Spotting Phishing Emails Before You Click a Link
Why Phishing Still Catches Careful People
Phishing has a reputation problem: most of us think we would spot a scam a mile off. In reality, the messages that do the damage are rarely the ones with spelling mistakes and cartoonish threats. They are the plausible ones — a delivery notice for a parcel you really are expecting, an invoice from a supplier you really do use, or a message from your bank that arrives the day after you made a large payment. The trick is not to be suspicious of everything, but to know which specific details to check and in what order.
The good news is that phishing leaves fingerprints. Almost every attempt, however polished, struggles with the same handful of things: the sender address, the link behind the text, the tone, and the attachment. Learn to check those four and you will filter out the overwhelming majority of scams before your mouse reaches the button.
1. Slow Down When a Message Is Pushing You
Urgency is the single most reliable warning sign. Phishing depends on you acting before you think, so the language is engineered to create a deadline: your account will be closed within 24 hours, a payment has failed, a parcel is being returned today, a subscription has been renewed and you must cancel it now.
Treat urgency as a signal to pause rather than a reason to hurry. A genuine organisation that needs something from you will still need it tomorrow, and it will not punish you for taking ten minutes to check. Ask yourself one question: is this message trying to make me act quickly, or is it simply giving me information? Information can wait. Pressure cannot.
Watch for other emotional levers too — fear of losing money, curiosity about an unexpected refund, or authority ("this is a final notice"). If a message makes you feel alarmed or excited, that reaction is the product being sold to you.
2. Read the Sender Address, Not the Display Name
On a phone or in a busy inbox, most of us read the name that appears at the top of the message. That name is free text and can be set to anything. The actual address is the part that matters.
- Tap or click the sender name to reveal the full address rather than the shortened version.
- Look at the domain — the part after the @ symbol. A message claiming to be from your bank but sent from a free webmail account is almost certainly fake.
- Check for small alterations: extra hyphens, doubled letters, a dot where there should be none, or a different ending such as .net where you would expect .co.uk.
- Be wary of display names that include a person's name plus a company, because scammers copy these directly from real signatures.
Also consider whether the message is even plausible from that source. A utility company will not usually email you from a personal-looking address, and a colleague asking for an urgent payment from an address you have never seen before deserves a phone call.
3. Hover Before You Click — Every Time
The visible text of a link tells you nothing. What matters is where it actually goes. On a computer, rest your pointer over the link without clicking and read the address that appears, usually in the bottom corner of the window. On a phone, press and hold the link to see a preview of the destination, then dismiss it without tapping through.
When you check the destination, look at the domain closest to the start of the address, just before the first single slash. Everything before that can be faked with subdomains; everything after it is just a page on the site. If a link reads like a well-known brand but the domain near the front is something random, that is your answer.
Shortened links, buttons in HTML emails, and links hidden behind images are all worth extra caution because the destination is deliberately obscured. If you cannot see where a link goes, do not click it. Open a new browser tab and navigate to the organisation's site yourself instead.
4. Treat Unexpected Attachments as Hostile Until Proven Otherwise
Attachments are the classic delivery method for malware, and the file types to distrust are consistent:
- Invoices and statements you were not expecting, especially as archives (.zip or .rar) or as documents asking you to "enable editing" or "enable macros" to view them.
- HTML files that open a fake login page in your browser.
- Executable files ending in .exe, .scr or .js, which should never arrive as an email attachment from a stranger.
- Calendar invites from unknown senders, which can carry links and clutter your diary.
If an attachment seems even slightly odd, contact the sender using a number or address you already have — not one supplied in the message — and ask whether they sent it.
5. Verify Separately, Never Through the Message
This is the habit that defeats even the best-crafted phishing email. If a message asks you to log in, confirm a payment, update card details or change a password, do not use the link, phone number or reply address provided. Open a fresh browser tab, type the organisation's address yourself, or use a bookmark you created earlier, and check your account there.
For requests that appear to come from a person — a colleague, a friend, a landlord — call or message them on a channel you already trust. A five-minute delay is trivial compared with the cost of a fraudulent transfer.
6. If You Think You Have Already Clicked
Act quickly and without embarrassment; it happens to careful people every day.
- Disconnect from the internet if you downloaded or opened a suspicious file.
- Change the password for the affected account from a different device, and change it anywhere you reused the same password.
- Contact your bank straight away if you entered card or banking details, and check recent transactions.
- Run a full antivirus scan and tell your IT support or a knowledgeable friend what happened.
- Report the message as phishing in your email client, then delete it.
None of this requires technical expertise — just a short pause before clicking. Build the check into your routine, and a suspicious email becomes a five-second decision rather than a nasty surprise.

Age, repair costs and changing needs all affect the decision. Compare a repair quote with the price of a suitable replacement before deciding.
Updates fix security flaws and improve stability, but they can sometimes cause problems. Learn how to prepare and recover if issues appear.
Check power cables, wall sockets and monitor connections first. If fans spin but nothing appears, test memory and graphics output methodically.
Unwanted programmes can slow startup and clutter menus. Use built-in removal tools, then check startup settings and browser extensions for leftovers.