Spotting Phishing Emails: Verify the Request, Not the Look

<p>Typos and logos are unreliable clues. Learn a calmer way of spotting phishing emails: check what the message asks you to do, then verify it through a channel you already trust.</p>

Person holding a phone with a delivery notice beside a laptop open to a bank's website they typed in themselves

Spotting phishing emails used to mean hunting for typos and clumsy logos. That advice has aged badly. The National Cyber Security Centre notes that attackers now routinely use generative AI to produce grammatically flawless, natural-sounding text, so a well-written message proves very little.

You don't need to become a detective. You need one habit: judge the request, not the look.

A convincing email can still carry a dangerous request

Polished writing, a familiar logo and a sender name you recognise are all easy to copy. Even the browser padlock is no guarantee. The FBI warns that attackers regularly obtain valid encryption certificates for their fraudulent pages.

Some features are worth a pause:

  • Urgency ("act within 24 hours")
  • Secrecy ("don't discuss this with anyone")
  • Attachments you weren't expecting
  • Requests for a password or for money

These are reasons to slow down, not proof of a scam. Genuine companies send urgent messages too, so you don't need to decide whether an email is fake. Ask something easier: What is this asking me to do, and can I verify that independently?

The requested action tells you what needs checking

Say three emails land in your inbox on the same morning.

  • A delivery fee. A parcel is supposedly on hold, and a small payment will release it. The United States Postal Inspection Service says the postal service never charges a fee for redelivery and never asks for payment to release a held parcel.
  • An account-lock warning. Your account will be suspended unless you sign in now. The action is signing in through a link someone else chose.
  • An invoice with changed bank details. It looks like one from a supplier you know, but the payment should now go to a different account. The action is sending money somewhere new.

Four kinds of request always deserve independent verification: signing in, sending money, sharing a verification code, and installing software. The Cybersecurity and Infrastructure Security Agency recommends exactly this, which it calls out-of-band verification: confirm through a known, separately sourced channel, such as a phone number you already trust.

Checking the sender address or hovering over a link can add clues. A mismatched address is a good reason to stop. A matching one is not reassurance, though, because addresses can be imitated or accounts taken over. And please don't open a link or attachment just to investigate.

Leave the email to verify the request

Verification means stepping outside the message.

For delivery and account alerts, open the company's official app, or use a bookmark or a web address you type yourself. If there is a real problem with your parcel or account, it will almost certainly show up there too. If nothing appears, you have your answer.

For payments and changed bank details, contact the person or organisation using a number you already trust, such as one from an earlier invoice, a contract or their official website. Don't use contact details supplied in the email.

Why not just reply? It feels sensible, but it isn't independent. The FBI's Internet Crime Complaint Center describes business email compromise, where criminals often work from a genuine but compromised mailbox or set up forwarding rules. Your reply may then reach the intruder, who will confirm everything.

If you can't verify it, don't do it. Leave the request unfulfilled. Not being able to confirm it is reason enough to stop.

A short routine works better than becoming an email detective

  1. Pause. Nothing legitimate is harmed by a few minutes' delay.
  2. Name the action. Pay, sign in, share a code, install, change details?
  3. Verify elsewhere. Use the app, a bookmark, or a trusted phone number.
  4. Act there. Do the task in the verified place, never through the email.

If you suspect phishing, use your email provider's report-phishing feature, then delete the message. On work email, follow your workplace's reporting procedure instead, usually through IT or security. In the US, the Federal Trade Commission also asks people to forward suspicious emails to reportphishing@apwg.org and log details at ReportFraud.ftc.gov.

If you already acted

It happens to careful people. Next steps:

  • You typed a password into a fake page. Change it on the real service, reaching it by your own bookmark or typed address. The FTC also advises setting up multi-factor authentication on affected services. Then review the account's active sessions or signed-in devices and sign out any you don't recognise. If you reused that password elsewhere, change those too.
  • Money or payment details were involved. Contact your bank promptly.
  • You only clicked. Clicking a link is not the same as submitting credentials or installing software. Close the page, then ask what was actually entered or downloaded. If the answer is nothing, there may be little more to do. If you did download something, don't open it, and get help from someone you trust.

Finally, pick the one account you would least like to lose and bookmark its real sign-in page. Next time an alert arrives, you'll already know where to go.