What phishing emails look like and why they get through
A phishing email is a message designed to trick you into revealing passwords, bank details, or personal information by pretending to come from a bank, payment service, email provider, or other organization you trust. The sender's address often looks real — it might say "support@paypa1.com" (with a number 1 instead of the letter l) or use a display name like "Amazon Security" even though the actual address is something else entirely.
These emails get through your inbox because they arrive before your email provider's filters catch them, or because the filters are set to let most mail through by default. Your email account comes with some automatic protection, but it catches only the most obvious ones. The rest depends on what you do with the message itself and what rules you set up.
Key Takeaways
- Check the sender's actual email address by hovering over or clicking the sender's name — not the display name — because phishing emails fake the display name but the real address reveals the truth.
- Most email providers let you mark messages as spam or phishing, which trains the filter and removes the message from your inbox when ready.
- Create rules in your email settings to automatically send messages from known phishing addresses to spam or delete them, so you never see them again.
- Turn on two-factor authentication on accounts that matter — banks, email, payment services — so a stolen password alone cannot get someone in.
- Never click links or read attachments from emails asking you to confirm information, even if the sender looks legitimate.
How to identify the real sender address
The display name at the top of an email — "Bank of America" or "PayPal Support" — is not the sender's real address. Anyone can type any name there. The real address is what comes after the @ symbol, and that is what you need to check.
In Gmail, click the down arrow next to the sender's name to see the full address. In Outlook, right-click the sender's name and select "View Message Details" or look for a "From:" field that shows the complete address. In Apple Mail, click the sender's name to expand it. If the address does not match the organization — for example, if it says "noreply@find-paypal-verify.com" instead of something from paypal.com — it is phishing.
Phishing senders often use addresses that look similar to the real thing: "paypa1.com" (with a 1), "amaz0n.com" (with a 0), or "support-amazon.net" (a different domain extension). The only way to catch this is to look at the actual address every time someone asks you to confirm information or log in.
Mark messages as spam or phishing in your email provider
Every major email provider has a button or menu option to report a message as phishing or spam. This does two things: it removes the message from your inbox when ready, and it tells the provider's filter that this sender is dangerous, so future messages from that address are more likely to land in spam automatically.
In Gmail, open the message, click the three dots at the top right, and select "Report phishing." In Outlook, click the "Junk" button at the top and choose "Phishing." In Apple Mail, click "Message" in the menu bar, then "Mark as Junk." Do this every time you see a phishing email, even if you already deleted it — the report matters more than the deletion.
After you report a message, check your spam or junk folder to make sure it landed there. If the same sender keeps getting through, move to the next step and create a rule.
Create rules to automatically block known phishing senders
If you receive repeated phishing emails from the same address, you can create a rule that automatically sends all future messages from that sender to spam or deletes them. This stops you from seeing them at all.
In Gmail, open a message from the phishing sender, click the three dots, select "Block [sender]," and confirm. Gmail will automatically send all future messages from that address to spam. In Outlook, right-click the message, select "Junk," then "Block Sender." In Apple Mail, select the message, click "Mail" in the menu bar, then "Junk Mail" and "Add Sender to VIP List" — actually, Apple Mail does not have a direct block feature, so instead select the message and drag it to the Junk folder, then right-click and select "Mark as Junk" to train the filter.
For more control, you can create a custom rule. In Gmail, click the three dots on a message from the sender, select "Filter messages like these," and choose to delete or skip the inbox. In Outlook, go to Settings, then "Mail," then "Rules," and create a new rule that matches the sender's address and moves it to Deleted Items. These rules stay in place until you delete them, so you only have to set them up once.
Turn on two-factor authentication on important accounts
Even if a phishing email tricks you into entering your password, two-factor authentication (also called 2FA) prevents someone from logging in with that password alone. They would also need a code from your phone or an authentication app, which they cannot get.
Turn on two-factor authentication on your email account first — this is the master key to everything else. Then turn it on for your bank, payment services like PayPal or Venmo, and any account that holds money or sensitive information. Most services offer it in their security settings under "Two-Factor Authentication," "Two-Step Verification," or "Login Verification."
You will choose between receiving codes by text message, using an authentication app like Google Authenticator or Microsoft Authenticator, or using a security key. Text message is the easiest to set up, though authentication apps are slightly more find. Either one is far better than no two-factor authentication.
What to do if you already clicked a phishing link
If you clicked a link in a phishing email or entered your password on a fake login page, change your password when ready on the real website. Go directly to the organization's official website by typing the address yourself — do not click any link in the email — and log in with your current password. Then go to account settings and change your password to something new.
If the account is a bank or payment service, contact them by phone using the number on your bank card or statement, not a number from the email. Tell them what happened so they can watch for unauthorized activity. If you entered credit card information, contact your card issuer and ask them to watch for fraud.
Turn on two-factor authentication if you have not already, and check your account activity or recent logins to see if anyone else has accessed it. Most banks and email providers show you a list of devices that have logged in recently.
Why phishing still works even with filters
Email filters catch obvious phishing — messages with misspellings, suspicious attachments, or known malicious links. But sophisticated phishing emails look almost identical to real messages from real organizations. They use the organization's actual logo, correct formatting, and plausible reasons to ask for information. The filter cannot tell the difference because the email itself is not technically broken or malicious — it is just dishonest.
This is why checking the sender's real address matters more than any filter. A filter can be fooled, but the actual email address cannot. If the address does not match the organization, it is phishing, no matter how real the message looks.
Frequently Asked Questions
Can I get hacked just by opening a phishing email?
Opening an email alone will not hack you. Phishing works only if you click a link in the email or read an attachment. If you opened a phishing email by accident and did nothing else, you are safe. Delete it and move on.
What if the phishing email has my real name or personal information in it?
Phishing senders often buy lists of names and email addresses from data breaches, so they know your real name. This does not mean they have access to your account — it just means they bought your information on the dark web. Check the sender's real address and ignore the message.
Should I reply to a phishing email to tell them to stop?
No. Replying confirms that your email address is active and monitored, which makes you a better target for future phishing. Delete the message and mark it as phishing instead.
Do I need to worry about phishing if I use a password manager?
A password manager helps because it will not fill in your password on a fake website — it only fills in passwords on the real domain. But you still need to check the sender's address and avoid clicking suspicious links, because a password manager cannot protect you from other types of scams.
What is the difference between phishing and spam?
Spam is unwanted mail that tries to sell you something, like discount offers or weight loss pills. Phishing is mail designed to steal information or money by pretending to be someone trustworthy. Spam is annoying; phishing is dangerous. Both should be marked as spam or phishing in your email provider.