What a Real Phishing Email Looks Like, Line by Line
The Email I Am Going to Pick Apart
A client forwarded me a phishing email last month and asked if it was safe to click. It was not, and it was also a near perfect teaching example, so I want to walk you through it piece by piece rather than just tell you the general rules again. Once you have seen how one of these is actually built, the general rules make a lot more sense.
I am not going to reproduce the exact email here, both because it named a real company and because scammers do read blogs like this one and adjust. Instead I am describing the structure, which barely changes even when the wording does. If you understand the structure, you can spot the next one regardless of which brand it is wearing.
The Sender Line Tells You More Than You Think
Most people glance at the display name and stop there. The email said it was from a parcel courier, and the display name matched. The actual address behind that display name was a string of random letters at a domain that had nothing to do with the courier.
This is the single most useful five second check you can do, and almost nobody does it. On a phone, you usually need to tap the sender name to reveal the full address. On a laptop, hovering over it is enough. If the visible name and the underlying address do not match the company they claim to be from, you are done, you already have your answer.
Some scammers now use domains that are close but not exact, swapping a letter or adding a word. That is worth a second look too, but the mismatched display name is the more common tell, because it costs the scammer nothing to fake and most people never check it.

The Subject Line Is Built to Short-Circuit Thinking
The subject said a delivery had failed and action was needed within twenty four hours. That is not an accident. Every convincing phishing email I have seen leans on the same two ingredients, a problem you did not cause and a clock that is already running.
The combination matters more than either part alone. A problem without urgency gives you time to think it through. Urgency without a problem has nothing to hook you with. Put them together and a lot of sensible people will click first and question it second, which is exactly the order the scammer wants.
When I read a subject line like that now, I treat the urgency itself as the red flag rather than something to react to. Genuine delivery problems can usually be checked by going to the courier's own app or website directly, not through a link in an email.
The Body Copy Follows a Formula
The message body had three parts, and I see this same shape constantly. First, a brief statement of the problem, kept vague on purpose so it could apply to almost anyone. Second, a consequence if you do not act, in this case the parcel being returned to sender. Third, a single button to fix it.
Notice what is missing. No parcel number that matches anything I could check independently. No specific date. No named person. Genuine companies tend to over include this kind of detail because it reduces their own support queries. Scam emails tend to under include it because specific, checkable detail is exactly what would let you catch them out.
The tone is also flatter than a real company's marketing usually is. Real courier emails often have a house style, a bit of personality, maybe an offer or a link to their app. This one read like it had been generated to be as universally applicable as possible, which is another way of saying it read like it had been generated for a mass send.
What I Do With the Link Itself
I never click the button in an email like this, but I am sometimes curious enough to check where it leads, and there is a safe way to do that. On a laptop, hovering over a link shows you the destination URL at the bottom of the browser window without visiting it. On most phones, a long press does something similar.
In this case the link went to a domain that had nothing to do with the courier, similar to the sender address problem. If you ever do this check and the destination looks even slightly off, close the email and go to the company's real website by typing the address yourself, or through their official app if you have it installed.
I would also point out that good antivirus software catches a meaningful share of these before you even get to the reasoning stage. I run Bitdefender on my own devices, and its anti-phishing filtering has flagged links like this one automatically, which is a useful second layer on days when you are tired, rushed, or simply not looking closely.
If you want the fuller picture of what protects an inbox beyond spotting one email, I have written about that in the simple checks I use, and if passwords are part of what is at risk here, my thoughts on password manager vs memory are worth a look too. For anyone in Liverpool who wants a second pair of eyes on something that has landed in their inbox, my safety toolkit has the free checklist I mentioned, and you are always welcome to get in touch directly.
None of this requires technical skill. It requires slowing down for the five seconds it takes to check a sender address and a link destination, which is exactly what these emails are designed to stop you from doing. If you report anything suspicious, the National Cyber Security Centre's reporting service is worth using, since it helps get malicious sites taken down faster for everyone else too.
