Suspicious Email? Ten Red Flags to Check Before You Click
Learn the telltale signs of phishing emails and messages, see realistic examples, how to verify them safely and what to do if you already clicked.

Phishing is when criminals pretend to be a trusted company or person to steal passwords, money or personal data. It is still one of the most common ways accounts get hacked, and it works because the messages look convincing. These warning signs will help you catch most of them.
10 warning signs
- Urgency or threats. "Your account will be closed in 24 hours" is designed to make you act before you think.
- Unexpected requests. A password reset you did not ask for, an invoice for something you did not buy, or a delivery you are not expecting.
- A sender address that is almost right. Look at the real address, not just the display name. Small changes such as paypa1.com are common.
- Generic greetings. "Dear customer" instead of your name, although some phishing is personalized.
- Links that do not match. Hover over a link (or press and hold on a phone) to see the real destination before you click.
- Unexpected attachments. Be careful with ZIP, Office files with macros or PDFs that ask you to log in.
- Requests for sensitive information. Legitimate companies do not ask for your full password or verification codes by email or text.
- Odd payment methods. Gift cards, cryptocurrency or a new bank account for "the same supplier".
- Poor language or formatting. Typos can be a sign, though modern scams are often well written.
- Pressure to keep it secret. "Do not tell anyone" is a classic sign of fraud.
Three realistic examples
Seeing how these messages are built makes them easier to recognize. These are typical patterns, not real messages.
- The fake security alert. An email says there was a suspicious sign-in to your account and asks you to "confirm your identity" through a button. The button leads to a page that copies the real login screen and sends your password to the attacker. The safe move is to ignore the button and log in through the official app or your own bookmark.
- The changed bank details. A message that looks like it comes from a supplier you pay says their bank account has changed and asks you to use the new one. The sender address differs by one letter. Always confirm payment changes by phone, using a number you already had.
- The parcel text. A text says a delivery failed and asks you to pay a small fee on a website. If you were not expecting a parcel, or the link is not the carrier's official site, do not follow it.
How to verify safely
- Do not use the links in the message. Open the company's website by typing the address yourself or using your bookmark.
- Call the company using a phone number from its official website.
- For work requests, confirm by phone or chat with the person involved.
- Check the account directly in the official app.
Other types of phishing
- Smishing: phishing by text message, often about parcels or bank alerts.
- Vishing: phone calls from a fake bank or support agent.
- Spear phishing: targeted messages that use details about you or your company.
- QR-code phishing: a QR code that leads to a fake login page.
What to do if you clicked
- Do not enter any data. If you already did, change that password immediately and anywhere else you reused it.
- Turn on two-factor authentication on the affected account.
- Contact your bank if you shared card or banking details.
- Run a security scan if you opened an attachment.
- Report the message as phishing in your email app and, at work, tell your IT team.
Habits that protect you every day
- Use a different password for every account, so one leak cannot unlock the others.
- Keep your phone, computer and browser updated so known weaknesses are fixed.
- Pause before you click on anything that arrives unexpectedly, even from a known contact. Their account may have been hacked.
- Look at the full address in the browser bar before typing a password.
- If you run a business, agree on a rule that payment changes must be confirmed by a second channel.
Common mistakes
- Trusting a message because the logo and colors look right. Logos are easy to copy.
- Believing that only careless people are fooled. Well-made messages catch careful people too, especially when they are busy.
- Replying to a suspicious email to ask if it is real. Use a separate, trusted channel instead.
- Waiting to act after clicking. Changing passwords quickly limits the damage.
Phishing at work
Attackers like businesses because one mistake can reach many systems. Some practical steps for teams:
- Give staff a simple way to report suspicious messages, such as a dedicated address or a button in the mail client.
- Make it clear that nobody will be blamed for reporting a message that turns out to be harmless.
- Require approval from a second person for payments to new accounts or changes to bank details.
- Run short, friendly training sessions with examples so people know what a real attempt looks like.
- Limit who has administrator rights, so a single stolen password does less harm.
Frequently asked questions
Can I get infected just by opening an email?
Opening a plain email is rarely dangerous with up-to-date software. The risk comes mostly from clicking links, opening attachments or entering data on a fake page.
Does two-factor authentication stop phishing?
It helps a lot, but not completely. Some fake sites ask for your one-time code and use it immediately. Security keys and passkeys resist this better than codes sent by text.
Should I report a phishing email?
Yes. Use the "report phishing" option in your email app, and tell your IT team if it reached your work account. Reports help providers block the sender.
What if the email really is from my bank?
Do not rely on the email. Open the bank's app or website yourself, or phone the number printed on your card. A real notice will also appear there.
Final thoughts
If a message makes you feel rushed, scared or unusually excited, stop and verify it in another way. A few seconds of doubt is the cheapest security tool you have.


