How to Recognize a Phishing Email — 7 Red Flags to Check Every Time
Phishing emails try to trick you into giving away your password or personal information. Learn the 7 warning signs and how to protect yourself.
At a Glance
Check the sender's actual email address — not just the display name
~25sQuick Tip
Even one letter off matters. "amaz0n.com" (with a zero instead of the letter O) is a fake domain.
Look for urgency, threats, and generic greetings
~29sWarning
The IRS never contacts people by email. The Social Security Administration never contacts people by email about suspended numbers. Medicare does not ask for personal information by email. These are always scams.
Check any links before clicking them
~19sReport the phishing email
~24sQuick Tip
After reporting, delete the email from your inbox and your trash folder so you are not tempted to click anything in it later.
Act quickly if you clicked a suspicious link or shared information
~34sWarning
Do not use any contact information from inside the suspicious email — phone numbers and websites listed there may be fake too. Look up the real company's phone number on their official website or on the back of your card.
You Did It!
You've finished reading: How to Recognize a Phishing Email — 7 Red Flags to Check Every Time
How well did this guide stick with you?
Need more help? Book a TekSure tech
Phishing (pronounced "fishing") is when a criminal sends you a fake email that looks like it comes from a real company — your bank, Medicare, Amazon, the post office, or even the IRS. The goal is always the same: get you to click a link, hand over your password, or share personal information like your Social Security number.
These emails have gotten more convincing over the years. But they still have tell-tale signs. Once you know what to look for, you will spot them much more reliably.
The 7 red flags of a phishing email
Red flag 1: The sender's email address looks off
The name in your inbox might say "Amazon Customer Service" or "Medicare Support" — but look at the actual email address, not just the display name.
Legitimate Amazon emails come from addresses ending in @amazon.com. Legitimate Medicare emails come from @cms.hhs.gov. Phishing emails often use addresses like: - amazon-support@gmail.com (Amazon does not use Gmail) - amazon@secure-account-verify.com (a made-up domain) - medicare-alert@medicarecenter.net (not a government domain)
To see the real email address on your phone: tap the sender's name to expand it. On a computer: hover your mouse over the sender's name.
Red flag 2: Urgent language and threats
Phishing emails create panic so you act without thinking. Common phrases to watch for:
- "Your account will be suspended in 24 hours"
- "Immediate action required"
- "Your Medicare benefits are at risk"
- "You have a package waiting — delivery attempt failed"
- "Verify your information or your account will be closed"
- "You owe back taxes — respond right away to avoid legal action"
Legitimate companies do not threaten to shut down your account in 24 hours over email. The IRS does not contact you by email at all — only by postal mail.
Red flag 3: A generic greeting
Phishing emails are sent to thousands of people at once. So they cannot use your name. They use generic openings like:
- "Dear Customer"
- "Dear Account Holder"
- "Dear Valued Member"
- "Hello User"
Your bank, Amazon, and Medicare all know your name. They will use it.
Red flag 4: Suspicious links
A link in an email might say "Click here to verify your account" but the actual web address it points to is something completely different.
On a computer: hover your mouse over the link without clicking. Look at the bottom-left of your screen (or in a tooltip that appears). The real web address will appear. If it shows a random-looking website instead of the real company's address, do not click.
On a phone: press and hold the link with your finger (do not tap — hold). A small preview of the web address appears. Check that address before tapping.
Real Amazon links go to amazon.com. Real bank links go to your bank's official domain. Real Social Security links go to ssa.gov. If the link goes anywhere else, treat it as suspicious.
Red flag 5: Requests for personal information
Legitimate companies do not ask for your Social Security number, password, full credit card number, or Medicare ID number over email. Ever. If an email asks for any of this information — whether by asking you to type it in a reply or by sending you to a form — that is a phishing attempt.
Red flag 6: Spelling errors and awkward phrasing
Professional companies proofread their emails carefully. Phishing emails often contain:
- Spelling mistakes ("Your acount has been compromized")
- Awkward sentences that do not sound natural in American English
- Strange formatting (random capitalization, extra spaces)
Not all phishing emails have errors — some are well-written. But errors are a reliable warning sign when present.
Red flag 7: Unexpected attachments
If you were not expecting a file, do not open an attached file. Phishing emails often include attachments labeled things like:
- "Invoice.pdf"
- "Your statement.doc"
- "Package tracking.exe"
Opening these files can install harmful software on your computer. When in doubt, contact the sender through a phone number or website you already know — not the contact information in the suspicious email.
How to check a link before clicking
On a computer: Hover your mouse over any link. The real destination appears in the bottom-left corner of your browser window. Compare it to the company's known official website. Even one letter off (amazon-login.com vs. amazon.com) means it is fake.
On a phone: Press and hold a link with your finger for one to two seconds. A small box appears showing the actual web address. Check it before tapping. If you are not sure, do not tap.
Common phishing examples seniors report
"Your Medicare information needs to be verified right away." — Medicare does not contact you by email asking for personal information. If you receive this, do not respond.
"We were unable to deliver your package. Click here to reschedule." — Delivery companies (UPS, FedEx, USPS) do send legitimate delivery notices, but always double-check the sender address and go to the company's official website directly rather than clicking the email link.
"Your Social Security number has been suspended due to suspicious activity." — Social Security numbers cannot be suspended. This is always a scam. The Social Security Administration does not contact people this way.
"Your bank account has been locked. Verify your information to restore access." — Go to your bank's official website (type the address yourself) or call the number on the back of your bank card. Do not click the email link.
How to report phishing in Gmail
Open the email → click the three dots (More options) in the top right corner of the email → click "Report phishing." Gmail removes the email and uses your report to protect other users.
How to report phishing in Outlook
Open the email → click the three dots at the top of the email → click "Report" → click "Report phishing." Or: select the email without opening it → click "Junk" in the toolbar → click "Phishing."
What to do if you already clicked a phishing link
Do not panic — clicking a link does not automatically mean your accounts are compromised, but act quickly:
- 1Do not enter any information on the page that opened. Close it right away.
- 2Change your password for any account that was mentioned in the phishing email. Do this from the real website — type the address yourself or use a bookmark.
- 3If you entered a credit card number, call your bank right away.
- 4If you entered your Social Security number, go to IdentityTheft.gov (the FTC's official site) to file a report and get a personalized recovery plan.
- 5Run a security scan on your device if you opened an attachment.
Report phishing to the FTC
at ReportFraud.ftc.gov. Your report helps the government track scammers.
Sources:
FTC.gov — How to Recognize and Avoid Phishing Scams (consumer.ftc.gov); CISA.gov — Phishing guidance (cisa.gov); IC3.gov — Internet Crime Complaint Center (ic3.gov)
Rate this guide
How helpful was this guide?
Official Resources
Sources used to create and verify this guide. View all sources →
← Previous
How to Free Up Space When Your Phone Says "Storage Full"
Next →
How to Use Google Translate on Your Phone
Still stuck? Let a pro handle it.
A real person can walk you through this over the phone, anywhere in the US. If we can't fix it, you don't pay.
Learn more from official sources
Related Guides
How to Secure Your Home Wi-Fi Network
Simple steps to lock down your home router, keep strangers off your network, and protect every device in your house.
3 min read
Setting Up Two-Factor Authentication (2FA) on Any Account
Add a second layer of security to your most important accounts. This one change stops most account takeovers cold.
3 min read
Staying Safe on Social Media
How to protect your privacy on Facebook and Instagram, spot fake accounts, and avoid the most common social media traps.
3 min read