How to spot a phishing email
Phishing emails try to rush you into clicking a link or handing over a password. Once you know the tells, they're surprisingly easy to catch. Here are the seven biggest ones.
1. The sender's address doesn't match the name
The display name might say “Apple Support,” but the actual address is something like support@apple-account-verify.com. Always expand the real address. Big companies send from their own domain — not a lookalike with extra words.
2. It creates urgency or fear
“Your account will be closed in 24 hours.” “Suspicious login — act now.” Scammers want you reacting, not thinking. A real company gives you time and never threatens instant loss over email.
3. The link text and the real destination differ
Hover over (or long-press on mobile) any link before tapping. If the button says paypal.com but the address that appears is anything else, stop. You can paste it into our checker on the home page to see the red flags.
4. It asks for a password, code, or payment
Legitimate companies never email you a link to “confirm your password” or ask for a one-time code. A one-time code is yours alone — anyone asking for it is trying to break in.
5. Generic greetings and odd wording
“Dear Customer,” awkward grammar, or slightly-off logos are common. Modern scams can look polished, so treat this as a supporting clue, not proof on its own.
6. Unexpected attachments
Invoices, “voicemails,” or shipping documents you weren't expecting — especially .zip, .html, or files that ask you to “enable content” — are a classic malware delivery method. Don't open them.
7. It's too good (or too strange) to be true
Refunds you didn't request, prizes you didn't enter, a colleague suddenly needing gift cards. When something feels off, verify through a channel you trust — not the email itself.
Stay a step ahead
Get a short weekly email on the scams going around right now.