How to spot phishing emails before you click
Most phishing is caught with three quick checks. Here's what to look for and what to do if you slip.
By SafePass.pro Team · Published · Updated · 6 min read
A phishing email is a fake message that impersonates a company or person you trust to trick you into handing over passwords, payment details, or access. You can usually spot one by checking three things: the real sender address, the true destination of any link, and whether the message manufactures urgency. When in doubt, don't click — go to the site directly instead.
What is a phishing email?
Phishing is a social-engineering attack that uses a convincing fake message to steal credentials or money, or to install malware. The Cybersecurity and Infrastructure Security Agency (CISA) describes it as attackers posing as a trusted source to manipulate you into acting.
How can I tell if an email is phishing?
Run three fast checks before you trust any unexpected email:
- The sender — does the address (not just the display name) match the company's real domain?
- The links — when you hover, does the URL go where it claims, or to a look-alike domain?
- The pressure — is the message rushing you with threats, deadlines, or "verify now" demands?
If any check fails, treat the message as hostile.
What are the most common phishing red flags?
- Look-alike sender domains, such as
paypa1.cominstead ofpaypal.com, or extra subdomains likepaypal.security-verify.com. - Generic greetings ("Dear Customer") instead of your name.
- Urgency and fear: "Your account will be closed," "unauthorized login detected," or "payment failed."
- Unexpected attachments, especially
.zip,.exe, or.htmlfiles. - Requests to confirm a password, one-time code, or payment details.
- Links whose visible text doesn't match the real destination URL.
How do I check if a link is safe before clicking?
Hover over the link on a computer, or long-press it on a phone, to preview the real URL without opening it. Compare the domain carefully against the official one, and watch for look-alike characters and extra words bolted onto a trusted brand name.
When you genuinely need to act, type the company's address into your browser yourself — never use the link in the email.
What should I do if I clicked a phishing link or entered my password?
Act quickly to limit the damage. Follow these steps in order:
- Stop and disconnect. Don't enter any more information, and close the page.
- Change the password on the real site. Go directly to the legitimate site and reset it — and change it anywhere you reused that password.
- Turn on two-factor authentication. Add a second factor so a stolen password alone can't grant access.
- Check for exposure. Look up your email on Have I Been Pwned to see related breaches.
- Report it and watch for fraud. Report the message (below) and monitor your accounts and statements.
How do I report a phishing email?
Mark the message as phishing in your email client so the provider can filter similar attacks. In the U.S., report scams to the FTC at reportfraud.ftc.gov and forward phishing to the Anti-Phishing Working Group at reportphishing@apwg.org. The FTC's guide walks through recognizing and reporting these scams.
Strong, unique passwords and 2FA limit the blast radius if you ever do slip. Generate credentials with SafePass.pro and review our password security tips.
Frequently asked questions
Can opening a phishing email infect my device?
Simply reading the text of an email is usually safe. The danger comes from clicking links, opening attachments, or enabling content, so avoid interacting with anything in a suspicious message.
How did attackers get my email address?
Email addresses are commonly exposed in data breaches, scraped from websites, or bought from data brokers. You can check whether your address has appeared in a known breach using Have I Been Pwned.
Are phishing text messages (smishing) the same thing?
Yes. Smishing is phishing delivered by SMS, and vishing is phishing by phone call. The same red flags apply: an unexpected sender, a link or request, and pressure to act fast.
Does two-factor authentication protect me from phishing?
It helps a lot, because a stolen password alone is no longer enough. For the strongest protection, use phishing-resistant methods such as passkeys or hardware security keys, which can't be replayed on a fake site.