspicious of every email. It's to slow down for the ones asking you to act fast.

Not sure where your organization stands?

The Business Success Assessment covers this topic and more, with results in about 7–10 minutes.