Home / Guides / Email and Messaging
How to Spot a Phishing Email
Phishing is when a scammer pretends to be a company or person you trust to steal your passwords, money or personal information. It works because the messages look real and create pressure. Here is how to recognize them.
The common warning signs
- Urgency or threats. "Your account will be closed in 24 hours" or "Unusual activity, act now."
- A request for sensitive information. Legitimate companies do not ask you to email passwords, full card numbers or one-time codes.
- A sender address that is slightly off. For example, a real name with an unrelated domain, or a look-alike domain such as one with a swapped letter.
- Links that do not match. On a computer, hover over a link to see where it really goes. On a phone, press and hold the link.
- Unexpected attachments. Especially invoices, "documents to sign" and compressed files.
- Generic greetings like "Dear customer" from a company that normally uses your name.
- Too good to be true. Prizes, refunds and job offers you did not ask for.
- Odd requests from someone you know. A boss asking for gift cards, or a relative asking for urgent money. Their account may have been hacked.
What to do instead
- Do not click links or open attachments.
- Go to the company directly. Type the site address yourself or use the official app.
- Call a phone number you already trust, not one in the message.
- Verify requests from people you know through a different channel.
- Take a minute. Scammers rely on you rushing.
If you already clicked or replied
- If you entered a password: change it now on the real site, and everywhere else you reused it. Turn on two-factor authentication.
- If you entered card or bank details: call the bank or card issuer and ask about freezing or replacing the card.
- If you opened an attachment: disconnect from the internet, run a security scan and update your device.
- If you shared your Social Security number or other identity details: visit IdentityTheft.gov, the official U.S. government site, to report it and get a recovery plan.
- Consider a free credit freeze with the three credit bureaus. See our guide on what to do after a data breach.
Where to report phishing in the United States
- Forward phishing emails to reportphishing@apwg.org, run by the Anti-Phishing Working Group.
- Report scams to the Federal Trade Commission at ReportFraud.ftc.gov.
- Use the "report phishing" or "report spam" button in your email app.
- Tell the company being impersonated, using its official contact details.
Protect yourself before it happens
- Use a password manager, which will not fill your password on a fake site with the wrong address.
- Use two-factor authentication, ideally with an authenticator app or security key instead of text messages where possible.
- Where a site offers passkeys, use them. They are much harder to phish.
- Keep your devices and browsers updated.