Phishing doesn't look like it used to — the obvious spelling errors and clumsy formatting are mostly gone. A few signals still hold up.
Fabricated example — not a real message
Our records show your mailbox has exceeded its storage limit. Verify your account now to avoid interruption of service.
Verify my account→ yourorg-helpdesk.net/verify
mailbox-report.zip
Display name doesn't match the domain
The name reads like your own IT team; the address is a lookalike domain nobody at your organization owns.
Manufactured urgency
A deadline measured in hours exists to stop you checking. Real vendors rarely apply this kind of pressure by email.
Link text hides the destination
Hovering shows where it actually goes. A domain that's almost right is the whole trick.
An attachment you weren't expecting
Invoices, shipping notices, and "signed documents" are the most common payloads, especially as compressed files.
Urgency is the tell, not the typos
"Your account will be suspended in 24 hours" or "Action required immediately" is designed to make you act before you think. Legitimate organizations rarely create that kind of pressure over email.
Check where a link actually goes
Hovering over a link (without clicking) shows the real destination. A mismatch between the display text and the actual URL — or a domain that's almost, but not quite, right — is a strong warning sign.
Unexpected attachments, especially invoices
An invoice, shipping notice, or "signed document" you weren't expecting is one of the most common phishing payloads, particularly when it arrives as a compressed file.
When in doubt, verify out of band
If an email claims to be from a vendor, your bank, or a coworker asking for something unusual, confirm through a different channel — a phone call or a separate message — before acting.
The goal isn't to be suspicious of every email. It's to slow down for the ones asking you to act fast.

