What phishing emails look like and how they work

A phishing email is a message designed to trick you into revealing passwords, credit card numbers, or other sensitive information by pretending to be from a company or person you trust. The sender might claim to be your bank, PayPal, Amazon, your employer, or a service you use regularly. They create urgency — your account is locked, suspicious activity was detected, you need to confirm your identity — and include a link that looks legitimate but actually leads to a fake website that captures whatever you type.

Phishing works because the emails often look nearly identical to real messages from the companies they impersonate. The sender address might be slightly off (like "amaz0n.com" instead of "amazon.com"), the logo might be copied, and the language might match the company's tone exactly. You are not being careless if you fall for one — these are designed by people whose job is to make them convincing.

The goal is almost always the same: get you to click a link and enter your login credentials on a fake website, or get you to download an attachment that installs malware on your computer. Once they have your password, they can access your real account. Once malware is installed, they can steal information or lock your files until you pay them.

Key Takeaways

  • Phishing emails create false urgency and ask you to click a link or download a file to "verify" or "confirm" something about your account.
  • Check the sender's email address carefully — phishing addresses often use similar-looking domains or misspellings of the real company name.
  • Hover over any link in the email to see where it actually goes before you click it; the displayed text may not match the real destination.
  • Real companies rarely ask you to enter passwords or credit card numbers by clicking a link in an email — they direct you to log in through their official website or app instead.
  • If you are unsure, contact the company directly using a phone number or website address you find yourself, not one provided in the suspicious email.

Check the sender's email address

The sender's address is the first place to look. Legitimate companies send from their own domain — Amazon uses @amazon.com, PayPal uses @paypal.com, your bank uses its official domain. Phishing emails often come from addresses that look similar but are not quite right: @amaz0n.com (zero instead of the letter O), @paypa1.com (one instead of the letter L), @amazons-security.com, or completely unrelated addresses like @mail-verification.net.

Open the email and look at the full sender address, not just the display name. Many email clients show only a friendly name like "Amazon Customer Service" — click on that name or look for a "details" option to see the actual email address behind it. If the address does not match the company's real domain, it is almost certainly phishing.

One exception: some companies use third-party services to send emails, so the sender address might be from a different domain than you expect. If you are unsure whether an address is legitimate, go to the company's official website and look for contact information or a help page that lists their official email addresses.

Hover over links before clicking them

Phishing emails often include links that look like they go to the real company's website but actually lead somewhere else. The text of the link might say "Click here to verify your account" and appear to point to amazon.com, but the actual destination could be a completely different website.

Before you click any link in an email, hover your mouse over it (do not click). Your email client will show you the real web address the link points to, usually in a small popup or at the bottom of your screen. If the address does not match what the link text says, or if it looks suspicious, do not click it.

On a phone or tablet, you can usually long-press a link to see where it goes without clicking it. If you cannot see the destination, it is safer to assume the email is phishing and delete it.

Look for requests to enter passwords or payment information

Real companies almost never ask you to enter sensitive information by clicking a link in an email. Banks, PayPal, Amazon, and other services know that email is not secure. If they need you to update your password or confirm your identity, they will direct you to log in through their official website or app — not through a link in an email.

If an email asks you to "verify your account," "confirm your identity," "update your payment method," or "click here to unlock your account," treat it as suspicious. Legitimate companies might send you a notification that something needs attention, but they will tell you to go directly to their website or app to handle it, not to click a link in the email.

The same applies to attachments. Do not download files from emails asking you to "confirm" or "verify" anything, especially if the sender is someone you do not know or if the request is unexpected.

Watch for generic greetings and poor grammar

Many phishing emails use generic greetings like "Dear Customer" or "Dear User" instead of your actual name. Real companies usually personalize their emails with your name or account number. If an email from your bank addresses you as "Dear Valued Customer," it is a red flag.

Phishing emails also often contain spelling mistakes, awkward phrasing, or grammatical errors. A message from a major company should be professionally written. Phrases like "We need to verify your informations" or "Your account has been compromised, please click the link below to secure it immediately" are common in phishing attempts.

This is not a perfect test — some phishing emails are well-written, and some legitimate emails from international companies might have minor grammar issues. But combined with other warning signs, poor writing is worth noting.

Be suspicious of unexpected urgency and threats

Phishing emails create pressure to act fast. They might say your account will be closed, your credit card will be blocked, suspicious activity was detected, or you need to confirm something immediately. The goal is to make you panic and click before you think.

Real companies do send urgent messages sometimes — if your account is actually compromised or your payment method failed. But they will not threaten to close your account unless you click a link in an email. If an email creates strong urgency and asks you to click a link or download something, pause and verify it through another method.

Contact the company directly using a phone number from their official website, or log into your account through their app or website (not through the email link) to check if there is actually a problem. If there is nothing wrong when you log in yourself, the email was phishing.

What to do if you receive a phishing email

If you suspect an email is phishing, do not click any links or download any attachments. Delete it, or if your email client has a "Report as Phishing" or "Report Spam" button, use that instead of deleting. This helps your email provider identify and block similar emails in the future.

If you already clicked a link or entered information, change your password immediately using the official website or app, not through any link in the email. If you entered credit card information, contact your card issuer. If you downloaded an attachment, run a scan with your antivirus software or take your device to a professional.

You can also report phishing emails to the company being impersonated. Most companies have a way to forward phishing attempts — Amazon has phishing@amazon.com, for example. Check the company's official website for their phishing report address.

Frequently Asked Questions

What should I do if I already clicked a phishing link?

If you clicked the link but did not enter any information, you are likely safe — just close the page. If you entered a password or credit card number, change your password immediately on the real website (not through any link in the email), and contact your bank or credit card company if you entered payment information. Run antivirus software on your device to check for malware.

Can phishing emails come from someone I know?

Yes. Scammers can hack email accounts or spoof email addresses to make messages appear to come from people you trust. If you receive an unusual request from a friend or colleague — especially one asking you to click a link or send money — contact them through another method (phone call, text message, in person) to verify they actually sent it.

Why do phishing emails look so similar to real emails?

Scammers copy logos, formatting, and language from real company emails to make their messages look legitimate. They often use publicly available information from company websites and previous emails. This is why checking the sender address and hovering over links is more reliable than judging an email by how it looks.

Is it safe to unsubscribe from a phishing email?

No. Clicking an unsubscribe link in a phishing email confirms to the scammer that your email address is active and monitored, which makes you a more valuable target. Just delete the email or use your email client's report spam feature instead.

Do I need to worry about phishing on my phone?

Yes. Phishing emails work the same way on phones as on computers. The same rules apply: check the sender address, do not click suspicious links, and do not enter passwords or payment information. Phone email apps sometimes make it harder to see the full sender address or link destination, so be extra cautious.