Skip to main content
    Step 1 of 5
    Safety & Privacy
    Beginner
    9 min read 5 stepsMay 6, 2026Verified May 2026

    How to Recognize a Phishing Email — 7 Red Flags to Check Every Time

    Phishing emails try to trick you into giving away your password or personal information. Learn the 7 warning signs and how to protect yourself.

    At a Glance

    Category
    Safety & Privacy
    Difficulty
    Beginner
    Read Time
    9 min read
    Steps
    5
    Topics covered
    phishing
    email scams
    scam warning signs
    gmail
    outlook
    suspicious email
    online safety
    fraud
    1

    Check the sender's actual email address — not just the display name

    ~25s
    In your email inbox, tap or click on the sender's name to reveal the full email address. Legitimate companies use their own domain: amazon.com, paypal.com, ssa.gov, cms.hhs.gov. If the email address is a Gmail account, a misspelled domain, or a random string of words, the email is almost certainly fake.

    Quick Tip

    Even one letter off matters. "amaz0n.com" (with a zero instead of the letter O) is a fake domain.

    2

    Look for urgency, threats, and generic greetings

    ~29s
    Read the email calmly. If it threatens account suspension within 24 hours, claims your benefits are at risk, or says you will face legal action — that is designed to make you panic and act without thinking. Also check the greeting: "Dear Customer" or "Dear Account Holder" instead of your name is a strong warning sign.

    Warning

    The IRS never contacts people by email. The Social Security Administration never contacts people by email about suspended numbers. Medicare does not ask for personal information by email. These are always scams.

    3

    Check any links before clicking them

    ~19s
    On a computer: hover your mouse over the link without clicking. The real web address appears in the bottom-left corner of your browser. On a phone: press and hold the link with your finger for 1-2 seconds. A preview of the web address appears. Verify the address matches the real company's official website before proceeding.
    4

    Report the phishing email

    ~24s
    In Gmail: open the email → click the three dots (top right of the email) → Report phishing. In Outlook: click the three dots at the top of the email → ReportReport phishing. You can also forward phishing emails to phishing@reportfraud.ftc.gov. Reporting helps protect other people from the same scam.

    Quick Tip

    After reporting, delete the email from your inbox and your trash folder so you are not tempted to click anything in it later.

    5

    Act quickly if you clicked a suspicious link or shared information

    ~34s
    Close the page right away without entering any information. Change your password for the account mentioned in the email — go directly to the real website by typing the address yourself. If you shared credit card information, call your bank right away. If you shared your Social Security number, visit IdentityTheft.gov to start the recovery process. Call 1-877-FTC-HELP (1-877-382-4357) for free guidance.

    Warning

    Do not use any contact information from inside the suspicious email — phone numbers and websites listed there may be fake too. Look up the real company's phone number on their official website or on the back of your card.

    You Did It!

    You've finished reading: How to Recognize a Phishing Email — 7 Red Flags to Check Every Time

    How well did this guide stick with you?

    Need more help? Book a TekSure tech

    Phishing (pronounced "fishing") is when a criminal sends you a fake email that looks like it comes from a real company — your bank, Medicare, Amazon, the post office, or even the IRS. The goal is always the same: get you to click a link, hand over your password, or share personal information like your Social Security number.

    These emails have gotten more convincing over the years. But they still have tell-tale signs. Once you know what to look for, you will spot them much more reliably.

    The 7 red flags of a phishing email

    Red flag 1: The sender's email address looks off

    The name in your inbox might say "Amazon Customer Service" or "Medicare Support" — but look at the actual email address, not just the display name.

    Legitimate Amazon emails come from addresses ending in @amazon.com. Legitimate Medicare emails come from @cms.hhs.gov. Phishing emails often use addresses like: - amazon-support@gmail.com (Amazon does not use Gmail) - amazon@secure-account-verify.com (a made-up domain) - medicare-alert@medicarecenter.net (not a government domain)

    To see the real email address on your phone: tap the sender's name to expand it. On a computer: hover your mouse over the sender's name.

    Red flag 2: Urgent language and threats

    Phishing emails create panic so you act without thinking. Common phrases to watch for:

    • "Your account will be suspended in 24 hours"
    • "Immediate action required"
    • "Your Medicare benefits are at risk"
    • "You have a package waiting — delivery attempt failed"
    • "Verify your information or your account will be closed"
    • "You owe back taxes — respond right away to avoid legal action"

    Legitimate companies do not threaten to shut down your account in 24 hours over email. The IRS does not contact you by email at all — only by postal mail.

    Red flag 3: A generic greeting

    Phishing emails are sent to thousands of people at once. So they cannot use your name. They use generic openings like:

    • "Dear Customer"
    • "Dear Account Holder"
    • "Dear Valued Member"
    • "Hello User"

    Your bank, Amazon, and Medicare all know your name. They will use it.

    Red flag 4: Suspicious links

    A link in an email might say "Click here to verify your account" but the actual web address it points to is something completely different.

    On a computer: hover your mouse over the link without clicking. Look at the bottom-left of your screen (or in a tooltip that appears). The real web address will appear. If it shows a random-looking website instead of the real company's address, do not click.

    On a phone: press and hold the link with your finger (do not tap — hold). A small preview of the web address appears. Check that address before tapping.

    Real Amazon links go to amazon.com. Real bank links go to your bank's official domain. Real Social Security links go to ssa.gov. If the link goes anywhere else, treat it as suspicious.

    Red flag 5: Requests for personal information

    Legitimate companies do not ask for your Social Security number, password, full credit card number, or Medicare ID number over email. Ever. If an email asks for any of this information — whether by asking you to type it in a reply or by sending you to a form — that is a phishing attempt.

    Red flag 6: Spelling errors and awkward phrasing

    Professional companies proofread their emails carefully. Phishing emails often contain:

    • Spelling mistakes ("Your acount has been compromized")
    • Awkward sentences that do not sound natural in American English
    • Strange formatting (random capitalization, extra spaces)

    Not all phishing emails have errors — some are well-written. But errors are a reliable warning sign when present.

    Red flag 7: Unexpected attachments

    If you were not expecting a file, do not open an attached file. Phishing emails often include attachments labeled things like:

    • "Invoice.pdf"
    • "Your statement.doc"
    • "Package tracking.exe"

    Opening these files can install harmful software on your computer. When in doubt, contact the sender through a phone number or website you already know — not the contact information in the suspicious email.

    How to check a link before clicking

    On a computer: Hover your mouse over any link. The real destination appears in the bottom-left corner of your browser window. Compare it to the company's known official website. Even one letter off (amazon-login.com vs. amazon.com) means it is fake.

    On a phone: Press and hold a link with your finger for one to two seconds. A small box appears showing the actual web address. Check it before tapping. If you are not sure, do not tap.

    Common phishing examples seniors report

    "Your Medicare information needs to be verified right away." — Medicare does not contact you by email asking for personal information. If you receive this, do not respond.

    "We were unable to deliver your package. Click here to reschedule." — Delivery companies (UPS, FedEx, USPS) do send legitimate delivery notices, but always double-check the sender address and go to the company's official website directly rather than clicking the email link.

    "Your Social Security number has been suspended due to suspicious activity." — Social Security numbers cannot be suspended. This is always a scam. The Social Security Administration does not contact people this way.

    "Your bank account has been locked. Verify your information to restore access." — Go to your bank's official website (type the address yourself) or call the number on the back of your bank card. Do not click the email link.

    How to report phishing in Gmail

    Open the email → click the three dots (More options) in the top right corner of the email → click "Report phishing." Gmail removes the email and uses your report to protect other users.

    How to report phishing in Outlook

    Open the email → click the three dots at the top of the email → click "Report" → click "Report phishing." Or: select the email without opening it → click "Junk" in the toolbar → click "Phishing."

    What to do if you already clicked a phishing link

    Do not panic — clicking a link does not automatically mean your accounts are compromised, but act quickly:

    1. 1Do not enter any information on the page that opened. Close it right away.
    2. 2Change your password for any account that was mentioned in the phishing email. Do this from the real website — type the address yourself or use a bookmark.
    3. 3If you entered a credit card number, call your bank right away.
    4. 4If you entered your Social Security number, go to IdentityTheft.gov (the FTC's official site) to file a report and get a personalized recovery plan.
    5. 5Run a security scan on your device if you opened an attachment.

    Report phishing to the FTC

    at ReportFraud.ftc.gov. Your report helps the government track scammers.

    Sources:

    FTC.gov — How to Recognize and Avoid Phishing Scams (consumer.ftc.gov); CISA.gov — Phishing guidance (cisa.gov); IC3.gov — Internet Crime Complaint Center (ic3.gov)

    Rate this guide

    How helpful was this guide?

    phishing
    email scams
    scam warning signs
    gmail
    outlook
    suspicious email
    online safety
    fraud
    identity theft
    seniors

    Official Resources

    Sources used to create and verify this guide. View all sources →

    Still stuck? Let a pro handle it.

    A real person can walk you through this over the phone, anywhere in the US. If we can't fix it, you don't pay.