Phishing messages try to look real enough that you act without thinking. The good news is they tend to share the same tells, and once you know them you can spot one in seconds. This is a short self-check to run on the next suspicious message you get.
The tells
Read the message and look for these signs. One alone can be innocent, but two or three together is a strong warning.
- Pressure to act now. Threats of closure, fees, or a lost prize, all demanding you respond immediately.
- A sender address that is slightly off. Look past the display name at the real address. Small changes, extra words, or an odd domain are common.
- A link that goes somewhere else. Hover over or press and hold the link to preview the real address. If it does not match the company’s genuine site, do not tap it.
- A request for a password or code. Real services do not ask you to send or read out your password or a one-time code.
- A generic greeting. « Dear customer » or « Dear user » where a real account would normally use your name.
How to run the check
- Pause before you tap or reply. Give yourself one calm minute.
- Go through the list above and count the tells.
- If anything is off, do not use the message’s links. Open the real site or app yourself and check there.
Tip. When you are unsure, treat it as suspicious and verify another way. It costs a minute, and being wrong the cautious direction is harmless.
You do not need to catch every trick. If pausing and checking against this list becomes your habit, the occasional convincing message will still meet a careful reader, and that is what keeps you safe.
Related in this set. Handle links and messages safely · Online Risks, Explained