How to Spot a Phishing Email or Text Message: A Practical Checklist
Updated: 10 September 2026 · Reading time: about 10 minutes
A phishing message pretends to be a trusted company, service or person so that you will reveal information, send money, install something or open a fake sign-in page. Modern phishing can look polished, use a real logo and mention current events. Spelling mistakes are no longer a reliable test.
Do not use the message’s link, attachment, QR code, phone number or reply button. Open the company’s official app, use a bookmark you already trust, or type a known address yourself. Check the account there. If the alert is real, the same issue will normally appear in the genuine account.
A 60-second phishing check
- Stop. Urgency is designed to shorten your thinking time.
- Ask whether you expected it. An unexpected invoice, delivery problem, job offer or security alert deserves extra caution.
- Check the actual sender. A display name can say “Your Bank” while the address belongs to an unrelated domain.
- Identify the requested action. Be suspicious of requests to sign in, pay, send a code, install an app, enable screen sharing or reveal personal details.
- Verify independently. Contact the organisation using a number or website you already know—not the details in the message.
- Report, then remove it. Use the email, messaging or service provider’s built-in phishing-report option when available.
The U.S. Federal Trade Commission advises people who receive a suspicious request to contact the company through a phone number or website known to be genuine, rather than using information in the email or text.
Ten warning signs
1. The message creates urgent fear
Examples include “your account closes today,” “payment failed,” “suspicious login—act now,” or “a warrant will be issued.” A genuine problem can be urgent, but urgency does not prove the message is genuine. Verify through the official account.
2. The offer creates urgent excitement
Phishing is not always threatening. A prize, refund, investment opportunity, free device or unusually well-paid job can also push you to act before checking. If you did not enter a competition, be especially careful with a surprise win.
3. The sender address does not match the organisation
Look beyond the display name. Watch for misspelled domains, extra words, random numbers or a free email address used for official business. Remember that a familiar-looking address can also be spoofed or a real account can be compromised, so the sender alone is not enough.
4. The link destination is different from the visible text
A button may say “Open Google Drive” while leading elsewhere. On a computer, hovering may reveal a destination, but a convincing-looking address is still not proof. On a phone, avoid experimenting with a suspicious link. Use the official app or your own bookmark instead.
5. It asks for a password or verification code
A verification code is designed for the sign-in you started. A scammer may already have your password and call or message for the remaining code. Never read or forward a one-time code, approve an unexpected prompt or send a backup code.
6. It changes payment instructions
An unexpected bank-account change, gift-card request, cryptocurrency address or invoice update needs verification through a known second channel. If the request appears to come from a colleague or supplier, call a number from your established records.
7. It contains an unexpected attachment
Invoices, delivery notices, résumés and shared documents are common disguises. An attachment can contain malware or lead to a fake sign-in. Confirm with the sender through a separate trusted channel before opening it.
8. It uses a QR code to move you away from the current screen
A QR code hides its destination until it is scanned. It can lead to the same kind of fake page as a normal link. Do not scan one merely because the message says it is a “secure” way to verify.
9. The request breaks the normal process
A manager who suddenly asks for gift cards, a bank that wants details by text, or support staff who want remote control are departures from normal procedure. Contact the person or organisation using a channel you already trust.
10. The story is difficult to verify
The message may discourage you from speaking to anyone, say an offer is secret or insist that only its link will work. A legitimate organisation should allow independent verification.
Common phishing stories and the safe response
| Message story | What it wants | Safer verification |
|---|---|---|
| “Your account is locked” | A sign-in through its link | Open the official app or known account page |
| “Package delivery failed” | A small fee and card details | Use the courier’s genuine site and manually enter a known tracking number |
| “Unpaid invoice attached” | Open a file or make a transfer | Call the supplier using existing records |
| “Boss needs gift cards now” | Buy cards and send the codes | Speak to the person directly through the normal workplace channel |
| “You qualify for a refund” | Identity or banking details | Find the programme on the responsible government or company site |
| “Support detected a virus” | Install remote-access software or pay | Close the contact and use the device maker’s official support page |
How to verify a message safely
- Do not reply or interact with anything inside the message.
- Write down the claimed issue in your own words, such as “card payment failed.”
- Open the provider’s app from your home screen or use a saved bookmark.
- Look for the same alert, transaction or document inside the account.
- If you must call, use the number printed on a bank card, statement or official website you found independently.
- For a message from a known person, contact them through a different established channel.
Search results and advertisements can sometimes lead to impersonation pages. For high-risk support or financial issues, prefer a previously installed official app, an existing bookmark, a number on a physical card or a domain you know and type carefully.
What if the message appears in a real conversation?
A scammer can take over a genuine email or social account and continue an existing conversation. Treat a sudden request for money, codes, secrecy or a new payment account as suspicious even when the message comes from a familiar address.
Verify using another channel. If the request arrived by email, call the person on a known number. Do not use a new phone number provided inside the suspicious message.
If you clicked but entered nothing
- Close the page. Do not download, install or allow notifications.
- If a file downloaded, do not open it. Remove it using your device’s normal file-management process.
- Update the operating system, browser and security software.
- Run the device’s trusted security scan if a file opened or software may have installed.
- Review the account’s recent security activity if the page attempted a sign-in.
A click does not always mean compromise, but the risk is higher if you installed a file, granted permissions, entered information or ignored a browser warning.
If you entered a password
- From a trusted device, open the genuine service directly.
- Change the exposed password to a new, unique password.
- If it was reused, change every account that shared it—starting with email and payments.
- Sign out of unfamiliar sessions and remove unknown devices, apps or recovery methods.
- Turn on two-step verification and replace backup codes if necessary.
- Check email forwarding rules, sent messages, payment activity and security alerts.
If you shared a code or approved a prompt
Treat the account as potentially accessed. Deny any further prompts, change the password through the official account page, revoke unknown sessions and review recovery details. If the account controls money, business systems or other people’s data, notify the responsible provider or administrator immediately through an established channel.
If you sent money or card information
Contact the bank, card issuer or payment provider immediately using a verified number. Ask what protective steps are available. Do not pay a second person who promises to “recover” the money for an upfront fee. Preserve the message, transaction details and relevant timestamps for a legitimate report.
How to report phishing
- Use the email or messaging app’s Report phishing or Report spam feature.
- Report an impersonated organisation through its official abuse or security channel.
- Notify a workplace security team if the message concerns a work account or data.
- In the United States, the FTC directs reports to ReportFraud.ftc.gov; other countries have their own national reporting channels.
- If money, identity documents or banking information were exposed, contact the relevant institution promptly.
Preserve evidence before deleting a message when a bank, employer or law-enforcement report may need it. Do not forward a dangerous attachment to friends as a warning.
Reduce the damage before a phishing attempt arrives
- Use unique passwords stored in a password manager.
- Enable the strongest practical multi-factor method on important accounts.
- Keep phones, computers, browsers and security tools updated.
- Turn on transaction and sign-in alerts through official apps.
- Keep offline or separately protected backups of important data.
- Limit public details that can make impersonation more convincing.
- Agree on a second-channel verification process for family or workplace money requests.
Frequently asked questions
Does HTTPS mean a link is safe?
No. HTTPS protects the connection to a site; it does not prove the person operating the site is honest. A phishing site can also use HTTPS.
Can a phishing email have perfect spelling?
Yes. Professional wording, a real logo and correct personal details can all appear in a scam. Judge the request and verify it independently.
Is the sender address enough to prove a message?
No. Addresses can be imitated, and legitimate accounts can be compromised. A sensitive or unusual request should be confirmed through a separate trusted channel.
Should I unsubscribe from a suspicious email?
Use the unsubscribe link only for a legitimate sender you recognise. In an obvious scam, clicking can confirm that your address is active or lead elsewhere. Report it through the mail provider instead.
Final checklist
- I did not use the message’s link, attachment, QR code or phone number.
- I checked the real sender and the exact action being requested.
- I opened the official account independently.
- I verified money or account changes through a second trusted channel.
- I did not share a password, one-time code, backup code or screen access.
- I reported the message through the relevant service.
Sources and review note
- U.S. Federal Trade Commission: How to Recognize and Avoid Phishing Scams
- Google Account Help: Turn on 2-Step Verification
Editorial note: Scams and reporting routes change. This guide provides general safety steps; use official local channels for a financial loss, identity theft or active workplace incident.
Comments
Post a Comment