How to Recognize a Phishing Email: 20 Warning Signs & Safety Tips
Phishing emails are designed to look trustworthy.
They may appear to come from:
- Your bank
- Google or another online service
- Your employer
- Your university
- A delivery company
- A government organization
- A colleague or friend
- A subscription or payment service
The goal may be to make you click a link, download a file, reveal a password, share a verification code, approve an action or provide financial information.
The good news is that many phishing messages contain clues that you can learn to recognize.
Google's Gmail guidance recommends checking the sender, link destination, authentication information and unusual requests. CISA similarly identifies suspicious sender addresses, spoofed hyperlinks, generic greetings, poor formatting and suspicious attachments as common warning signs.
What Is a Phishing Email?
A phishing email is a deceptive email intended to manipulate the recipient into doing something that benefits an attacker.
That action could include:
- Clicking a malicious link
- Opening an attachment
- Entering a password into a fake website
- Sharing a one-time verification code
- Sending money
- Providing personal information
- Installing software
The email often pretends to come from a trusted source.
How a Phishing Email Works
Attacker ↓ Creates Deceptive Email ↓ Impersonates Trusted Source ↓ Victim Receives Email ↓ Victim Clicks / Replies / Downloads ↓ Information or Access Is Targeted
Phishing is therefore partly a technical problem and partly a human-behavior problem.
20 Warning Signs of a Phishing Email
No single warning sign proves that an email is malicious. Instead, look at the overall combination of clues.
1. The Sender Address Looks Strange
One of the first things to inspect is the actual sender address.
A message may display:
Example Bank
But the actual email address might be:
support@example-bank-security.invalid
The display name alone is not enough.
Google recommends checking whether the sender name and email address match. CISA also lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.
2. The Domain Is Almost Correct
Attackers may use domains that visually resemble legitimate domains.
For example, a fake domain might use:
example-support.invalid example-security.invalid example-login.invalid
Instead of trusting the appearance, carefully inspect the actual domain.
Pay attention to:
- Unexpected words
- Extra characters
- Different top-level domains
- Subdomain confusion
- Spelling variations
3. The Email Creates Urgency
Urgency is one of the most common psychological techniques used in phishing.
Examples include:
Your account will be deleted today. Immediate action required. You have 15 minutes to verify your account. Final warning.
Google advises users to be cautious with urgent-sounding requests because scammers often use emotional pressure to make people act without thinking.
When an email makes you feel rushed, slow down.
4. The Email Requests Sensitive Information
Be suspicious of unexpected messages asking for:
- Passwords
- PINs
- Bank account information
- Card information
- Government identification numbers
- Verification codes
- Personal information
Google advises users not to respond to requests for private information through email, text or phone without independently confirming the request.
5. The Link Goes Somewhere Unexpected
A message may display text such as:
Verify your account
But the actual destination could be a different website.
On a computer, you can often hover over a link without clicking it and inspect where it leads.
Google specifically recommends checking whether the URL matches the description of the link.
6. The Greeting Is Generic
Some phishing emails use greetings such as:
Dear Customer, Dear User, Dear Account Holder,
A generic greeting by itself does not prove phishing, but it can become more suspicious when combined with urgent language or a request for sensitive information.
CISA lists generic greetings and signatures among common signs of phishing.
7. There Are Spelling or Formatting Problems
Look for:
- Unusual grammar
- Strange sentence structure
- Random capitalization
- Inconsistent fonts
- Broken formatting
- Odd spacing
- Incorrect company details
CISA identifies misspellings, poor grammar, sentence-structure problems and inconsistent formatting as common indicators.
However, do not use grammar as your only test. Modern phishing messages can be well written.
8. The Message Contains an Unexpected Attachment
Be cautious when an unexpected email includes:
- Office documents
- PDF files
- Compressed archives
- Scripts
- Installers
- Unknown file types
CISA includes suspicious attachments among phishing warning signs.
Especially be careful when the attachment is accompanied by urgent instructions.
9. The Email Pretends to Be From Someone You Know
Phishing does not always come from an unknown sender.
An attacker may impersonate:
- Your manager
- A colleague
- A friend
- A family member
- A customer
- A supplier
Google warns that scammers may impersonate people you know and recommends contacting that person directly using the normal communication channel to verify unusual requests.
10. The Request Is Unusual for That Person
Imagine your manager usually sends normal work emails, but suddenly asks:
Please purchase gift cards immediately. Send me the codes when finished.
Even if the sender name appears correct, the request itself is unusual.
Verify it through another trusted channel.
11. The Email Demands Money
Be especially cautious when an unexpected email requests:
- Wire transfers
- Gift cards
- Cryptocurrency payments
- Urgent invoices
- Account payments
- Refund fees
Financial requests should be independently verified using a trusted contact method.
12. The Email Claims Your Account Has a Problem
A common phishing technique is creating fear about account security.
For example:
Suspicious login detected. Your account is at risk. Confirm your identity now.
The attacker wants you to react quickly.
Instead, go directly to the service's official website or application and check your account there.
Google recommends checking account activity directly through your account rather than trusting a suspicious message link.
13. The Email Says You Won a Prize
Be skeptical of unexpected prize messages.
For example:
Congratulations! You have won ₹50,000. Pay a small processing fee to claim your prize.
An unexpected reward combined with a request for money or personal information is a major warning sign.
Google specifically advises users to be cautious with messages that appear too good to be true, including prize and get-rich-quick scams.
14. The Email Claims to Be From a Government Organization
Attackers can impersonate:
- Tax authorities
- Law-enforcement organizations
- Government departments
- Regulatory bodies
A message may attempt to create fear by threatening fines or legal consequences.
Do not rely on the email alone.
Find the organization's official website independently and verify the message.
15. The Message Contains a Fake Login Button
A phishing email may contain:
[ Sign In ] [ Verify Account ] [ Restore Access ] [ Secure Account ]
These buttons may lead to fake login pages.
Never enter your password simply because an email asks you to.
Google specifically recommends going directly to the service website if clicking a message link leads to a password request.
16. The Email Uses Fear or Threats
Examples:
Your account will be permanently deleted. Legal action will begin today. Your payment will be blocked. Your device has been compromised.
Fear can reduce careful decision-making.
When you see strong threats or pressure, stop and independently verify them.
17. The Email Says You Must Act Immediately
Some emails repeatedly use phrases like:
- Act now
- Final notice
- Immediate action required
- Last chance
- Expires today
Urgency does not prove that an email is malicious, but it is a reason to slow down and verify.
18. The Email Requests an Unusual Verification Code
Attackers may attempt to trick users into sharing one-time passwords or authentication codes.
For example:
I am helping you secure your account. Please send me the verification code you just received.
Do not share authentication codes with unexpected callers or messages.
A verification code is generally intended for the authentication process you initiated—not for someone contacting you unexpectedly.
19. The Email Contains a Strange Reply-To Address
Sometimes the visible sender and reply destination are different.
That can be a warning sign, particularly when the message asks for sensitive information.
Advanced users can inspect message headers for additional information.
Google's Gmail guidance specifically recommends checking message headers when the sender identity is questionable.
20. The Message Does Not Match the Context
This is one of the most useful tests.
Ask:
- Was I expecting this message?
- Did I recently request this service?
- Do I actually have an account with this company?
- Was I expecting an attachment?
- Was there really a payment or login problem?
- Does the sender normally contact me this way?
Context can reveal suspicious messages that look technically convincing.
A Realistic Phishing Email Example
Consider this fictional message:
From: Google Security Team Subject: Urgent: Your account will be suspended We detected unusual activity on your account. You must verify your identity within 15 minutes. [Verify Account] Failure to verify will result in permanent suspension.
Let's analyze it.
| Clue | Why It Matters |
|---|---|
| Urgency | Creates pressure to act quickly |
| Account threat | Uses fear |
| Login button | Could lead to a deceptive page |
| Identity request | May attempt to collect sensitive information |
The safe response is not to click the button. Open the official service separately and check account security there.
How to Check the Sender
Start with the sender information.
Look beyond the display name.
Display Name → Can be misleading Actual Email Address → More useful clue Domain → Important Reply-To → Additional clue Authentication → Additional information
Google recommends checking whether the sender name and email address match and whether the message is authenticated.
How to Check a Link Without Clicking It
On a desktop computer, move your mouse over the link.
Look at the URL shown by the email client.
For example:
Displayed: Verify Account Actual destination: https://unexpected-example.invalid/login
If the destination does not match the organization you expected, do not click it.
Google explicitly recommends checking the URL before clicking.
Do Not Trust the Displayed Link Text
Text can say:
https://trusted-example.com
while the actual hyperlink destination is different.
This is why visually reading the email is not always enough.
How to Verify an Email Independently
This is one of the most important habits you can develop.
Suppose an email says your bank account has a problem.
Do not use the link in the email.
Instead:
Suspicious Email
↓
Close / Ignore Link
↓
Open Official Bank App
↓
Check Account
↓
Verify Alert
Google similarly recommends opening the legitimate website independently instead of relying on a suspicious email link.
How to Check Gmail Security Alerts Safely
If you receive an email about suspicious activity on your Google Account, do not assume the email link is genuine.
Google recommends checking security activity directly through your Google Account.
A current Google workflow is:
Google Account ↓ Security ↓ Recent security events ↓ Review activity
Google also recommends reviewing unfamiliar devices or security events and securing the account when something is not recognized.
What Does "Authenticated Email" Mean?
Email authentication mechanisms can provide additional information about whether a message is authorized to use a particular domain.
Common email-authentication technologies include:
- SPF
- DKIM
- DMARC
Gmail can display authentication-related information for messages.
Authentication signals can be useful, but users should still examine the entire message and context rather than treating one indicator as an absolute guarantee of safety. Google recommends checking whether an email is authenticated when reviewing suspicious messages.
Can a Phishing Email Look Perfect?
Yes.
Do not assume that a message is legitimate simply because:
- The grammar is perfect
- The logo looks real
- The formatting is professional
- Your name appears in the message
- The sender display name looks familiar
Modern scams can use convincing language and visual design.
Context, domain verification and independent confirmation are stronger habits than relying on appearance alone.
Can a Phishing Email Come From a Real Account?
Yes.
An attacker may use a compromised account belonging to a legitimate person or organization.
This means:
Consider the content, links, attachments and request itself.
What Should You Do With a Suspicious Email?
Use this process:
STOP ↓ Don't Click ↓ Check Sender ↓ Check Request ↓ Check Link ↓ Verify Independently ↓ Report
Do not forward suspicious messages to other people within an organization unless your security process specifically instructs you to do so.
CISA recommends reporting suspicious correspondence to the appropriate security team and warns against forwarding malicious email to other employees inside an organization.
How to Report a Phishing Email in Gmail
Gmail provides a built-in reporting mechanism.
The current Gmail process is:
- Open Gmail.
- Open the suspicious message.
- Click More.
- Select Report phishing.
Google documents these steps in its Gmail Help guidance.
Should You Delete a Phishing Email?
Follow the appropriate reporting process first.
For a personal mailbox, you can report the message and then remove it according to your normal email practices.
For a workplace mailbox, follow company procedures because security teams may need the message for investigation.
What If You Already Clicked?
Clicking a link does not necessarily mean that your account or device has been compromised.
What matters is what happened next.
If You Opened the Page but Entered Nothing
Close the page and do not continue interacting with it.
If You Entered a Password
Change the password through the legitimate service's official website or app.
Change the same password on other accounts where you reused it.
If You Shared a Verification Code
Secure the affected account immediately and review recent security activity.
Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.
If You Downloaded a File
Do not open it again. Follow your organization's security procedures or use trusted security tools to assess the device.
If Financial Information Was Shared
Contact the relevant bank or financial institution using a trusted contact method.
Phishing Email Checklist
Before responding to an unexpected email, ask:
- □ Do I know the sender?
- □ Does the actual email address match?
- □ Does the domain look correct?
- □ Was I expecting this message?
- □ Is the message creating urgency?
- □ Is it asking for sensitive information?
- □ Is there a suspicious link?
- □ Is there an unexpected attachment?
- □ Is the request unusual?
- □ Can I verify it independently?
A 10-Second Phishing Test
When you receive an unexpected message, ask these five questions:
2. Why did I receive it?
3. What is it asking me to do?
4. Where does the link actually go?
5. Can I verify the request without using the email?
If several answers do not make sense, stop and investigate.
Phishing Emails Targeting Students
Students may receive messages pretending to be about:
- Scholarships
- University accounts
- Exam results
- Course registration
- Internships
- Job opportunities
- Certificates
- Fee payments
Example:
Congratulations! You have been selected for a scholarship. Pay ₹999 for verification and send your bank details to complete the process.
Do not send money or personal information until the opportunity has been verified independently.
Phishing Emails Targeting Developers
Developers may encounter messages pretending to be:
- Git hosting services
- Cloud providers
- Package repositories
- Project-management tools
- Code-review systems
- Security teams
A fake message might ask you to:
- Reset your password
- Review a pull request
- Download a project archive
- Install a security update
- Authenticate to a cloud account
Developers should verify domains and software downloads especially carefully.
Phishing Emails Targeting Employees
Employees should be alert to:
- Urgent payment changes
- Password-reset requests
- Cloud-document shares
- Unexpected invoices
- IT-support messages
- Executive impersonation
- Vendor account changes
A company should have clear procedures for verifying sensitive financial and administrative requests.
How Organizations Can Reduce Phishing Risk
Individual awareness is important, but technical controls also matter.
Organizations can use:
- Email filtering
- SPF
- DKIM
- DMARC
- MFA
- Phishing-resistant authentication
- Endpoint security
- Web filtering
- Security awareness training
- Incident reporting procedures
CISA recommends layered defenses that include email-authentication controls, user education, reporting and phishing-resistant MFA.
Why Security Awareness Training Matters
Security tools cannot always recognize every social-engineering attempt.
Employees should know how to:
- Recognize suspicious messages
- Report suspicious emails
- Verify unusual requests
- Avoid sharing credentials
- Handle suspicious attachments
- Respond quickly after an accidental interaction
CISA recommends educating employees about common phishing indicators and creating clear reporting procedures.
Common Phishing Myths
Myth 1: "Bad Grammar Means Phishing"
Not always. Professional-looking messages can also be malicious.
Myth 2: "The Logo Looks Real"
Logos and visual layouts can be copied.
Myth 3: "The Email Uses HTTPS"
HTTPS does not prove that a website is legitimate.
Myth 4: "The Sender Is Someone I Know"
The person's account may have been compromised or impersonated.
Myth 5: "I Have MFA, So I Cannot Be Phished"
MFA improves account security, but attackers can still try to manipulate users into approving fraudulent requests or revealing authentication information.
Myth 6: "Antivirus Will Catch Everything"
Security software is useful, but it cannot replace careful verification and secure account practices.
Phishing Recognition Cheat Sheet
| Warning Sign | What to Do |
|---|---|
| Unknown sender | Verify before responding |
| Unexpected urgency | Stop and slow down |
| Suspicious link | Do not click |
| Unexpected attachment | Do not open |
| Password request | Use official website independently |
| OTP/code request | Do not share it |
| Unexpected payment request | Verify through another channel |
| Account threat | Check account directly |
Final Thoughts
Recognizing phishing is less about finding one magical clue and more about developing a habit of slowing down and verifying unexpected requests.
Remember the most important warning signs:
When several of these appear together, treat the message with caution.
Google recommends checking the sender, authentication and URLs and avoiding requests for private information from suspicious messages.
CISA likewise recommends awareness of suspicious senders, spoofed hyperlinks, generic greetings, formatting problems and unexpected attachments, combined with reporting and other technical protections.
The safest habit is simple:
When possible, open the official website or application yourself and confirm the information there.
Recommended Reading on CodeWithAV
- What Is Phishing?
- Cybersecurity Roadmap for Beginners
- How to Secure Your Gmail Account
- How to Secure Your Social Media Accounts
- Password Security: How to Create Strong Passwords
- What Is Two-Factor Authentication?
Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.
Official Resources
- Google Gmail Help — Avoid & Report Phishing Emails
- Google Search Help — Prevent & Report Phishing Attacks
- Google Account Help — Suspicious Sign-In Activity
- CISA — Phishing Guidance and Indicators
- CISA — Phishing Security Guidance
Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.