What phishing emails actually look like
A phishing email is a message designed to trick you into giving up a password, bank details, or other sensitive information by pretending to be from a company or person you trust. The sender is not who they claim to be, and clicking links or opening attachments can install malware on your device or take you to a fake website that looks real.
Phishing emails often create fake urgency — your account will be closed, a payment failed, you need to confirm your identity right away. They ask you to click a link and log in, reset a password, or read a document. The email might look almost identical to a real message from your bank, PayPal, Amazon, or your employer, but small details give it away if you know where to look.
The goal is always the same: get you to enter credentials or personal information on a fake website, or get you to run malicious code. Once they have your password, they can access your real account. Once malware is installed, they can monitor everything you type.
Key Takeaways
- Check the sender's email address carefully — phishing emails often use addresses that look similar to the real company but have a slightly different domain name.
- Hover over links before clicking to see the actual URL; if it does not match the company name or looks suspicious, do not click.
- Real companies rarely ask you to log in, reset passwords, or confirm sensitive information by email — they ask you to go directly to their website or call them.
- Look for spelling errors, awkward phrasing, generic greetings like "Dear Customer," and mismatched logos or formatting as signs the email is not legitimate.
- If you are unsure, contact the company directly using a phone number or website you know is real, not contact information from the email itself.
How to check the sender's email address
The sender's email address is the first place to look. Real companies use their own domain — Amazon uses @amazon.com, your bank uses its official domain, your employer uses the company domain. Phishing emails often use addresses that look similar but are slightly different: @amaz0n.com (zero instead of the letter O), @amazonservices.co, or completely unrelated domains like @find-verify-account.com.
Click on the sender's name or address to see the full email header. Different email programs show this differently — in Gmail, click the three dots next to "Reply" and select "Show original." In Outlook, right-click the message and choose "Message Options." You will see the actual email address the message came from, which is harder to fake than the display name.
If the sender claims to be from your bank but the address is from a free email service like Gmail or Yahoo, it is phishing. Real companies use their own domain for official communications.
Checking links before you click them
Never click a link in an email without checking where it actually goes first. Hover your mouse over the link (do not click) and look at the bottom left corner of your screen — most email programs will show you the real URL. If the link text says "Click here to verify your account" but the URL shown is something like "http://phishing-site.ru/fake-login", do not click.
Real links from real companies go to the company's actual website. If an email from your bank asks you to click a link to log in, the URL should start with the bank's real domain name. If it starts with something else, or if you cannot see the URL clearly, do not click.
A safer approach: do not click email links at all for sensitive actions. If an email claims your bank account needs attention, go directly to your bank's website by typing the address into your browser or calling the number on the back of your card. Do not use contact information from the email.
Red flags in the message itself
Phishing emails often contain spelling mistakes, awkward grammar, or odd phrasing that a real company would catch. Look for "Dear Customer" or "Dear User" instead of your actual name — real companies usually personalize messages. Check for mismatched logos, strange formatting, or images that do not load properly.
Urgent language is a common tactic: "Your account will be closed in 24 hours," "Confirm your identity when ready," "Unusual activity detected — act now." Real companies do send urgent messages sometimes, but they also provide clear next steps and do not pressure you to click a link in the email. If you feel rushed, that is a sign to stop and verify through another channel.
Generic greetings, requests for passwords or full credit card numbers, and links that do not match the company name are all warning signs. Real companies never ask for passwords by email.
What to do if you think you received a phishing email
Do not click any links or read any attachments. Do not reply to the email. If the email claims to be from a real company, contact that company directly using a phone number or website you know is legitimate — not information from the email itself.
Report the email to your email provider. In Gmail, click the three dots and select "Report phishing." In Outlook, click "Junk" and then "Phishing." You can also forward phishing emails to the real company — most have a dedicated email address for reporting fraud. For example, you can report Amazon phishing to stop-spoofing@amazon.com.
If you already clicked a link or entered information, change your password when ready from a different device if possible. If you entered credit card or banking information, contact your bank or card issuer right away. Many banks have fraud departments that can monitor your account and issue new cards if needed.
How phishing emails get your address
Phishing emails are often sent to thousands of addresses at once in the hope that some will work. They buy email lists from data breaches, scrape addresses from websites, or use common naming patterns to guess addresses. You do not have to have been hacked for your email to end up on a phishing list.
If you receive a phishing email, it does not mean your account has been compromised — it means someone has your email address and is trying to trick you. The fact that they do not know your real name or account details is actually a sign it is phishing, not a targeted attack.
Phishing emails that reference a real breach or data leak are more convincing because they use information that is actually public. If an email mentions a company you use and references a real incident, it is still phishing if it is asking you to click a link or enter credentials.
Frequently Asked Questions
What if the email looks exactly like a real message from my bank?
Phishing emails can look very similar to real ones because scammers copy the design and logos. The difference is in the details: check the sender address, hover over links, and remember that your real bank will not ask you to log in by email. When in doubt, call your bank using the number on your card or statement.
Is it safe to open a phishing email if I do not click anything?
Opening and reading an email is usually safe. The danger comes from clicking links, downloading attachments, or entering information. Some advanced phishing emails can run code just by opening them, but this is rare. If you are worried, do not open suspicious emails at all.
Can phishing emails infect my computer with a virus?
Phishing emails themselves do not usually contain viruses, but attachments can. If you read and open a file from a phishing email, malware can be installed. Never read attachments from emails you do not trust, even if the sender looks legitimate.
What should I do if I already gave them my password?
Change your password when ready from a different device. Use a strong, unique password that you have not used anywhere else. If you used the same password on other accounts, change those too. Monitor your account for suspicious activity and consider enabling two-factor authentication if the service offers it.
How do I know if a website is fake?
Check the URL in your browser's address bar — it should match the company name and use https (with a lock icon). Look for spelling errors in the domain name. If a login page looks slightly off or the website feels slow, leave and go to the company's official site instead. Never log in through a link in an email.