Skip to Main Content
Back to Learning CenterSecurity

How to spot a phishing email before you click

By Samuel ChenardAugust 25, 20269 min read

In brief

Learn how to spot a phishing email by checking its request, sender, links, and context, then verify the claim safely without using the message.

How to spot a phishing email before you click

To spot a phishing email, check what it wants before judging how polished it looks. Treat unexpected links, attachments, phone numbers, payment demands, passwords, and verification-code requests as reasons to stop. Then verify the claimed event through an app, website, statement, or contact method you open independently. A logo, familiar display name, or urgent subject line cannot replace that check.

At a glance

Quick takeaways

  • Start with the requested action, not the logo or writing quality.
  • Do not click, call, reply, download, or sign in while the message is unverified.
  • Read the complete sender address and the real destination behind each link.
  • Compare the claim with an account or record you open separately.
  • Report the message through your mailbox and the impersonated organization's current official path.
  • If you already interacted, protect the affected account before doing more analysis.

What are the clearest signs of a phishing email?

The strongest warning sign is a message that tries to keep the entire decision inside channels chosen by the sender. It gives you a button to fix the problem, a number to call, a reply address to contact, or an attachment to open. If every route back to safety comes from the same unverified message, you have no independent confirmation.

Common phishing patterns include a claimed account lock, failed payment, unfamiliar purchase, refund, shared document, voicemail, tax notice, delivery problem, or security alert. Each pretext creates a reason to act. The requested action may be entering a password, sharing a one-time code, paying an invoice, installing software, opening a document, calling a fake support desk, or changing bank details.

CISA's guidance on recognizing and reporting phishing advises people to resist urgent requests, avoid suspicious links or attachments, and use a known contact method to verify the message. The point is not that urgency proves fraud. Urgency tells you to slow the process down and obtain evidence elsewhere.

Spelling mistakes can support suspicion, but clean grammar does not make a message genuine. Modern templates can copy branding, legal footers, personal names, and transaction details. The decision should survive even when the message looks professional.

For a broader gallery of patterns, use the phishing email examples guide. This page focuses on the checks you can apply to the message in front of you.

How do I check the sender without trusting the display name?

Expand the sender details and read the complete address. A display name such as "Account Security" or the name of a company is chosen text. The domain after the final @ matters more than the name before it, but it is still only one clue.

Look for substitutions, extra words, unexpected domains, and familiar words placed inside a longer hostname or URL path. Do not infer ownership from one recognizable word. Compare the complete hostname with a destination you reached independently through the organization's app, a trusted bookmark, or a typed address.

Do not turn one familiar sender domain into a permanent allowlist. Organizations can use several authorized services, and a compromised account can send harmful content through a legitimate system. An unfamiliar domain should trigger caution, while a familiar one should still be checked against the request and the independently verified account event.

The reply address also matters. If Reply-To sends the conversation somewhere different from the visible sender, record the mismatch. Do not test it by replying because that keeps you in the sender's chosen channel.

Use the preview your mail client exposes, such as hovering on a desktop or a long press on a mobile device, without navigating. Compare the displayed label with the actual destination. Shortened links, encoded redirects, unrelated domains, and misspelled hostnames all justify stopping.

Be careful with buttons. A large "Review activity" button can hide a destination that would be obvious in plain text. The visible company name, a padlock icon, or https does not establish that the destination belongs to the organization named in the email.

Do not open a suspicious link merely to inspect the page. If an authorized security team needs the URL, preserve it without visiting it and follow the team's evidence-handling process.

The phishing link checker can inspect public URL signals without requiring you to visit the destination. A clean result is not proof that the message or account claim is legitimate, so keep the independent verification step.

How do I verify the claim without touching the email?

Leave the message open only as a reference. Start a new browser window, use a saved bookmark, open the established app, consult a statement you already possess, or call a number printed on a card or prior document. Do not copy a contact method from the suspicious message.

Match a specific claim with specific evidence:

  • For a purchase or payment, look for the transaction in the independently opened account and in your own payment records.
  • For a password or sign-in alert, open the account's security area and review recent activity.
  • For a shared file, contact the supposed sender through a known channel and ask what they sent.
  • For an invoice or bank-detail change, confirm it with the known person or organization using an established number.
  • For a delivery or subscription issue, open the relevant service directly and look for the same status.
A real issue can exist alongside a malicious email. If your card was declined or your password needs attention, finish the task only through the independent session. Do not return to the email button once you have confirmed the underlying event.

How should I report a phishing email?

Locate the reporting process documented for the mailbox that received the message. The available control, forwarding method, and deletion guidance depend on the provider or organization, so do not assume that every mailbox uses the same button. If the message reached a work account, follow the organization's security process as well.

To alert the impersonated organization, find its current security or fraud guidance from an official site or app you opened yourself. Do not use a reporting address, form, or number supplied by the suspected email. Reporting routes change, and different message types may have different paths.

Do not forward active attachments or links to coworkers for informal opinions. If a reviewer needs the message, use the approved reporting workflow. The guide to reporting email phishing scams covers evidence preservation and reporting destinations without turning the suspicious email into a new distribution path.

What if I already clicked, replied, or entered information?

The response depends on what left your control. Close the page, stop further interaction, and use a trusted device if you think the current one may have downloaded or installed something.

  • If you entered a password, change it through the real account and change any other account that reused it.
  • If you shared a verification code or approved a sign-in, review sessions, devices, recovery details, and recent account changes.
  • If you supplied card or bank details, contact the financial institution through the number on the card or another verified channel.
  • If you installed software or opened an unexpected attachment, disconnect only when your incident procedure calls for it and contact the security team.
  • If you sent money, contact the payment provider promptly and keep receipts, timestamps, and message evidence.
Do not spend time proving the message was phishing before protecting the affected account. Recovery is time-sensitive even when attribution remains uncertain. The recovery guide for a clicked phishing link separates password, payment, device, and workplace response paths.

Does passing authentication mean the email is safe?

Delivery does not make the sender's claim true, and an authentication pass does not make the message honest. Treat inbox placement and domain-authentication results as separate from the account, payment, document, or support claim you still need to verify.

DMARC connects a passing authentication result to the domain visible in the From address and publishes a domain owner's requested handling policy for failures. That result is domain-identity evidence. Verify the message's payment, document, support, or account claim through the separate process described above.

The Palisade guide on why phishing emails can pass SPF and DKIM explains that boundary. For the person holding a suspicious message, independent account verification remains the decisive step.

A repeatable phishing decision rule

Use the same sequence whenever an unexpected email demands action:

  • Name the claim in one sentence.
  • Name the requested action in one sentence.
  • Identify which parts of the verification path came from the message.
  • Stop using those parts.
  • Open a trusted account, record, app, site, or contact method separately.
  • Compare the claimed event with the independent evidence.
  • Report the message through current official paths.
  • Start recovery immediately if credentials, money, codes, or device access were exposed.
This rule is more dependable than memorizing logos, templates, or old sender addresses. It also works when the message mixes a genuine account fact with a fraudulent instruction.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

See which senders are using your domain

Start in Palisade.

Get started

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles and tools