How I Spot a Phishing Email Before I Click Anything

Jul 24, 2026

I get sent screenshots of dodgy emails more than almost anything else I deal with. Someone's not sure if it's real, something about it feels off, and they just want a second opinion before they delete it or click something they shouldn't. Over the years I've turned that instinct into an actual routine, the same handful of checks in the same order, every single time. Here's exactly what I look at.

None of this takes more than about thirty seconds once it's a habit. The point isn't to become paranoid about every email, it's to have a routine you can run through automatically so the decision isn't a guess.

The First Thing I Check: The Sender Address

Before I read a single word of the message, I look at who it's actually from, not the display name, the address underneath it. A message claiming to be from your bank should come from your bank's actual domain, not something like a random free email address or a string of nonsense letters. Most email apps let you tap or hover on the sender name to reveal the real address behind it. It takes two seconds and catches more fakes than anything else on this list, because the display name is the one thing that's trivial for a scammer to fake convincingly.

What I Do Before Clicking Any Link

I never click a link straight from an email if I can help it. On a computer, hovering over the link shows the actual destination in the corner of the screen, and it's astonishing how often that destination has nothing to do with the company the email claims to be from. On a phone, a long press does something similar. If a link looks even slightly off, a misspelled domain, an unfamiliar country code, a string of random characters, I go to the actual company's website directly by typing the address myself rather than trusting the link at all. That single habit has saved me more than once, and I've written more on the specific red flags I always check first if you want the fuller list.

The Urgency Is the Tell, Not the Content

Every convincing phishing email I've ever seen has one thing in common: it wants you to act before you think. A locked account, a missed delivery, a payment that needs confirming within the hour. Genuine organisations very rarely operate that way, and the ones that do usually give you a proper amount of time and a way to verify through a channel you already trust, not just the link in the message itself. Whenever I feel that little jolt of urgency reading an email, that's my actual signal to slow down, not speed up. It's the single most reliable check I have, more reliable than spelling or logos, because the emotional pressure is the one thing scammers can't fake away.

Attachments Get the Same Suspicion as Links

An unexpected attachment, especially one you weren't told to expect, gets treated exactly like a suspicious link in my routine. Invoices I didn't order, delivery notices for parcels I'm not expecting, documents that need me to "enable content" to view them properly, all of these are extremely common ways malware actually gets onto a device. If I'm not expecting the attachment, I contact the supposed sender through a separate channel to check it's genuinely from them before I open anything, even if the email itself looks polished and professional.

The Logo and Formatting Trick People Into False Confidence

I still hear from people who assume a professional-looking email with the right logo and colours must be genuine. It's one of the most out of date pieces of advice still floating around. Copying a company's branding pixel for pixel takes minutes with tools freely available online, and I've seen fake bank and delivery emails that were indistinguishable from the real thing at a glance, footer and all. Polish tells you nothing about authenticity anymore. What actually matters is the sender address, the link destination, and whether the message is trying to rush you, exactly the checks above, not how nice it looks.

The Same Checks Apply to Texts and App Notifications

Phishing doesn't stay in your inbox anymore, and I run through more or less the same routine for texts and app notifications too. A text claiming to be from a delivery courier with a link to "reschedule" your parcel gets the same treatment as a suspicious email: I don't tap the link, I go to the courier's actual app or website directly. Scam texts are often even harder to check the sender address on than email, since a phone just shows a name or short number, so the urgency test becomes even more important on mobile than it is on a laptop. If a text is trying to rush you into tapping something right now, that's the same signal, regardless of which app it arrived through.

What I Actually Do Once I've Decided It's Fake

I don't click unsubscribe, and I don't reply asking what it wants, both just confirm to whoever sent it that your address is active and being read. I delete it, or mark it as phishing if my email provider offers that option, since that helps train their filters for the next person too. If you ever do click something you shouldn't have, report it through Action Fraud so it's on record, and change your passwords straight away, starting with whichever account the email was impersonating. A password manager like NordPass also helps here in a quieter way, since it won't autofill your login details on a lookalike site even when the email itself looks completely convincing, which is often the first real sign something's wrong. My Safety Toolkit has the tools I use myself to keep my own inbox clean, and if you want a second pair of eyes on a suspicious email, feel free to get in touch.