Skip to main content
    Step 1 of 6
    Safety & Privacy
    Beginner
    4 min read 6 stepsApril 14, 2026Verified April 2026

    How to Recognize Phishing Emails Before It's Too Late

    Phishing emails try to trick you into clicking fake links or giving up passwords. Here are the warning signs to look for in every email.

    At a Glance

    Category
    Safety & Privacy
    Difficulty
    Beginner
    Read Time
    4 min read
    Steps
    6
    Topics covered
    phishing
    email scams
    spam
    fraud
    identity theft
    email safety
    1

    Check the sender's actual email address

    ~15s
    Tap or click the sender's name to reveal the full email address. Real companies use their own domain (@amazon.com, @apple.com, @bankname.com). Watch for extra words, hyphens, or wrong domains.
    2

    Look for urgency and threats

    ~15s
    Phrases like "suspended in 24 hours," "pay right away," or "unauthorized access detected" are designed to rush you. Slow down — take a breath before clicking anything.
    3

    Check for your name

    ~15s
    Your real bank or service knows your name and uses it. "Dear Customer" or "Dear Account Holder" is a warning sign.
    4

    Hover over links before clicking

    ~15s
    On a computer, hover your mouse over any link to see the real URL at the bottom of the screen. On a phone, press and hold the link (don't tap) to see where it actually goes.
    5

    Never open unexpected attachments

    ~15s
    Don't open any attached file you weren't expecting — even PDFs or Word documents. If it claims to be an invoice or receipt, verify by going directly to the company's website.
    6

    Report it and delete it

    ~15s
    In Gmail, click the three dots → "Report phishing." Then delete the email. Report phishing emails to reportphishing.antiphishing.org to help protect others.

    You Did It!

    You've finished reading: How to Recognize Phishing Emails Before It's Too Late

    How well did this guide stick with you?

    Need more help? Book a TekSure tech

    Phishing emails are designed to look like they come from real companies — your bank, Amazon, the IRS, Apple, or your email provider. Their goal is to get you to click a link that takes you to a fake website, where they steal your password or personal information.

    Learning to recognize them is one of the most powerful security skills you can have.

    Warning sign #1: The sender's email address looks off

    This is the most reliable signal. Look at the actual email address (not the display name). Scammers often use addresses like: - support@apple-security-center.com (not a real Apple address) - noreply@amazon-accounts.net (Amazon's real address ends in @amazon.com) - IRS-refund@gmail.com (the IRS never emails from Gmail)

    Real companies use their own domain: @apple.com, @amazon.com, @irs.gov.

    To see the full email address in Gmail: tap the sender's name at the top. A line appears showing the real address.

    Warning sign #2: Urgent language designed to panic you

    Phrases like "Your account will be suspended in 24 hours!", "You owe $2,347 — pay now or face arrest!", or "URGENT: Unauthorized login detected" are designed to make you act fast without thinking. Real companies give you time to respond.

    Warning sign #3: Generic greetings

    "Dear Customer," "Dear User," or "Dear Account Holder" instead of your name. Your real bank knows your name and uses it.

    Warning sign #4: Links that don't go where they say

    Before clicking any link, hover your mouse over it (on a computer) to see the real web address at the bottom of your screen. If it says "Click here to verify your Amazon account" but the real link goes to a weird website like amaz0n-secure-login.ru, it's fake.

    On a phone: press and hold a link (don't tap it) to see the real URL before deciding whether to tap.

    Warning sign #5: Attachments you didn't expect

    Never open an attachment you weren't expecting, even if the email claims to be a receipt, invoice, or shipping notice. Attachments in phishing emails often install malware on your device.

    What to do with a suspicious email:

    • Don't click any links or open attachments.
    • If you think it might be real, go directly to the company's website by typing the address yourself (not clicking the email link).
    • Report it to your email provider: in Gmail, click the three dots → "Report phishing."
    • Forward phishing emails to phishing@reportphishing.antiphishing.org

    Quick Tip:

    When in doubt, call the company directly using the phone number on the back of your card or on their official website — never the number in a suspicious email.

    Rate this guide

    How helpful was this guide?

    phishing
    email scams
    spam
    fraud
    identity theft
    email safety

    Official Resources

    Sources used to create and verify this guide. View all sources →

    Still stuck? Let a pro handle it.

    A real person can walk you through this over the phone, anywhere in the US. If we can't fix it, you don't pay.