Skip to content
TECHNOARTH Technology in practice.
Security

How to spot phishing: the signs of a fake email or message

Got an urgent email asking you to confirm details or click a link? Here are the signs of phishing, how to check the sender and link before clicking, and what to do if you already clicked.

Phishing is a fake message that tries to get you to hand over a password or card details, or install malware — usually pretending to be a bank, a store, a delivery company, the government or your own company’s IT support. It arrives by email, text message, WhatsApp or social media. The signs repeat; learn to recognize them.

Fictitious phishing email example with an odd sender domain, urgent subject, fake link and .zip attachment highlighted
The signs: odd sender domain (1), urgency and threats (2), a link that isn’t the official site (3) and a compressed attachment (4).
In this article
  1. The most common signs
  2. How to check before you click
  3. If you already clicked or typed your password
  4. How to report it
  5. FAQ

The most common signs

  1. Odd sender: the name looks official, but the address is from another domain (@account-security-check.xyz, not the company’s real domain).
  2. Urgency or threats: “your account will be locked in 24 hours”, “last chance”, “payment declined”.
  3. A link that doesn’t go to the official site: the link text says one thing, but the real address is another.
  4. Unexpected attachments: especially .zip, .exe, .html or Office documents asking you to “enable content”.
  5. Requests for passwords, codes or full card details: legitimate companies don’t ask for these by email or message.
  6. Mistakes and generic greetings: “Dear customer”, spelling errors and odd formatting.

How to check before you click

  • Hover over the link (without clicking): the real address appears at the corner of the screen. On a phone, press and hold the link.
  • Read the domain from right to left: in bank.com.secure-login.xyz, the real site is secure-login.xyz — not the bank.
  • When in doubt, don’t use the link: type the official address into your browser or open the company’s app.
  • Confirm through another channel: call the official number or ask the supposed sender in person (including coworkers and your boss).

If you already clicked or typed your password

  1. Change the password right away from a trusted device, and everywhere you used the same one.
  2. Turn on two-factor authentication.
  3. If you entered card details, call your bank and ask them to block the card.
  4. If you downloaded an attachment, run a full malware scan.
  5. At work, tell IT immediately — the sooner, the less damage.

If your email account was already taken over, see email hacked: what to do.

How to report it

  • In Outlook, use Report › Report phishing; in Gmail, ⋮ › Report phishing.
  • At companies, follow IT’s process (many have their own button in Outlook).

FAQ

The email came from the company’s real address. Can it be phishing?

Yes, if the sender’s account was compromised, or if the domain isn’t protected against spoofing. Domain owners should set up SPF, DKIM and DMARC.

Is just opening the email dangerous?

Opening and reading is usually safe. The risk is clicking links, opening attachments and typing in details.

Does a padlock mean the site is safe?

No. The padlock (HTTPS) only means the connection is encrypted — fake sites use it too. Always check the address.

Share

About the author

TECHNOARTH Editorial Team

The TECHNOARTH newsroom: technology tutorials, guides, comparisons and news produced with AI assistance and checked against manufacturers’ official sources.