Phishing Awareness

📧 How to Spot a Phishing Email Before You Click

By Sophie Laurent, Hobbyist with a keen interest in password security and online safety, Trusty Password · 7 May 2026 · Updated 29 Jun 2026 · 6 min read · 1275 words

Phishing emails are the most common entry point for account takeovers, ransomware, and data breaches. In 2025, the NCSC reported that 92% of UK businesses encountered at least one phishing attempt. But phishing is not just a corporate problem — individuals lose money, credentials, and identity data to these attacks every single day. Learning to spot a phishing email before you click is the single most effective skill for protecting your accounts, whether you're securing your personal inbox or your entire team.

The reason phishing remains so effective is simple: it exploits human psychology rather than technical vulnerabilities. Attackers craft messages that trigger urgency, fear, or curiosity — emotions that override our normal caution. A well-crafted phishing email can bypass spam filters, deceive password managers, and even fool experienced security professionals. That is why developing a systematic checking process matters more than relying on instinct alone.

In this guide, I will walk through each red flag in detail, explain how attackers tailor their approach for different platforms, and share the single golden rule that has saved me — and countless others — from credential theft. I also recommend a password manager like NordPass as your safety net against phishing sites that try to capture your credentials.

Check the Sender Address, Not Just the Display Name

Phishing emails often spoof the display name of a trusted organisation but the actual email address behind it tells a different story. Your email client typically shows a friendly display name like "Apple Support" or "NatWest Security" but the underlying email address is what matters. Attackers rely on the fact that most people read the name and stop there.

To check the sender address properly, you need to look past the display name. On desktop email clients, hover over the sender name or click the "Details" link next to it. On mobile, tap the sender field to expand the full address. A legitimate email from PayPal will come from paypal.com, not paypa1-security.com or paypal-verify.co.uk. Look for subtle misspellings: rnicrosoft.com uses a lowercase "r" and "n" to mimic "m", and g00gle.com uses zeros in place of the letter "o".

There is a deeper layer worth knowing about: email authentication protocols like SPF, DKIM, and DMARC. When properly configured by the sender, these protocols help your email provider verify that a message genuinely came from the domain it claims to be from. You can check these headers in Gmail by clicking the three dots next to the reply button and selecting "Show original." If the message fails SPF or DKIM checks, treat it as suspicious.

Pro tip: Create a contact list in your email client for your bank, utilities, and other essential services. Any email from one of these services that comes from an address not on that list is automatically suspect, regardless of the display name.

Look for Generic Greetings

Legitimate organisations use your name in their communications because they have it on file. Phishing emails typically start with "Dear Customer," "Dear User," or "Dear Valued Member" because the attacker does not know your name. This is one of the easiest red flags to spot once you train yourself to notice it.

However, AI-generated phishing emails in 2026 have become more sophisticated. Some now include personalised greetings scraped from data breaches or social media profiles. If you receive an email that uses your name but still feels off — perhaps the tone is wrong, or the context does not match — do not let the personalisation lower your guard. Attackers can obtain your name, job title, and even recent purchase history from data leaks and public sources.

The safest approach is to treat any unexpected communication — personalised or not — with the same level of scepticism. If the message asks you to click a link, download a file, or enter credentials, verify through a separate channel before acting.

Examine the URL Before You Click

Before clicking any link in an email, hover over it to preview the destination URL. On desktop, the full URL appears in a small tooltip or in the status bar at the bottom of your browser window. On mobile, press and hold the link until a preview pops up. If the URL does not match the organisation's official domain, do not click.

Attackers use several URL tricks to deceive you. Lookalike domains substitute visually similar characters: arnazon.com instead of amazon.com, Iinkedin.com (capital I instead of lowercase l) instead of linkedin.com. Subdomain obfuscation places the real domain in the middle of the URL: login-security.paypal.com.evil-site.com — the actual domain is evil-site.com, not PayPal. URL shorteners like bit.ly or tinyurl.com hide the destination entirely; never click shortened links in unsolicited emails.

For an extra layer of defence, a password manager like NordPass will only autofill your credentials on the exact domain you saved them for. If a phishing site uses paypa1.com instead of paypal.com, NordPass will refuse to fill in your login details — giving you an immediate signal that something is wrong.

Watch for Urgency and Threats

Phishing emails create artificial urgency to bypass your normal caution. "Your account will be closed in 24 hours," "Immediate action required to prevent suspension," or "Suspicious login detected — verify now" are classic techniques that pressure you into clicking without thinking. The attacker is counting on your fear of losing access to a service you rely on.

Legitimate organisations do not use threats or ultimatums to drive action. A real bank might send a fraud alert, but it will never threaten immediate account closure via a link in an email. If you receive a message with urgent language, the safest response is to ignore the email's call to action entirely. Instead, open a new browser tab, navigate directly to the organisation's official website, and check your account status or notifications from there.

Time pressure is the enemy of good security judgment. Attackers know this and design their emails to prevent you from pausing to verify. If an email makes you feel anxious or rushed, that emotional reaction is itself a red flag. Take a breath, step away from the keyboard for 30 seconds, and then approach the message with a calm, analytical mindset.

Beware of Unexpected Attachments

An unexpected invoice, voicemail, document, or shipping notification attachment is a common malware delivery mechanism. Attackers send fake invoices from companies you do not recognise, spoofed voicemail notifications from messaging platforms, and fraudulent shipping confirmations from delivery services. The attachment itself — typically a ZIP file, a macro-enabled Office document, or a PDF with embedded links — installs malware when opened.

Even if the sender looks familiar, verify with them through a known phone number or a separate communication channel before opening any unexpected attachment. Call the person or company using a number you have on file — not one listed in the suspicious email itself. If you have no prior relationship with the purported sender, delete the email without opening the attachment.

Many organisations now use secure document portals rather than email attachments for sensitive files. If a message claims to contain an invoice or statement from a company you do business with, check your account on their official website through your browser rather than opening the attachment. Legitimate documents will be available for download within your account dashboard.

Check for Poor Grammar and Formatting

While AI-generated phishing emails in 2026 now have near-perfect grammar — a significant shift from the poorly translated scams of the past — many campaigns still contain subtle inconsistencies in formatting, logo quality, or brand voice. A phishing email might use the wrong shade of blue for a well-known brand, stretch a logo to the wrong aspect ratio, or use a font that does not match the brand's official typography.

Pay attention to the email's visual quality. Legitimate brand emails are designed by professional teams and rendered consistently across devices. Phishing emails often look slightly off — the alignment is a few pixels out, the header image is low resolution, or the footer contains outdated copyright years or generic placeholder text. These visual cues matter more than ever now that text-based red flags are disappearing.

Also check the greeting-to-content match. If the email greets you as "Dear Sophie" but references a product or service you have never used, the message is almost certainly a phishing attempt. Attackers often pair personal data from one breach with context from another, creating a Frankenstein message that does not quite fit.

The Golden Rule: Navigate, Don't Click

If an email asks you to log in to your bank, PayPal, Amazon, or any service, do not click the link. Open a new browser tab, type the URL yourself, and log in from there. This single habit prevents the majority of credential theft regardless of how convincing the phishing email looks. It is simple, it is free, and it works against even the most sophisticated AI-generated phishing campaigns.

This rule applies to every context: email attachments, email links, QR codes in emails, and text message links. If you need to check your account, navigate there directly. Bookmark the official login pages for the services you use most frequently — your bank, email provider, cloud storage, and social media — so you always have a known-safe entry point. A bookmark cannot be spoofed the way an email link can.

For an extra layer of defence, using a password manager like NordPass reinforces this habit. When you click a browser bookmark or type a URL directly, NordPass offers to fill your saved credentials. When you land on a phishing page, it does nothing — giving you a clear signal to stop and verify.

Even the most vigilant among us can have a bad moment. If you have clicked a link in a suspicious email, do not panic — act immediately. The faster you respond, the better your chances of preventing damage.

First, do not enter any credentials on the page you landed on. Close the browser tab immediately. If you already entered your password, go to the real website of the service you were impersonated and change your password right away. If you reused that password anywhere else — and let us be honest, many of us do — change it on every other account too. This is why using unique passwords for every account is essential.

Next, run a security scan on your device using reputable antivirus software. If you downloaded an attachment or executed a file, the scan may detect and remove malware. Enable multi-factor authentication on any account that supports it. Even if the attacker has your password, MFA blocks them from logging in. Finally, report the phishing email to your email provider as spam or phishing, and forward it to the Anti-Phishing Working Group at reportphishing@apwg.org.

How a Password Manager Protects Against Phishing

A password manager like NordPass does more than store your passwords securely. It acts as a practical anti-phishing tool in three important ways. First, it refuses to autofill on lookalike domains. If you saved your login for amazon.com but land on amzon-login.com, the password manager simply will not offer your credentials — a clear red flag that something is wrong.

Second, a password manager generates and stores strong, unique passwords for every account. If one account is compromised in a data breach, the attacker cannot use that same password to access your other accounts. This limits the blast radius of any single phishing attack. Third, a password manager encourages direct navigation because you can click saved logins from your vault rather than clicking links in emails. This naturally reinforces the "navigate, don't click" habit that is the foundation of phishing defence.

Combining a password manager with the skills in this guide gives you both a safety net and the awareness to avoid phishing emails in the first place. The technology handles the domain matching and credential uniqueness; your trained eye catches the social engineering and manipulation attempts that software cannot.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🛡️ Best Password Generator🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔀 Random Password Tool✈️ Password Pilot🎯 Generator Password
We use cookies to improve your experience. Learn more