How to Spot a Phishing Email Before You Click

Updated September 1, 2026

Lines of code on a dark screen

The email looks right. The logo is correct, the sender is someone you deal with, and the request is only slightly out of the ordinary. In Verizon's 2026 Data Breach Investigations Report, phishing was the way in for 16% of breaches, and the human element figured in 62% of them. It stays near the top every year because it does not attack your software — it attacks the fact that you are busy.

The tells are learnable, they take seconds to check, and they are not the ones most people were taught.

Forget spelling mistakes

The advice to look for bad grammar is a decade out of date. Modern phishing is well written — much of it drafted with the same AI tools everyone else uses — correctly branded, and sent at a believable time of day. The most dangerous kind is not even a fake email: it is a real reply, inside a real thread, sent from a mailbox the attacker has quietly taken over. Checking for typos catches none of that. The four tells below do.

The four reliable tells

  1. Urgency with a deadline. Your account closes today, the invoice is overdue, the payroll change must go in before five. Real organisations rarely give you hours. The pressure exists to stop you checking.
  2. The link does not go where the text says. Hover over the link on a computer and the real address appears in the corner of the window. On a phone, press and hold the link — do not tap — for a preview. Read the domain immediately before the first single slash: microsoft.com.login-verify.net is not Microsoft, it is login-verify.net wearing a costume.
  3. It asks you to break a normal process. Pay to new bank details, buy gift cards, send a document outside the usual system, tell nobody because it is confidential. The request to bypass the usual way of doing things is the tell, all by itself.
  4. The reply-to address differs from the sender. Tap the sender's name to see the actual address behind it. A display name can be set to anything; the address underneath is harder to fake, and a reply-to pointing somewhere else is close to proof.

When it comes from someone you actually know

The most effective phishing arrives from a colleague's or supplier's genuinely compromised account, so every technical signal checks out — real address, real history, real signature block. The favourite version is the thread hijack: the attacker sits silently inside a hacked mailbox, waits for a live conversation about an invoice or a contract, then replies inside that thread with new bank details or a link to the "updated documents". You have been emailing this person for weeks. Nothing about the message looks wrong, because almost nothing about it is.

The defence is not technical — it is a habit. Any request involving money, passwords or sensitive files gets verified on a different channel. Phone the person on the number you already have on file. Not the number in the email — the attacker typed that one.

QR codes, texts and phone calls

Attackers have noticed that people scrutinise email links and trust everything else.

  • QR codes (quishing). An email says you must re-enrol in two-factor authentication or review a shared file, and helpfully includes a QR code. Scanning it moves you off your filtered work computer onto your phone, where nothing checks the address. Treat a QR code in an email exactly like a link — and be suspicious that one was used at all; there is rarely a legitimate reason for it.
  • Texts. The unpaid toll, the parcel that could not be delivered, the bank fraud alert. Verizon's 2026 report found phone-based phishing lures were clicked roughly 40% more often than email ones — small screens hide addresses, and people tap fast.
  • Phone calls. Someone claiming to be your bank, Microsoft or your own IT department, often paired with a matching email so each makes the other feel real. Anyone who calls you and then asks you to prove your identity, read out a security code or install remote-access software is running a script. Hang up and call back on the published number.

The two emails that empty business accounts

If you run payroll or pay suppliers, two specific frauds deserve their own drill.

The payroll change. "I've switched banks — can you update my direct deposit before this month's run?" It goes to HR or the bookkeeper, apparently from an employee, actually from a lookalike address or a hacked account. The next payroll leaves for the attacker's account and is not coming back.

The vendor bank change. A supplier — or someone sitting inside the supplier's mailbox — sends new payment details, often attached to a genuine outstanding invoice. Every detail on the invoice is right except the account number. That one is worth its own read: fake invoice fraud is the version that empties six figures at a time.

The fix for both is the callback rule, written down and made policy: no bank-detail change is ever actioned on email alone. Someone phones the employee or supplier on a number from your own records, confirms out loud, and only then edits the account. Two minutes per change, and it defeats the whole category. Put it on your cybersecurity checklist next to backups and two-factor.

If you clicked

What to do depends on what happened after the click. Speed matters far more than embarrassment — everyone has clicked something.

  • You only opened the email: generally fine. Reading a message rarely does anything by itself. Report it, delete it, move on.
  • You clicked but entered nothing: usually fine too. Close the page, do not download anything it offered, and run an antivirus scan for reassurance.
  • You entered a password: change it now, from a different device, along with anywhere you reused it, then turn on two-factor authentication. If it was your email password, assume the mailbox itself is compromised and work through the first hour in Email Hacked — email resets every other account you own.
  • You entered card or banking details: call the bank on the number printed on the card, cancel it, and watch the statements. Banks deal with this every day; the sooner you call, the cleaner it ends.
  • You opened an attachment: disconnect the machine from the network and get it looked at. Deleting the file does not undo whatever it did while it was open.
  • It was a work account: tell whoever handles IT immediately, even if you are not sure anything happened. The expensive breaches are the ones reported on Thursday about a click that happened on Monday.

Report it where it counts

Reporting takes ten seconds and does real work — it trains the filters and warns the next person.

  • Outlook: select the message, use the Report button on the ribbon, then Report phishing. Older setups call it the Report Message add-in.
  • Gmail: open the message, click the three-dot menu at the top right, choose Report phishing.
  • At work: tell your IT contact before deleting anything — the headers help them find who else received it.

When you'd rather have someone check it with you

Maybe you clicked and cannot tell what happened next, or the "supplier" email is sitting in your accounts inbox and something feels off. Post the problem free at Koadi in your own words — "clicked a link in a fake invoice, need the machine checked" — and a vetted, identity-verified technician picks it up. You set a fixed price or take bids; payment sits in escrow until you approve the work. Remote help covers every US state, evenings and weekends included; on-site visits are available through local technicians when hands are needed.

Frequently asked questions

Is it dangerous to just open a phishing email without clicking anything?
Rarely. Modern mail apps do not run code simply by displaying a message, so opening one is almost always harmless. The risk starts when you click a link, open an attachment, scan a QR code or reply. Report the message, delete it, and move on.
How do I check where a link goes on my phone?
Press and hold the link instead of tapping it — a preview of the full address appears. Read the domain immediately before the first single slash: that is where you will really go. If it is a shortened link or you cannot make sense of it, leave it alone until you can check on a computer.
What is quishing, and why are QR codes in emails a red flag?
Quishing is phishing by QR code. The code hides the destination from both you and your employer's email filters, and scanning it moves you onto your phone, where nothing is checking the address. Legitimate senders almost never need a QR code inside an email, so treat one as a warning sign in itself.
Should I report a phishing email or just delete it?
Report it first — it takes seconds. Outlook has a Report phishing button on the ribbon; Gmail has Report phishing under the three-dot menu. Reporting trains the filters that protect everyone else. If it targeted a work account or imitated a colleague, tell your IT contact before deleting so they can check who else received it.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides