Phishing red flags: how to spot a fake email, text or breach notice

Breach / exposure. Updated 2026-09-13. About 6 minutes to read.

Check two things before anything else: the real sender domain after the @ sign, and the real destination of the link. Those checks catch most phishing in under ten seconds.

Most phishing no longer looks like a badly written windfall letter. It looks like a parcel notice, a toll charge, a password reset you did not request, or an email saying your data was leaked. The writing is clean, the logo is right, and the only thing wrong is the part nobody reads: the sender domain and the link target.

This guide puts the checks in the order that catches the most fakes for the least effort. The first two take about five seconds each and settle most suspicious messages. The rest are for the ones that survive the first pass.

If you have already clicked something, skip ahead to the reporting section and then follow our phishing email response steps. Speed matters more than diagnosis once a password is involved.

The red flags that actually appear in real phishing

These are ordered by how often they turn up, not by how dramatic they sound. Spelling mistakes sit near the bottom, because modern phishing kits are proofread and many are written with AI tools.

  • A sender domain that is close but not exact: paypal-secure-login.com, microsoft-account.net, auspost-delivery.info.
  • Urgency with a deadline attached: 24 hours to confirm, account closing today, parcel returning to sender.
  • Link text that does not match where the link actually goes.
  • A push to move somewhere less traceable: a phone number to call, a chat app, a QR code.
  • An attachment you did not expect, especially .html, .htm, .zip, .iso, or a document asking you to enable editing or macros.
  • A request for a one time code that was just texted to you, or for your password to verify your identity.
  • A change of payment details inside a real invoice thread, which is how business email compromise usually lands.
  • A generic greeting on an account that knows your name, or your full email address used as the salutation.

Read the sender domain, not the display name

The display name is free text. Anyone can set it to Apple Support, your bank, or your own manager. What matters is the part after the @ sign, and on a phone it is usually hidden until you tap the name.

  1. Tap or hover over the sender name to reveal the full address.
  2. Read the address from the right. The true domain is the last two labels before the end. In accounts@bank.com.verify-secure.net the real domain is verify-secure.net.
  3. Look for inserted words and hyphens. Real companies send from their own domain or a clearly branded sending domain, not from a hyphenated variant registered last week.
  4. Check whether the Reply-To address differs from the From address. That mismatch means your reply goes somewhere else.

Check the link before you tap it

On a computer, hover over the link and read the status bar at the bottom of the window. On a phone, press and hold until a preview appears, read the domain, then cancel. Never judge a link by its text, because the text can say anything.

  1. Read the domain immediately before the first single slash. Everything after that slash is decoration the attacker controls.
  2. Treat shorteners such as bit.ly and tinyurl as unknown. Real transactional mail rarely needs them.
  3. Watch for open redirects, where a genuine domain appears first and the true destination hides in a parameter such as ?url= or ?redirect=.
  4. Treat a QR code in an email exactly like a link. Codes move the destination off screen so mail filters cannot read it, which is why QR phishing works.
  5. If you still need to know, copy the address without opening it and paste it into a link checker or the Google Safe Browsing site status page.

Do not use the unsubscribe link in a suspicious email. On a phishing message it simply confirms that a human reads that address.

Headers tell the truth in about 60 seconds

Email authentication results are written into every message. They are the closest thing to a verdict you can get without contacting the sender yourself.

  1. In Gmail, open the message, click the three dot menu and choose Show original.
  2. In desktop Outlook, open the message and choose File, then Properties, then read the Internet headers box.
  3. Find the Authentication-Results line and read the spf, dkim and dmarc results.
  4. A message claiming to be from a large bank or platform that shows dmarc=fail should be treated as fake, because those organisations publish strict email policies.
  5. Compare the Return-Path domain with the From domain. A mismatch on transactional mail is a strong warning.

Breach themed phishing and the old password extortion email

Scammers follow the news. After any large breach, a wave of mail goes out claiming to be the breached company and offering a checker, a compensation form or a forced password reset. The link leads to a credential harvesting page that looks exactly like the real login screen.

The other version quotes a real password of yours in the subject line and claims your webcam was recorded. That password came from a public breach dump, not from your computer. There is no footage. Change that password anywhere it still works, then delete the email and never reply.

When a company genuinely is breached, reach its site by typing the address yourself. Never use the link in the notification, even when the notification is real.

Text and voice variants: smishing, vishing and the code request

  • Scam texts favour tolls, parcels, bank holds and job offers, because almost everyone is expecting one of those.
  • A text asking you to reply Y to activate a link is a trick. iPhone disables links from unknown senders until you reply, and replying also confirms your number is live.
  • Vishing calls spoof the number printed on your card. Caller ID proves nothing. Hang up and dial the number on the card yourself.
  • The code request is the giveaway. A one time code sent to you is for you alone. No bank, carrier, courier or government agency will ask you to read it back.
  • A caller who knows your address, date of birth and recent purchases is not verified. That detail is sold by people search sites and leaked in breaches.

Report it so the next person gets blocked

  • United States: forward the email to reportphishing@apwg.org and file at ReportFraud.ftc.gov. Forward scam texts to 7726.
  • United Kingdom: forward emails to report@phishing.gov.uk, the NCSC Suspicious Email Reporting Service, and forward scam texts to 7726.
  • Australia: report at scamwatch.gov.au and, if you lost money or data, at cyber.gov.au. Telstra customers can forward scam texts free to 7226, and anyone can forward spam texts to the ACMA on 0429 999 888.
  • In Gmail use the three dot menu and Report phishing. In Outlook use Report, then Report phishing. Reporting inside the mail app trains the filter for everyone on that platform.
  • If it arrived at a work address, tell IT even if you did nothing. Phishing arrives in waves and you are almost never the only recipient.

Frequently asked questions

Can I get hacked just by opening a phishing email?

Opening a message in a current mail app is normally safe. Images may load and tell the sender that the address is live, which is why blocking remote images is worth doing, but reading text does not install anything. The risk starts when you click a link, open an attachment, enable macros in a document, or type credentials into the page the link opens.

I clicked the link but did not type anything. Am I safe?

Almost certainly. Close the tab, enter nothing, and run a full scan with the security software you already have. If the page pushed a download, delete the file without opening it. If it impersonated your bank, change that password anyway as a cheap precaution.

I entered my password. What do I do now?

Change that password on the real site immediately, then change it anywhere you reused it. Sign out of all active sessions, turn on multi factor authentication using an authenticator app or passkey, and check your mailbox for new forwarding rules or filters. Attackers often add silent forwarding rules soon after taking an inbox.

How do I check whether a link is safe without clicking it?

Copy the link without opening it, by long pressing and choosing copy on mobile or right clicking and choosing copy link address on a computer. Paste it into a link checker. A clean result means not yet known to be malicious, which is not the same as proven safe.

Tools that help

Related guides

Sources