How to spot a phishing email: the red flags that matter
Spotting a phishing email used to be easy: bad grammar, a strange address, an obvious scam. It is harder now. Still, reliable red flags remain — and knowing which ones still hold (and which no longer do) is the core of email security awareness.
The red flags that still matter
- Urgency and threats — "act now," "account will be closed," "final notice." Pressure is the oldest trick and still the most common.
- Sender mismatch — the display name says your bank; the actual address does not.
- Link mismatch — the visible text and the real destination differ (hover or long-press to check).
- Requests for credentials or payment — legitimate organisations rarely ask you to confirm a password by email.
- Unexpected attachments — especially ones urging you to enable content.
- Generic greetings — "Dear customer" where your name is expected.
The flag that no longer works
"Look for spelling mistakes" is outdated advice. AI writes fluent, personalised, error-free emails, so language quality tells you little. Judge behaviour instead: what is the message asking you to do, how urgently, and does the sender and link actually check out?
The modern test isn't 'does it look clumsy?' — it's 'is it pressuring me to act on a link or payment?' Urgency plus an action is the real pattern.
Why brands can't rely on this alone
Teaching people the red flags helps, but it cannot catch everything — especially targeted lures and cloaked pages that look clean to checks. For a brand, awareness is one layer. Authenticating your domain, verifying requests, and removing the fake pages behind the links protect customers who miss the signs.
Phish Plug covers the layer awareness can't: it finds and takes down the cloned pages and lookalike domains that phishing emails link to.
The takeaway
The durable red flags are about behaviour — urgency, mismatched senders and links, requests for credentials or money — not spelling. Train people on those, but back it with authentication and takedowns, because no one spots every lure.
Keep reading
Related articles
DMARC, SPF and DKIM: stop attackers spoofing your domain
Three email-authentication standards decide whether someone can send mail as you. What SPF, DKIM and DMARC do, and how to roll them out without breaking mail.
Read article Email security · 6 minEmail spoofing: how attackers fake your 'from' address
Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.
Read article Detection · 8 minDomain monitoring: a practical buyer's guide
What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.
Read articleRemove the clones targeting your brand
Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.