How to Recognize a Phishing Email: 20 Warning Signs & Safety Tips

How to Recognize a Phishing Email: 20 Warning Signs & Safety Tips

Phishing emails are designed to look trustworthy.

They may appear to come from:

  • Your bank
  • Google or another online service
  • Your employer
  • Your university
  • A delivery company
  • A government organization
  • A colleague or friend
  • A subscription or payment service

The goal may be to make you click a link, download a file, reveal a password, share a verification code, approve an action or provide financial information.

The good news is that many phishing messages contain clues that you can learn to recognize.

Google's Gmail guidance recommends checking the sender, link destination, authentication information and unusual requests. CISA similarly identifies suspicious sender addresses, spoofed hyperlinks, generic greetings, poor formatting and suspicious attachments as common warning signs.

Golden rule: Never let an unexpected email rush you into providing sensitive information. Stop, verify the request independently and then decide what to do.

What Is a Phishing Email?

A phishing email is a deceptive email intended to manipulate the recipient into doing something that benefits an attacker.

That action could include:

  • Clicking a malicious link
  • Opening an attachment
  • Entering a password into a fake website
  • Sharing a one-time verification code
  • Sending money
  • Providing personal information
  • Installing software

The email often pretends to come from a trusted source.


How a Phishing Email Works

Attacker
   ↓
Creates Deceptive Email
   ↓
Impersonates Trusted Source
   ↓
Victim Receives Email
   ↓
Victim Clicks / Replies / Downloads
   ↓
Information or Access Is Targeted

Phishing is therefore partly a technical problem and partly a human-behavior problem.


20 Warning Signs of a Phishing Email

No single warning sign proves that an email is malicious. Instead, look at the overall combination of clues.


1. The Sender Address Looks Strange

One of the first things to inspect is the actual sender address.

A message may display:

Example Bank

But the actual email address might be:

support@example-bank-security.invalid

The display name alone is not enough.

Google recommends checking whether the sender name and email address match. CISA also lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.


2. The Domain Is Almost Correct

Attackers may use domains that visually resemble legitimate domains.

For example, a fake domain might use:

example-support.invalid
example-security.invalid
example-login.invalid

Instead of trusting the appearance, carefully inspect the actual domain.

Pay attention to:

  • Unexpected words
  • Extra characters
  • Different top-level domains
  • Subdomain confusion
  • Spelling variations

3. The Email Creates Urgency

Urgency is one of the most common psychological techniques used in phishing.

Examples include:

Your account will be deleted today.

Immediate action required.

You have 15 minutes to verify your account.

Final warning.

Google advises users to be cautious with urgent-sounding requests because scammers often use emotional pressure to make people act without thinking.

When an email makes you feel rushed, slow down.


4. The Email Requests Sensitive Information

Be suspicious of unexpected messages asking for:

  • Passwords
  • PINs
  • Bank account information
  • Card information
  • Government identification numbers
  • Verification codes
  • Personal information

Google advises users not to respond to requests for private information through email, text or phone without independently confirming the request.


5. The Link Goes Somewhere Unexpected

A message may display text such as:

Verify your account

But the actual destination could be a different website.

On a computer, you can often hover over a link without clicking it and inspect where it leads.

Google specifically recommends checking whether the URL matches the description of the link.

Tip: An HTTPS address does not automatically mean that the website is legitimate. Check the actual domain and context.

6. The Greeting Is Generic

Some phishing emails use greetings such as:

Dear Customer,

Dear User,

Dear Account Holder,

A generic greeting by itself does not prove phishing, but it can become more suspicious when combined with urgent language or a request for sensitive information.

CISA lists generic greetings and signatures among common signs of phishing.


7. There Are Spelling or Formatting Problems

Look for:

  • Unusual grammar
  • Strange sentence structure
  • Random capitalization
  • Inconsistent fonts
  • Broken formatting
  • Odd spacing
  • Incorrect company details

CISA identifies misspellings, poor grammar, sentence-structure problems and inconsistent formatting as common indicators.

However, do not use grammar as your only test. Modern phishing messages can be well written.


8. The Message Contains an Unexpected Attachment

Be cautious when an unexpected email includes:

  • Office documents
  • PDF files
  • Compressed archives
  • Scripts
  • Installers
  • Unknown file types

CISA includes suspicious attachments among phishing warning signs.

Especially be careful when the attachment is accompanied by urgent instructions.


9. The Email Pretends to Be From Someone You Know

Phishing does not always come from an unknown sender.

An attacker may impersonate:

  • Your manager
  • A colleague
  • A friend
  • A family member
  • A customer
  • A supplier

Google warns that scammers may impersonate people you know and recommends contacting that person directly using the normal communication channel to verify unusual requests.


10. The Request Is Unusual for That Person

Imagine your manager usually sends normal work emails, but suddenly asks:

Please purchase gift cards immediately.

Send me the codes when finished.

Even if the sender name appears correct, the request itself is unusual.

Verify it through another trusted channel.


11. The Email Demands Money

Be especially cautious when an unexpected email requests:

  • Wire transfers
  • Gift cards
  • Cryptocurrency payments
  • Urgent invoices
  • Account payments
  • Refund fees

Financial requests should be independently verified using a trusted contact method.


12. The Email Claims Your Account Has a Problem

A common phishing technique is creating fear about account security.

For example:

Suspicious login detected.

Your account is at risk.

Confirm your identity now.

The attacker wants you to react quickly.

Instead, go directly to the service's official website or application and check your account there.

Google recommends checking account activity directly through your account rather than trusting a suspicious message link.


13. The Email Says You Won a Prize

Be skeptical of unexpected prize messages.

For example:

Congratulations!

You have won ₹50,000.

Pay a small processing fee to claim
your prize.

An unexpected reward combined with a request for money or personal information is a major warning sign.

Google specifically advises users to be cautious with messages that appear too good to be true, including prize and get-rich-quick scams.


14. The Email Claims to Be From a Government Organization

Attackers can impersonate:

  • Tax authorities
  • Law-enforcement organizations
  • Government departments
  • Regulatory bodies

A message may attempt to create fear by threatening fines or legal consequences.

Do not rely on the email alone.

Find the organization's official website independently and verify the message.


15. The Message Contains a Fake Login Button

A phishing email may contain:

[ Sign In ]

[ Verify Account ]

[ Restore Access ]

[ Secure Account ]

These buttons may lead to fake login pages.

Never enter your password simply because an email asks you to.

Google specifically recommends going directly to the service website if clicking a message link leads to a password request.


16. The Email Uses Fear or Threats

Examples:

Your account will be permanently deleted.

Legal action will begin today.

Your payment will be blocked.

Your device has been compromised.

Fear can reduce careful decision-making.

When you see strong threats or pressure, stop and independently verify them.


17. The Email Says You Must Act Immediately

Some emails repeatedly use phrases like:

  • Act now
  • Final notice
  • Immediate action required
  • Last chance
  • Expires today

Urgency does not prove that an email is malicious, but it is a reason to slow down and verify.


18. The Email Requests an Unusual Verification Code

Attackers may attempt to trick users into sharing one-time passwords or authentication codes.

For example:

I am helping you secure your account.

Please send me the verification code
you just received.

Do not share authentication codes with unexpected callers or messages.

A verification code is generally intended for the authentication process you initiated—not for someone contacting you unexpectedly.


19. The Email Contains a Strange Reply-To Address

Sometimes the visible sender and reply destination are different.

That can be a warning sign, particularly when the message asks for sensitive information.

Advanced users can inspect message headers for additional information.

Google's Gmail guidance specifically recommends checking message headers when the sender identity is questionable.


20. The Message Does Not Match the Context

This is one of the most useful tests.

Ask:

  • Was I expecting this message?
  • Did I recently request this service?
  • Do I actually have an account with this company?
  • Was I expecting an attachment?
  • Was there really a payment or login problem?
  • Does the sender normally contact me this way?

Context can reveal suspicious messages that look technically convincing.


A Realistic Phishing Email Example

Consider this fictional message:

From: Google Security Team
Subject: Urgent: Your account will be suspended

We detected unusual activity on your account.

You must verify your identity within 15 minutes.

[Verify Account]

Failure to verify will result in permanent suspension.

Let's analyze it.

Clue Why It Matters
Urgency Creates pressure to act quickly
Account threat Uses fear
Login button Could lead to a deceptive page
Identity request May attempt to collect sensitive information

The safe response is not to click the button. Open the official service separately and check account security there.


How to Check the Sender

Start with the sender information.

Look beyond the display name.

Display Name → Can be misleading

Actual Email Address → More useful clue
Domain → Important
Reply-To → Additional clue
Authentication → Additional information

Google recommends checking whether the sender name and email address match and whether the message is authenticated.


How to Check a Link Without Clicking It

On a desktop computer, move your mouse over the link.

Look at the URL shown by the email client.

For example:

Displayed:
Verify Account

Actual destination:
https://unexpected-example.invalid/login

If the destination does not match the organization you expected, do not click it.

Google explicitly recommends checking the URL before clicking.


Do Not Trust the Displayed Link Text

Text can say:

https://trusted-example.com

while the actual hyperlink destination is different.

This is why visually reading the email is not always enough.


How to Verify an Email Independently

This is one of the most important habits you can develop.

Suppose an email says your bank account has a problem.

Do not use the link in the email.

Instead:

Suspicious Email
      ↓
Close / Ignore Link
      ↓
Open Official Bank App
      ↓
Check Account
      ↓
Verify Alert

Google similarly recommends opening the legitimate website independently instead of relying on a suspicious email link.


How to Check Gmail Security Alerts Safely

If you receive an email about suspicious activity on your Google Account, do not assume the email link is genuine.

Google recommends checking security activity directly through your Google Account.

A current Google workflow is:

Google Account
   ↓
Security
   ↓
Recent security events
   ↓
Review activity

Google also recommends reviewing unfamiliar devices or security events and securing the account when something is not recognized.


What Does "Authenticated Email" Mean?

Email authentication mechanisms can provide additional information about whether a message is authorized to use a particular domain.

Common email-authentication technologies include:

  • SPF
  • DKIM
  • DMARC

Gmail can display authentication-related information for messages.

Authentication signals can be useful, but users should still examine the entire message and context rather than treating one indicator as an absolute guarantee of safety. Google recommends checking whether an email is authenticated when reviewing suspicious messages.


Can a Phishing Email Look Perfect?

Yes.

Do not assume that a message is legitimate simply because:

  • The grammar is perfect
  • The logo looks real
  • The formatting is professional
  • Your name appears in the message
  • The sender display name looks familiar

Modern scams can use convincing language and visual design.

Context, domain verification and independent confirmation are stronger habits than relying on appearance alone.


Can a Phishing Email Come From a Real Account?

Yes.

An attacker may use a compromised account belonging to a legitimate person or organization.

This means:

A legitimate-looking sender address does not automatically make every message trustworthy.

Consider the content, links, attachments and request itself.


What Should You Do With a Suspicious Email?

Use this process:

STOP
 ↓
Don't Click
 ↓
Check Sender
 ↓
Check Request
 ↓
Check Link
 ↓
Verify Independently
 ↓
Report

Do not forward suspicious messages to other people within an organization unless your security process specifically instructs you to do so.

CISA recommends reporting suspicious correspondence to the appropriate security team and warns against forwarding malicious email to other employees inside an organization.


How to Report a Phishing Email in Gmail

Gmail provides a built-in reporting mechanism.

The current Gmail process is:

  1. Open Gmail.
  2. Open the suspicious message.
  3. Click More.
  4. Select Report phishing.

Google documents these steps in its Gmail Help guidance.


Should You Delete a Phishing Email?

Follow the appropriate reporting process first.

For a personal mailbox, you can report the message and then remove it according to your normal email practices.

For a workplace mailbox, follow company procedures because security teams may need the message for investigation.


What If You Already Clicked?

Clicking a link does not necessarily mean that your account or device has been compromised.

What matters is what happened next.

If You Opened the Page but Entered Nothing

Close the page and do not continue interacting with it.

If You Entered a Password

Change the password through the legitimate service's official website or app.

Change the same password on other accounts where you reused it.

If You Shared a Verification Code

Secure the affected account immediately and review recent security activity.

Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.

If You Downloaded a File

Do not open it again. Follow your organization's security procedures or use trusted security tools to assess the device.

If Financial Information Was Shared

Contact the relevant bank or financial institution using a trusted contact method.


Phishing Email Checklist

Before responding to an unexpected email, ask:

  • □ Do I know the sender?
  • □ Does the actual email address match?
  • □ Does the domain look correct?
  • □ Was I expecting this message?
  • □ Is the message creating urgency?
  • □ Is it asking for sensitive information?
  • □ Is there a suspicious link?
  • □ Is there an unexpected attachment?
  • □ Is the request unusual?
  • □ Can I verify it independently?

A 10-Second Phishing Test

When you receive an unexpected message, ask these five questions:

1. Who sent it?

2. Why did I receive it?

3. What is it asking me to do?

4. Where does the link actually go?

5. Can I verify the request without using the email?

If several answers do not make sense, stop and investigate.


Phishing Emails Targeting Students

Students may receive messages pretending to be about:

  • Scholarships
  • University accounts
  • Exam results
  • Course registration
  • Internships
  • Job opportunities
  • Certificates
  • Fee payments

Example:

Congratulations!

You have been selected for a scholarship.

Pay ₹999 for verification and send your
bank details to complete the process.

Do not send money or personal information until the opportunity has been verified independently.


Phishing Emails Targeting Developers

Developers may encounter messages pretending to be:

  • Git hosting services
  • Cloud providers
  • Package repositories
  • Project-management tools
  • Code-review systems
  • Security teams

A fake message might ask you to:

  • Reset your password
  • Review a pull request
  • Download a project archive
  • Install a security update
  • Authenticate to a cloud account

Developers should verify domains and software downloads especially carefully.


Phishing Emails Targeting Employees

Employees should be alert to:

  • Urgent payment changes
  • Password-reset requests
  • Cloud-document shares
  • Unexpected invoices
  • IT-support messages
  • Executive impersonation
  • Vendor account changes

A company should have clear procedures for verifying sensitive financial and administrative requests.


How Organizations Can Reduce Phishing Risk

Individual awareness is important, but technical controls also matter.

Organizations can use:

  • Email filtering
  • SPF
  • DKIM
  • DMARC
  • MFA
  • Phishing-resistant authentication
  • Endpoint security
  • Web filtering
  • Security awareness training
  • Incident reporting procedures

CISA recommends layered defenses that include email-authentication controls, user education, reporting and phishing-resistant MFA.


Why Security Awareness Training Matters

Security tools cannot always recognize every social-engineering attempt.

Employees should know how to:

  • Recognize suspicious messages
  • Report suspicious emails
  • Verify unusual requests
  • Avoid sharing credentials
  • Handle suspicious attachments
  • Respond quickly after an accidental interaction

CISA recommends educating employees about common phishing indicators and creating clear reporting procedures.


Common Phishing Myths

Myth 1: "Bad Grammar Means Phishing"

Not always. Professional-looking messages can also be malicious.

Myth 2: "The Logo Looks Real"

Logos and visual layouts can be copied.

Myth 3: "The Email Uses HTTPS"

HTTPS does not prove that a website is legitimate.

Myth 4: "The Sender Is Someone I Know"

The person's account may have been compromised or impersonated.

Myth 5: "I Have MFA, So I Cannot Be Phished"

MFA improves account security, but attackers can still try to manipulate users into approving fraudulent requests or revealing authentication information.

Myth 6: "Antivirus Will Catch Everything"

Security software is useful, but it cannot replace careful verification and secure account practices.


Phishing Recognition Cheat Sheet

Warning Sign What to Do
Unknown sender Verify before responding
Unexpected urgency Stop and slow down
Suspicious link Do not click
Unexpected attachment Do not open
Password request Use official website independently
OTP/code request Do not share it
Unexpected payment request Verify through another channel
Account threat Check account directly

Final Thoughts

Recognizing phishing is less about finding one magical clue and more about developing a habit of slowing down and verifying unexpected requests.

Remember the most important warning signs:

Suspicious Sender + Urgency + Strange Link + Sensitive Request + Unexpected Attachment

When several of these appear together, treat the message with caution.

Google recommends checking the sender, authentication and URLs and avoiding requests for private information from suspicious messages.

CISA likewise recommends awareness of suspicious senders, spoofed hyperlinks, generic greetings, formatting problems and unexpected attachments, combined with reporting and other technical protections.

The safest habit is simple:

Don't trust the email. Verify the request.

When possible, open the official website or application yourself and confirm the information there.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

What Is Phishing? Types, Examples, Warning Signs & Prevention

What Is Phishing? Types, Examples, Warning Signs & Prevention

Have you ever received a message saying:

"Your account will be suspended. Click here immediately to verify it."

Or perhaps:

"Congratulations! You have won a prize. Claim it now."

Or:

"We detected a suspicious transaction. Log in now to secure your account."

These are common examples of phishing.

Phishing is one of the most common forms of social engineering. Instead of depending entirely on a technical vulnerability, attackers often try to manipulate a person into clicking a link, opening an attachment, sharing credentials, approving an action or providing sensitive information.

CISA defines phishing as a form of social engineering where a cyber threat actor poses as a trusted colleague, acquaintance or organization to persuade a victim to provide sensitive information or network access. The lure may arrive through email, text message or phone call.

Google similarly describes phishing as attempts to steal personal information or gain access to online accounts using deceptive emails, messages, advertisements or websites that imitate services people already use.

This article explains phishing in simple language, including how it works, common types, warning signs, prevention techniques, reporting steps and what to do after interacting with a suspicious message.

Important: Never provide passwords, one-time codes, banking information or other sensitive information in response to an unexpected message until you independently verify that the request is genuine.

What Is Phishing?

Phishing is a deceptive technique used to trick people into revealing information, clicking malicious links, downloading harmful files or taking actions that benefit an attacker.

The attacker often pretends to be someone trustworthy.

For example:

  • A bank
  • An employer
  • A university
  • A delivery company
  • A social-media platform
  • A cloud service
  • A colleague
  • A government organization

The objective is to create enough trust, fear, curiosity or urgency that the victim acts before checking the message carefully.


How Does Phishing Work?

A simplified phishing attack can look like this:

Attacker
   ↓
Creates Deceptive Message
   ↓
Impersonates Trusted Entity
   ↓
Victim Receives Message
   ↓
Victim Clicks / Responds / Downloads
   ↓
Attacker Attempts to Obtain Information or Access
   ↓
Possible Account or System Compromise

CISA's recent joint phishing guidance identifies credential theft and malware deployment among the primary objectives of phishing campaigns.


Why Is Phishing So Effective?

Phishing attacks target human decision-making.

Attackers may deliberately create:

  • Urgency
  • Fear
  • Curiosity
  • Authority
  • Financial pressure
  • Excitement
  • Trust

For example:

Fear: "Your account has been compromised."

Urgency: "Verify within 10 minutes."

Authority: "Your administrator requires this action."

Reward: "You have won a prize."

Google advises users to slow down when a communication creates urgency and to independently verify suspicious requests before providing information.


What Information Do Phishing Attacks Try to Steal?

Depending on the campaign, phishing messages may attempt to collect:

  • Usernames
  • Passwords
  • Banking information
  • Payment details
  • PINs
  • Identity information
  • One-time verification codes
  • Recovery information
  • Business credentials
  • Access tokens or session information

Google specifically warns users not to provide private or financial information in response to suspicious emails, texts, webpages or pop-ups.


Common Types of Phishing

Phishing is not one single attack technique.

Some common forms include:

  • Traditional email phishing
  • Spear phishing
  • Whaling
  • Smishing
  • Vishing
  • Business email compromise-related impersonation
  • Clone phishing

CISA's phishing guidance identifies spearphishing, whaling, vishing and smishing among common types.


1. Email Phishing

This is one of the most familiar forms of phishing.

The victim receives an email designed to look legitimate.

Example

From: Security Team
Subject: Urgent Account Verification

We detected unusual activity on your account.

Please verify your account immediately:
[Verify Account]

The message may imitate a real company, but the link may lead somewhere else.


2. Spear Phishing

Spear phishing is targeted phishing aimed at a particular person or organization.

The attacker may use information about the target to make the message appear more believable.

For example, the attacker might know:

  • The victim's name
  • The company they work for
  • Their job role
  • A current project
  • The name of a colleague

CISA describes spearphishing as phishing targeted at an individual using information about that person.


3. Whaling

Whaling is targeted phishing aimed at a high-profile individual, such as an executive or other person with access to sensitive information.

The objective can include:

  • Credentials
  • Financial information
  • Business information
  • Account access

CISA identifies whaling as phishing targeted at a high-profile individual to obtain sensitive or high-value information.


4. Smishing

Smishing is phishing delivered through SMS or text messages.

Example:

Your parcel could not be delivered.

Update delivery information:
https://example.invalid/verify

The message may appear to come from a shipping company even when it does not.

CISA identifies smishing as phishing delivered through text messages.


5. Vishing

Vishing is phishing conducted through voice communication, including phone calls.

For example, a caller may claim to be:

  • Bank support
  • Technical support
  • Government personnel
  • Company IT staff
  • Account-security staff

The caller may attempt to persuade you to reveal a password, verification code or other information.

CISA identifies vishing as phishing through voice communication.

Google's current guidance also warns about phone scams in which attackers impersonate Google account-security personnel and attempt to obtain passwords, codes or fraudulent approval of login prompts.


6. Clone Phishing

In clone phishing, an attacker may create a deceptive message that resembles a legitimate message the victim has previously received.

The attacker may attempt to reproduce:

  • Visual design
  • Subject line
  • Message structure
  • Sender identity
  • Link appearance

The copied message may contain a malicious replacement link or attachment.


7. Business Email Compromise

Business email compromise involves deceptive communications that attempt to manipulate employees or organizations into taking actions such as transferring money or sharing information.

These attacks can involve impersonation, compromised accounts or other forms of deception.

Because financial and business workflows are involved, organizations should verify sensitive requests using trusted communication channels.


Phishing vs Spam

People sometimes use the terms interchangeably, but they are different.

Spam Phishing
Usually unwanted messages Deceptive messages intended to manipulate the recipient
Often advertising or bulk content Often attempts to steal information or gain access
May be annoying Can cause security or financial harm

Some phishing messages can also be considered spam, but not all spam is phishing.


Phishing vs Malware

Phishing is a social-engineering technique.

Malware is malicious software.

They can be connected.

Phishing Message
      ↓
Malicious Attachment / Link
      ↓
Malware Download
      ↓
Potential System Compromise

CISA's 2025 joint guidance specifically identifies malware deployment as one of the major objectives of phishing campaigns.


Phishing vs Social Engineering

Social engineering is the broader concept of manipulating people into revealing information or taking actions that undermine security.

Phishing is one form of social engineering.

Social Engineering
       |
       +---- Phishing
       |
       +---- Impersonation
       |
       +---- Pretexting
       |
       +---- Other Manipulation Techniques

CISA describes phishing as a form of social engineering.


Common Signs of a Phishing Message

There is no single sign that proves a message is phishing, but several warning indicators can raise suspicion.

1. Suspicious Sender Address

The display name may look correct while the actual email address is different.

For example:

Display Name:
Example Bank

Actual Address:
security@example-security.invalid

Always inspect the actual sender information.

CISA specifically lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.


2. Unexpected Urgency

Be careful with messages saying:

  • "Act immediately"
  • "Your account will be closed today"
  • "Final warning"
  • "Respond within 10 minutes"

Google recommends slowing down because scams frequently use urgency to pressure people into acting without verification.


3. Suspicious Links

A message may show text such as:

Verify your account

But the actual URL may point somewhere unexpected.

On a computer, hovering over a link before clicking can reveal the destination. Google specifically recommends checking whether the displayed destination matches the expected service.

Do not assume that a link is safe merely because it contains https://. HTTPS encrypts the connection to a website, but it does not prove that the website itself is legitimate.


4. Generic Greetings

Messages that use generic greetings such as "Dear Customer" can sometimes be suspicious, especially when combined with other warning signs.

CISA includes generic greetings among indicators worth checking.


5. Spelling or Formatting Problems

Incorrect spelling, strange formatting, unusual wording or inconsistent branding can indicate phishing.

However, modern phishing messages can be professionally written, so perfect grammar does not prove legitimacy.


6. Unexpected Attachments

Be cautious when an unexpected message asks you to open a file.

Examples include:

  • Invoices
  • Documents
  • Compressed files
  • Scripts
  • Unknown installers

CISA lists suspicious attachments among common phishing indicators.


7. Requests for Private Information

Be particularly careful when an unexpected message asks for:

  • Password
  • OTP
  • PIN
  • Bank information
  • Identity information
  • Credit-card details

Google advises against responding to requests for private information through email, text or phone unless the request has been independently verified.


Phishing Example: Fake Bank Message

Imagine receiving:

URGENT: Suspicious transaction detected.

Your banking access has been restricted.

Verify your identity now:
[Secure Account]

Failure to respond within 15 minutes
may result in permanent suspension.

Warning signs include:

  • Urgency
  • Fear
  • Unexpected account action
  • Request for information
  • Unknown link destination

A safer response is to open the bank's official application or type its known website address yourself instead of using the message link.


Phishing Example: Fake Job Message

Congratulations!

You have been selected for a remote IT job.

Please pay a small registration fee and
send your ID and bank details to complete
your onboarding.

This contains several warning signs:

  • Unexpected job offer
  • Pressure to act
  • Request for money
  • Request for sensitive information
  • Potentially unverifiable employer

Always independently verify the company and application process.


Phishing Example: Fake Delivery Message

Delivery failed.

Please pay a small fee to reschedule
your delivery.

[Pay Delivery Fee]

Before clicking anything, ask:

  • Am I actually expecting a delivery?
  • Did I order anything from this company?
  • Does the message match my order information?
  • Can I verify the delivery using the official app?

How to Check a Suspicious Link Safely

Do not click first and investigate later.

Instead:

  1. Check the sender.
  2. Read the message carefully.
  3. Inspect the link destination.
  4. Look for spelling or domain inconsistencies.
  5. Open the organization's official website independently.
  6. Verify the request through a trusted channel.

Google recommends opening the legitimate site separately rather than using a suspicious email link when possible.


What Is Link Spoofing?

A phishing message can display one URL-like text while sending the victim somewhere else.

For example:

Displayed:
https://trusted-example.com

Actual destination:
https://different-example.invalid/login

This is why checking the actual destination is important.


How Attackers Use Fake Login Pages

A phishing campaign may create a fake login page that visually resembles a legitimate service.

For example:

Fake Login Page
      ↓
Username
Password
Verification Code
      ↓
Attacker Receives Credentials

Google's guidance warns that phishing sites can imitate services users already know and trust.

This is why users should verify the domain and preferably navigate directly to the official service.


Can MFA Stop Phishing?

MFA can significantly improve account security, but not every MFA method provides the same protection against phishing.

CISA's phishing guidance recommends phishing-resistant multifactor authentication as an important protection for organizations.

Phishing can sometimes attempt to trick users into:

  • Sharing a one-time code
  • Approving a fraudulent login prompt
  • Entering credentials into a fake site

For stronger protection, organizations can use phishing-resistant authentication technologies where appropriate.


What Is Phishing-Resistant MFA?

Phishing-resistant MFA is authentication designed to make it significantly harder for an attacker to use a fake website or deceptive interaction to capture reusable authentication information.

Modern methods can include cryptographic authentication technologies such as security keys and passkeys, depending on the service.

The important lesson is:

MFA is important, but the specific authentication method matters.

How Organizations Can Prevent Phishing

Phishing prevention should not rely only on individual users.

Organizations can combine technical and human controls.

Email Authentication

CISA recommends technologies such as:

  • SPF
  • DKIM
  • DMARC

These technologies can help organizations establish and enforce email-authentication policies and reduce certain types of email impersonation.

User Education

Train employees to recognize:

  • Suspicious sender addresses
  • Fake links
  • Unexpected attachments
  • Urgency
  • Requests for sensitive information

CISA recommends employee education and encourages reporting suspicious correspondence to the appropriate security team.

Technical Controls

Organizations may also use:

  • Email filtering
  • Domain reputation systems
  • Malware scanning
  • Web filtering
  • MFA
  • Endpoint protection
  • Security monitoring

What Should You Do When You Receive a Suspicious Message?

Use this simple process:

STOP
 ↓
Do Not Click
 ↓
Do Not Reply
 ↓
Verify Independently
 ↓
Report
 ↓
Delete / Follow Organization Procedure

CISA's guidance recommends reporting suspicious messages to the appropriate security team and not forwarding malicious email to other employees within an organization.


What If You Already Clicked the Link?

Do not panic.

Take action quickly.

If You Only Opened the Page

Close the page and avoid entering information.

Review what happened and consider reporting the message.

If You Entered Your Password

Change the password through the legitimate service's official website or app.

If the password was reused elsewhere, change it on those accounts too.

If You Shared a Verification Code

Immediately secure the account through its official security controls and review recent activity.

Google recommends reviewing account security activity and securing the account when unfamiliar activity is detected.

If You Downloaded a File

Do not open it again. Follow your organization's security procedure or use trusted security software to assess the device.

If Financial Information Was Shared

Contact the relevant financial institution using a trusted, independently verified contact method.


How to Report Phishing

Reporting helps organizations investigate attacks and can help prevent additional victims.

For Gmail, Google provides a Report Phishing option within Gmail.

Within organizations, follow the company's security or IT reporting process.

For suspicious websites, Google also provides a mechanism for reporting phishing pages.


Phishing and Social Media

Phishing does not only happen through email.

Attackers can use:

  • Direct messages
  • Social-media posts
  • Fake support accounts
  • Chat applications
  • SMS
  • Voice calls

CISA advises people to remain alert across communication platforms, including social media.


Phishing on Messaging Apps

A scammer may send:

Your account violated our policy.

Appeal here:
[Link]

The same principles apply:

  • Do not rush.
  • Do not trust the message automatically.
  • Verify through the official application or website.
  • Do not reveal credentials.

Phishing and QR Codes

QR codes can also be used as part of phishing attempts.

A QR code can hide the destination URL behind an image, making it harder to visually inspect before scanning.

If you receive an unexpected QR code:

  • Ask why it was sent.
  • Verify the sender.
  • Preview the destination where your device allows it.
  • Navigate directly to the official service instead.

Phishing and AI

Modern generative AI can make it easier to produce convincing text, translations and impersonation material.

This means traditional clues such as spelling mistakes may be less reliable than they once were.

A stronger defense is to focus on:

  • Unexpected requests
  • Unusual payment instructions
  • Unverified login requests
  • Domain mismatches
  • Urgency
  • Requests for confidential information
  • Independent verification

In other words:

Do not judge a message only by how professional it looks.

How to Verify a Request

Suppose your manager sends a message asking you to transfer money.

Instead of immediately responding:

Message
  ↓
Verify sender through another trusted channel
  ↓
Confirm request
  ↓
Proceed only if legitimate

For sensitive actions, independent verification is one of the most useful defenses against impersonation.


Phishing Prevention Checklist

  • □ Slow down when a message creates urgency.
  • □ Check the actual sender address.
  • □ Inspect links before opening them.
  • □ Avoid unexpected attachments.
  • □ Never share passwords through messages.
  • □ Never share one-time verification codes with unexpected callers or messages.
  • □ Verify financial requests independently.
  • □ Use MFA.
  • □ Prefer phishing-resistant authentication where available.
  • □ Keep devices and applications updated.
  • □ Report suspicious messages.

Phishing Prevention for Students

Students can be targeted with messages about:

  • Scholarships
  • Exam results
  • University accounts
  • Internships
  • Jobs
  • Certificates
  • Fees
  • Course registrations

Before clicking, ask:

Was I expecting this?

Who actually sent it?

Does the domain look correct?

Can I verify this through the official university or organization's website?

Phishing Prevention for Employees

Employees should be particularly careful with:

  • Payment requests
  • Password-reset requests
  • Cloud-storage invitations
  • Unexpected file shares
  • CEO or manager impersonation
  • Urgent IT requests
  • Vendor payment changes

Sensitive requests should follow established company procedures.


Phishing Prevention for Businesses

A business should use multiple layers of protection.

Email Authentication
       +
Email Filtering
       +
MFA
       +
Endpoint Security
       +
User Training
       +
Reporting
       +
Incident Response
       ↓
Reduced Phishing Risk

CISA's guidance similarly recommends combining technical protections, employee awareness and reporting procedures rather than relying on one control alone.


How Security Teams Respond to a Phishing Attack

A security team may follow a workflow such as:

User Reports Message
       ↓
Security Team Investigates
       ↓
Identify Indicators
       ↓
Search for Other Recipients
       ↓
Block Malicious Domains / Messages
       ↓
Investigate Any Compromise
       ↓
Contain and Remediate
       ↓
Review Lessons Learned

CISA notes that employee reporting can help incident responders determine whether an attack is isolated or widespread and identify indicators that can be used in security protections.


What Are SPF, DKIM and DMARC?

These are email-authentication technologies used to help organizations establish whether messages claiming to come from their domains are legitimate.

SPF

Sender Policy Framework allows domain owners to publish which mail servers are authorized to send mail for a domain.

DKIM

DomainKeys Identified Mail uses cryptographic signatures to help verify that a message is associated with the domain and has not been altered in transit in ways covered by the signature.

DMARC

Domain-based Message Authentication, Reporting, and Conformance builds on SPF and DKIM and lets domain owners publish policies and receive reports related to email authentication.

CISA specifically recommends SPF, DKIM and DMARC as part of organizational defenses against phishing and email impersonation.


Does HTTPS Prevent Phishing?

No.

HTTPS helps protect the connection between your browser and the website.

It does not automatically prove that the website is trustworthy.

For example:

https://legitimate-example.com
        ≠
https://malicious-example.com

Both may technically use HTTPS.

Therefore:

Look at the domain and context, not just the padlock or HTTPS.

Can Antivirus Stop Phishing?

Security software can help detect malicious files, websites or other harmful activity, but it should not be treated as a complete phishing defense.

Human verification and secure authentication remain important.

A multilayer approach is stronger than relying on one product.


Can a Phishing Email Look Completely Real?

Yes.

Attackers can imitate:

  • Logos
  • Writing style
  • Email layouts
  • Company names
  • Support messages
  • Login pages

Therefore, do not assume:

"It looks professional, so it must be legitimate."

Google warns that phishing messages can look exactly like communications from people or organizations you trust.


Phishing Awareness: A Simple Rule

Use the following rule:

STOP → CHECK → VERIFY → ACT

STOP: Do not react immediately.

CHECK: Look at the sender, link, request and context.

VERIFY: Contact the organization through an official channel.

ACT: Only continue once you know the request is legitimate.


Phishing Incident Response Checklist

If you suspect that you interacted with a phishing message:

  • Stop interacting with the message.
  • Change compromised passwords through the legitimate service.
  • Review recent account activity.
  • Revoke suspicious sessions where the service supports it.
  • Enable or strengthen MFA.
  • Contact the relevant organization or financial institution if necessary.
  • Report the phishing message.
  • Follow your company's incident-response procedure if it occurred at work.

Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.


Common Phishing Myths

Myth 1: Phishing Only Happens Through Email

False. Phishing can occur through text messages, phone calls, social media and other communication channels.

Myth 2: Bad Grammar Always Means Phishing

Not necessarily. Some phishing messages contain obvious mistakes, but sophisticated messages may be professionally written.

Myth 3: HTTPS Means a Website Is Safe

No. HTTPS protects the connection but does not prove the website is legitimate.

Myth 4: MFA Makes Phishing Impossible

No. MFA improves security, but attackers can try to trick users into sharing codes or approving fraudulent authentication requests. Phishing-resistant authentication provides stronger protection against some phishing scenarios.

Myth 5: Phishing Only Targets Large Companies

Phishing can target individuals, students, small businesses and large organizations alike.

Myth 6: Only Non-Technical People Fall for Phishing

Anyone can make a mistake, especially when a message is designed to create urgency or mimic a trusted source.


Frequently Asked Questions

1. What is phishing in simple words?

Phishing is a deception technique in which an attacker pretends to be trustworthy in order to trick someone into sharing information, clicking a malicious link, downloading harmful content or taking another action.

2. Is phishing a type of social engineering?

Yes. CISA describes phishing as a form of social engineering.

3. What is spear phishing?

Spear phishing is targeted phishing directed at a specific person or organization using information that makes the message more convincing.

4. What is smishing?

Smishing is phishing delivered through text messages or SMS.

5. What is vishing?

Vishing is phishing performed through voice communications such as phone calls.

6. What is whaling?

Whaling is targeted phishing aimed at a high-profile individual or other high-value target.

7. Can phishing steal passwords?

Yes. Credential theft is one of the major objectives of phishing campaigns.

8. Can phishing install malware?

Yes. Attackers may use malicious links or attachments to deliver malware. CISA identifies malware deployment as another major phishing objective.

9. Can I get phished through a text message?

Yes. This form is commonly called smishing.

10. Can a phone call be phishing?

Yes. Voice-based phishing is commonly called vishing.

11. Does HTTPS prevent phishing?

No. HTTPS protects communication between the browser and website but does not guarantee that the site itself is legitimate.

12. Is MFA useful against phishing?

Yes. MFA can reduce the impact of stolen passwords, and phishing-resistant MFA provides stronger protection against phishing attacks.

13. What should I do if I clicked a phishing link?

Stop interacting with the page, avoid entering further information, secure any potentially affected accounts, review recent activity and report the incident. If credentials were submitted, change the affected password through the legitimate service.

14. What should I do if I gave a scammer my password?

Change the password immediately through the legitimate service, change it anywhere else you reused it, review account activity and strengthen authentication.

15. Should I reply to a phishing email?

Generally no. Do not engage with suspicious senders. Use the appropriate reporting mechanism instead.

16. How can I verify a suspicious bank message?

Do not use the message link or reply to the message. Open the bank's official app or type its known website address yourself, or contact the institution through a trusted contact method.


Final Thoughts

Phishing works by exploiting trust, urgency and human behavior.

The attacker does not always need to defeat an advanced technical security system directly. Sometimes the easiest path is convincing a person to hand over the information or access instead.

Remember this simple process:

Suspicious Message
↓
STOP
↓
CHECK
↓
VERIFY INDEPENDENTLY
↓
REPORT IF NECESSARY

CISA recommends combining user awareness, reporting procedures, email-authentication controls and phishing-resistant authentication to reduce the effects of phishing.

Google similarly recommends not responding to unexpected requests for sensitive information and opening trusted services independently instead of relying on suspicious message links.

The most important habit is simple:

Never let a surprising message rush you into a security decision.

Slow down, verify independently and protect your credentials.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.