Advertising disclosure: this site carries partner links. If you buy through one, DALAMIS s.r.o. earns a commission from the seller. It costs you nothing extra, and it does not change what we write. How we work.

orviden.onlineIndependent security guidance
Guide

Spotting phishing and scam emails

This is the threat where software helps least and habit helps most — because nothing malicious is ever downloaded. You simply type your password into the wrong box.

Why filters cannot finish the job

A phishing page is, technically, an ordinary web page. It contains no malware for a scanner to find. Web-filtering layers block addresses already reported as fraudulent, which catches a great deal — but a domain registered forty minutes ago has no reputation yet, and by the time it is listed the campaign may already be over.

That is the honest limit. Security software raises the floor. The last check is you.

The five signs

Diagram of an invented phishing email with five numbered warning signs: a sender domain that does not match the organisation, a generic greeting, an artificial 24-hour deadline, a button whose visible text does not match its real destination, and an unexpected attachment with an unusual file extension.
Figure 1. The message shown is invented for this diagram and does not represent any real company. Original diagram, drawn for this site.

1. The sender domain does not belong to the organisation

Read what comes after the @ symbol, not the display name — the display name is free text and the sender chooses it. Look for domains that merely resemble the real one: an extra word, a hyphen, a different ending, a substituted character. On a phone, tap the sender to expand the full address; the collapsed view shows only the name.

2. A generic greeting

"Dear valued customer" from a company that has your name on file is a signal. It is not conclusive — plenty of legitimate bulk mail is impersonal — but combined with anything else on this list it should stop you.

3. Manufactured urgency

Twenty-four hours to confirm. Your account will be suspended. A payment will be taken unless you cancel now. The deadline exists to prevent you from doing what would expose the fraud: pausing, and checking through a channel you chose yourself. Real organisations do occasionally impose deadlines, but rarely short ones and rarely by email alone.

4. The link does not go where it says

On a computer, hover over the link and read the address in the status bar. On a phone, press and hold to preview it. Watch for a raw IP address, a domain unrelated to the sender, or a lookalike spelling. Shortened links hide the destination entirely, which is reason enough for caution in an unexpected message.

5. An unexpected attachment

Particularly an HTML file (a login page delivered to your inbox, so no suspicious domain appears in the mail), an archive containing a single executable, or a document that asks you to enable macros or editing before it will display. An invoice you were not expecting is not an invoice.

The one habit that replaces all five

Never use the link in the message. If you think it might be real, open the organisation's site yourself — from a bookmark, from your banking app, or by typing the address — and look for the same notice there. If it is genuine, it will be in your account. If it is not, you have lost ten seconds.

Variants worth knowing

If you have already entered your password

  1. Change that password immediately, on the real site, reached without using the link.
  2. Change it everywhere you reused it. This is the step people skip, and it is the one that matters most, because credential stuffing against other services is the standard follow-up.
  3. Turn on multi-factor authentication on that account if it is not on already.
  4. Sign out all active sessions in the account's security settings. A stolen session cookie survives a password change; ending the sessions is what revokes it.
  5. Check the account's recovery settings — a redirected recovery email address or an added phone number is how an attacker keeps access after you change the password.
  6. If it was a bank, call the bank on the number from your card, and watch statements for small test transactions.
  7. If you downloaded or opened anything, run a full scan, and follow the steps in our ransomware guide.

Two habits that make you a hard target

Use a password manager. Not mainly for the strong passwords — for the autofill. A password manager fills credentials by matching the domain, so on a lookalike site it silently does nothing. That refusal to fill is a warning your own eyes can miss.

Prefer phishing-resistant multi-factor authentication. A passkey or a hardware security key is bound to the real site's domain and cannot be handed to a fake one. Codes from an authenticator app are far better than nothing but can still be typed into the wrong page; SMS codes are the weakest of the three.

Related


This guide is general consumer information, not professional security advice. It is written by Sandra Ward for DALAMIS s.r.o. and is funded, like the rest of this site, by affiliate commission earned elsewhere on it — see our editorial policy. Product names mentioned are the trademarks of their owners; where a vendor's own published information differs from this page, the vendor's information prevails.

← All guides