Email security

How to spot a phishing email: the red flags that matter

Phish Plug TeamMay 27, 20267 min read

Spotting a phishing email used to be easy: bad grammar, a strange address, an obvious scam. It is harder now. Still, reliable red flags remain — and knowing which ones still hold (and which no longer do) is the core of email security awareness.

The red flags that still matter

  • Urgency and threats — "act now," "account will be closed," "final notice." Pressure is the oldest trick and still the most common.
  • Sender mismatch — the display name says your bank; the actual address does not.
  • Link mismatch — the visible text and the real destination differ (hover or long-press to check).
  • Requests for credentials or payment — legitimate organisations rarely ask you to confirm a password by email.
  • Unexpected attachments — especially ones urging you to enable content.
  • Generic greetings — "Dear customer" where your name is expected.

The flag that no longer works

"Look for spelling mistakes" is outdated advice. AI writes fluent, personalised, error-free emails, so language quality tells you little. Judge behaviour instead: what is the message asking you to do, how urgently, and does the sender and link actually check out?

The modern test isn't 'does it look clumsy?' — it's 'is it pressuring me to act on a link or payment?' Urgency plus an action is the real pattern.

Why brands can't rely on this alone

Teaching people the red flags helps, but it cannot catch everything — especially targeted lures and cloaked pages that look clean to checks. For a brand, awareness is one layer. Authenticating your domain, verifying requests, and removing the fake pages behind the links protect customers who miss the signs.

Phish Plug covers the layer awareness can't: it finds and takes down the cloned pages and lookalike domains that phishing emails link to.

The takeaway

The durable red flags are about behaviour — urgency, mismatched senders and links, requests for credentials or money — not spelling. Train people on those, but back it with authentication and takedowns, because no one spots every lure.

Remove the clones targeting your brand

Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.