Everything Student

How to Spot a Phishing Email

The warning signs of a scam email, and what to do instead of clicking the link.

Illustration of a fishing hook reaching into an email on a laptop screen, with a magnifying glass on one side and a shield with a checkmark on the other.

Quick Start

The short version. The details, tips, and FAQ are below.

  1. Don't click links or open attachments you weren't expecting.
  2. Read the sender's full email address, not just the name.
  3. Be suspicious of urgency, threats and requests for passwords or payment.
  4. Check by going to the real website or app yourself.
  5. If you clicked, change your password now and report the email.
From:Harborline Bank Supportsupport@harborline-secure-verify.netSubject:URGENT: Your account will be suspended in 24 hours!Dear Customer,We detected unusual activity on you're account.Please verify you're account informationsimmediately by clicking the button below.Verify My Account →Where the button really goes (hover to see it):http://harborline-secure-verify.net/verify?id=8841
A made-up example: a fake "Harborline Bank" email pressuring the reader to "verify" their account within 24 hours.
  1. Sender address — The actual email address the message came from, not just the display name — a mismatched or unusual domain paired with a familiar-sounding organization name is one of the clearest phishing signs.
  2. Urgency in the subject line — Language like "immediately" or a tight deadline is designed to make you act before you look closely — a real account issue rarely comes with a countdown.
  3. Generic greeting — "Dear Customer" instead of your actual name — an organization that already has your account would normally know it.
  4. Suspicious link or button — A button asking you to log in or "verify" something right now. Legitimate organizations rarely ask you to authenticate through a link inside an email.
  5. Spelling or grammar errors — Awkward wording is a common tell, though AI-written phishing increasingly gets the grammar right too — don't rely on this sign alone.
  6. The link's real destination — Hovering over a link (without clicking) shows where it actually goes, usually in your browser's status bar. Here the visible text says one thing, but the real address is a completely different domain.

A phishing email tries to get you to hand over a password, payment details or personal information by pretending to be someone you trust — a bank, your school, a delivery company, even a friend whose account was hacked. The diagram above marks the warning signs on a real-looking example.

Warning Signs

  • Urgency or fear. “Your account will be suspended in 24 hours” or “Unusual activity detected” is meant to make you act before you think.
  • A link to log in, or a request for payment details. Real organizations rarely ask you to sign in through an email link to fix something urgent.
  • A sender address that’s close but not exact. Read the whole domain: support@amaz0n-billing.com is not amazon.com.
  • A generic greeting. “Dear Customer” from a company that knows your name.
  • An unexpected attachment, especially a .zip, an .exe, or a document that asks you to “enable content” or “enable macros.”
  • A link that doesn’t go where it says. On a computer, hover over a link to see its real address before you click; on a phone, press and hold it.

One sign alone isn’t proof, but two or more together is a strong signal something is off.

Quick Red-Flag Checklist

Before you click, reply or download anything:

  • Does it pressure you to act now, or threaten a consequence if you don’t?
  • Does it ask you to log in, “verify” or pay through a link in the email?
  • Is the sender’s domain slightly different from the real organization’s?
  • Does it greet you generically instead of by name?
  • Is there an attachment you weren’t expecting?

If you can check two or more boxes, stop and verify it another way first.

How to Check Whether It’s Real

Don’t use anything in the email itself. Instead:

  • Open a new tab and go to the organization’s website yourself, or use an app or bookmark you already trust.
  • Call a number you already know is correct — never one from the suspicious email.
  • If something is really wrong with your account, you’ll see it when you log in the normal way.

Warning: Your school, your bank and real tech-support teams will never ask for your password or a one-time sign-in code by email, text or phone. Anyone who asks for either is a scammer.

If You Already Clicked

  1. Entered a password? Change it right away on the real site — and on every other account that uses the same password. Turn on two-step verification if you can.
  2. Entered card or bank details? Call your bank or card issuer now. Most can freeze or replace a card within minutes.
  3. Downloaded a file? Don’t open it. Run a security scan on that device.
  4. Report it. Use your email’s “Report phishing” button, forward school-related phishing to your school’s IT help desk, and report scams to the FTC at reportfraud.ftc.gov.

Acting quickly limits the damage far more than waiting to see what happens.

Frequently Asked Questions

What are the biggest red flags?

Urgency or fear ('your account will be closed in 24 hours'), a request to click a link and enter your password or payment info, a sender address that almost — but not exactly — matches a real company's domain, and generic greetings ('Dear Customer') instead of your actual name. Any one of these alone isn't proof, but two or more together is a strong signal.

The email looks like it's from my bank/school — how do I check if it's real?

Don't click anything in the email. Instead, open a new browser tab and go to the organization's website directly (or use an app/bookmark you already trust), or call a phone number you already know is real — never one provided in the suspicious email itself. If there's a real issue, it'll show up when you log in normally.

I already clicked a phishing link — what should I do?

If you entered a password, change it immediately on the real site (and on any other account using that same password). If you entered payment or bank info, contact your bank or card issuer right away to flag possible fraud. Run a security scan if you downloaded anything. Acting quickly limits the damage far more than waiting.

Can a phishing message come from someone I actually know?

Yes — if a friend's, classmate's, or coworker's account was itself hacked, a phishing message can come from a real, familiar address. An unexpected link or request, even from someone you trust, is worth double-checking with them a different way (text or call) before acting on it.

Does phishing only happen over email?

No — the same tactics happen over text ("smishing") and phone calls ("vishing"), including fake IRS, delivery, or bank calls/texts. The same core rule applies regardless of the channel: don't act on urgency alone, and verify independently before clicking, replying, or giving out information.

How can I see a link's real destination before clicking it?

On a computer, hover your mouse over the link (without clicking) and the real URL usually appears in your browser's status bar. On a phone, press and hold the link to preview the destination before opening it.

Where can I report a phishing email?

Most email providers have a built-in "Report phishing" option — using it helps flag the sender for other users too. In the U.S., you can also report phishing and other scams to the FTC at reportfraud.ftc.gov.

Sources

Home