How to Recognize a Phishing Email: 20 Warning Signs & Safety Tips

How to Recognize a Phishing Email: 20 Warning Signs & Safety Tips

Phishing emails are designed to look trustworthy.

They may appear to come from:

  • Your bank
  • Google or another online service
  • Your employer
  • Your university
  • A delivery company
  • A government organization
  • A colleague or friend
  • A subscription or payment service

The goal may be to make you click a link, download a file, reveal a password, share a verification code, approve an action or provide financial information.

The good news is that many phishing messages contain clues that you can learn to recognize.

Google's Gmail guidance recommends checking the sender, link destination, authentication information and unusual requests. CISA similarly identifies suspicious sender addresses, spoofed hyperlinks, generic greetings, poor formatting and suspicious attachments as common warning signs.

Golden rule: Never let an unexpected email rush you into providing sensitive information. Stop, verify the request independently and then decide what to do.

What Is a Phishing Email?

A phishing email is a deceptive email intended to manipulate the recipient into doing something that benefits an attacker.

That action could include:

  • Clicking a malicious link
  • Opening an attachment
  • Entering a password into a fake website
  • Sharing a one-time verification code
  • Sending money
  • Providing personal information
  • Installing software

The email often pretends to come from a trusted source.


How a Phishing Email Works

Attacker
   ↓
Creates Deceptive Email
   ↓
Impersonates Trusted Source
   ↓
Victim Receives Email
   ↓
Victim Clicks / Replies / Downloads
   ↓
Information or Access Is Targeted

Phishing is therefore partly a technical problem and partly a human-behavior problem.


20 Warning Signs of a Phishing Email

No single warning sign proves that an email is malicious. Instead, look at the overall combination of clues.


1. The Sender Address Looks Strange

One of the first things to inspect is the actual sender address.

A message may display:

Example Bank

But the actual email address might be:

support@example-bank-security.invalid

The display name alone is not enough.

Google recommends checking whether the sender name and email address match. CISA also lists suspicious sender addresses that imitate legitimate organizations as a phishing indicator.


2. The Domain Is Almost Correct

Attackers may use domains that visually resemble legitimate domains.

For example, a fake domain might use:

example-support.invalid
example-security.invalid
example-login.invalid

Instead of trusting the appearance, carefully inspect the actual domain.

Pay attention to:

  • Unexpected words
  • Extra characters
  • Different top-level domains
  • Subdomain confusion
  • Spelling variations

3. The Email Creates Urgency

Urgency is one of the most common psychological techniques used in phishing.

Examples include:

Your account will be deleted today.

Immediate action required.

You have 15 minutes to verify your account.

Final warning.

Google advises users to be cautious with urgent-sounding requests because scammers often use emotional pressure to make people act without thinking.

When an email makes you feel rushed, slow down.


4. The Email Requests Sensitive Information

Be suspicious of unexpected messages asking for:

  • Passwords
  • PINs
  • Bank account information
  • Card information
  • Government identification numbers
  • Verification codes
  • Personal information

Google advises users not to respond to requests for private information through email, text or phone without independently confirming the request.


5. The Link Goes Somewhere Unexpected

A message may display text such as:

Verify your account

But the actual destination could be a different website.

On a computer, you can often hover over a link without clicking it and inspect where it leads.

Google specifically recommends checking whether the URL matches the description of the link.

Tip: An HTTPS address does not automatically mean that the website is legitimate. Check the actual domain and context.

6. The Greeting Is Generic

Some phishing emails use greetings such as:

Dear Customer,

Dear User,

Dear Account Holder,

A generic greeting by itself does not prove phishing, but it can become more suspicious when combined with urgent language or a request for sensitive information.

CISA lists generic greetings and signatures among common signs of phishing.


7. There Are Spelling or Formatting Problems

Look for:

  • Unusual grammar
  • Strange sentence structure
  • Random capitalization
  • Inconsistent fonts
  • Broken formatting
  • Odd spacing
  • Incorrect company details

CISA identifies misspellings, poor grammar, sentence-structure problems and inconsistent formatting as common indicators.

However, do not use grammar as your only test. Modern phishing messages can be well written.


8. The Message Contains an Unexpected Attachment

Be cautious when an unexpected email includes:

  • Office documents
  • PDF files
  • Compressed archives
  • Scripts
  • Installers
  • Unknown file types

CISA includes suspicious attachments among phishing warning signs.

Especially be careful when the attachment is accompanied by urgent instructions.


9. The Email Pretends to Be From Someone You Know

Phishing does not always come from an unknown sender.

An attacker may impersonate:

  • Your manager
  • A colleague
  • A friend
  • A family member
  • A customer
  • A supplier

Google warns that scammers may impersonate people you know and recommends contacting that person directly using the normal communication channel to verify unusual requests.


10. The Request Is Unusual for That Person

Imagine your manager usually sends normal work emails, but suddenly asks:

Please purchase gift cards immediately.

Send me the codes when finished.

Even if the sender name appears correct, the request itself is unusual.

Verify it through another trusted channel.


11. The Email Demands Money

Be especially cautious when an unexpected email requests:

  • Wire transfers
  • Gift cards
  • Cryptocurrency payments
  • Urgent invoices
  • Account payments
  • Refund fees

Financial requests should be independently verified using a trusted contact method.


12. The Email Claims Your Account Has a Problem

A common phishing technique is creating fear about account security.

For example:

Suspicious login detected.

Your account is at risk.

Confirm your identity now.

The attacker wants you to react quickly.

Instead, go directly to the service's official website or application and check your account there.

Google recommends checking account activity directly through your account rather than trusting a suspicious message link.


13. The Email Says You Won a Prize

Be skeptical of unexpected prize messages.

For example:

Congratulations!

You have won ₹50,000.

Pay a small processing fee to claim
your prize.

An unexpected reward combined with a request for money or personal information is a major warning sign.

Google specifically advises users to be cautious with messages that appear too good to be true, including prize and get-rich-quick scams.


14. The Email Claims to Be From a Government Organization

Attackers can impersonate:

  • Tax authorities
  • Law-enforcement organizations
  • Government departments
  • Regulatory bodies

A message may attempt to create fear by threatening fines or legal consequences.

Do not rely on the email alone.

Find the organization's official website independently and verify the message.


15. The Message Contains a Fake Login Button

A phishing email may contain:

[ Sign In ]

[ Verify Account ]

[ Restore Access ]

[ Secure Account ]

These buttons may lead to fake login pages.

Never enter your password simply because an email asks you to.

Google specifically recommends going directly to the service website if clicking a message link leads to a password request.


16. The Email Uses Fear or Threats

Examples:

Your account will be permanently deleted.

Legal action will begin today.

Your payment will be blocked.

Your device has been compromised.

Fear can reduce careful decision-making.

When you see strong threats or pressure, stop and independently verify them.


17. The Email Says You Must Act Immediately

Some emails repeatedly use phrases like:

  • Act now
  • Final notice
  • Immediate action required
  • Last chance
  • Expires today

Urgency does not prove that an email is malicious, but it is a reason to slow down and verify.


18. The Email Requests an Unusual Verification Code

Attackers may attempt to trick users into sharing one-time passwords or authentication codes.

For example:

I am helping you secure your account.

Please send me the verification code
you just received.

Do not share authentication codes with unexpected callers or messages.

A verification code is generally intended for the authentication process you initiated—not for someone contacting you unexpectedly.


19. The Email Contains a Strange Reply-To Address

Sometimes the visible sender and reply destination are different.

That can be a warning sign, particularly when the message asks for sensitive information.

Advanced users can inspect message headers for additional information.

Google's Gmail guidance specifically recommends checking message headers when the sender identity is questionable.


20. The Message Does Not Match the Context

This is one of the most useful tests.

Ask:

  • Was I expecting this message?
  • Did I recently request this service?
  • Do I actually have an account with this company?
  • Was I expecting an attachment?
  • Was there really a payment or login problem?
  • Does the sender normally contact me this way?

Context can reveal suspicious messages that look technically convincing.


A Realistic Phishing Email Example

Consider this fictional message:

From: Google Security Team
Subject: Urgent: Your account will be suspended

We detected unusual activity on your account.

You must verify your identity within 15 minutes.

[Verify Account]

Failure to verify will result in permanent suspension.

Let's analyze it.

Clue Why It Matters
Urgency Creates pressure to act quickly
Account threat Uses fear
Login button Could lead to a deceptive page
Identity request May attempt to collect sensitive information

The safe response is not to click the button. Open the official service separately and check account security there.


How to Check the Sender

Start with the sender information.

Look beyond the display name.

Display Name → Can be misleading

Actual Email Address → More useful clue
Domain → Important
Reply-To → Additional clue
Authentication → Additional information

Google recommends checking whether the sender name and email address match and whether the message is authenticated.


How to Check a Link Without Clicking It

On a desktop computer, move your mouse over the link.

Look at the URL shown by the email client.

For example:

Displayed:
Verify Account

Actual destination:
https://unexpected-example.invalid/login

If the destination does not match the organization you expected, do not click it.

Google explicitly recommends checking the URL before clicking.


Do Not Trust the Displayed Link Text

Text can say:

https://trusted-example.com

while the actual hyperlink destination is different.

This is why visually reading the email is not always enough.


How to Verify an Email Independently

This is one of the most important habits you can develop.

Suppose an email says your bank account has a problem.

Do not use the link in the email.

Instead:

Suspicious Email
      ↓
Close / Ignore Link
      ↓
Open Official Bank App
      ↓
Check Account
      ↓
Verify Alert

Google similarly recommends opening the legitimate website independently instead of relying on a suspicious email link.


How to Check Gmail Security Alerts Safely

If you receive an email about suspicious activity on your Google Account, do not assume the email link is genuine.

Google recommends checking security activity directly through your Google Account.

A current Google workflow is:

Google Account
   ↓
Security
   ↓
Recent security events
   ↓
Review activity

Google also recommends reviewing unfamiliar devices or security events and securing the account when something is not recognized.


What Does "Authenticated Email" Mean?

Email authentication mechanisms can provide additional information about whether a message is authorized to use a particular domain.

Common email-authentication technologies include:

  • SPF
  • DKIM
  • DMARC

Gmail can display authentication-related information for messages.

Authentication signals can be useful, but users should still examine the entire message and context rather than treating one indicator as an absolute guarantee of safety. Google recommends checking whether an email is authenticated when reviewing suspicious messages.


Can a Phishing Email Look Perfect?

Yes.

Do not assume that a message is legitimate simply because:

  • The grammar is perfect
  • The logo looks real
  • The formatting is professional
  • Your name appears in the message
  • The sender display name looks familiar

Modern scams can use convincing language and visual design.

Context, domain verification and independent confirmation are stronger habits than relying on appearance alone.


Can a Phishing Email Come From a Real Account?

Yes.

An attacker may use a compromised account belonging to a legitimate person or organization.

This means:

A legitimate-looking sender address does not automatically make every message trustworthy.

Consider the content, links, attachments and request itself.


What Should You Do With a Suspicious Email?

Use this process:

STOP
 ↓
Don't Click
 ↓
Check Sender
 ↓
Check Request
 ↓
Check Link
 ↓
Verify Independently
 ↓
Report

Do not forward suspicious messages to other people within an organization unless your security process specifically instructs you to do so.

CISA recommends reporting suspicious correspondence to the appropriate security team and warns against forwarding malicious email to other employees inside an organization.


How to Report a Phishing Email in Gmail

Gmail provides a built-in reporting mechanism.

The current Gmail process is:

  1. Open Gmail.
  2. Open the suspicious message.
  3. Click More.
  4. Select Report phishing.

Google documents these steps in its Gmail Help guidance.


Should You Delete a Phishing Email?

Follow the appropriate reporting process first.

For a personal mailbox, you can report the message and then remove it according to your normal email practices.

For a workplace mailbox, follow company procedures because security teams may need the message for investigation.


What If You Already Clicked?

Clicking a link does not necessarily mean that your account or device has been compromised.

What matters is what happened next.

If You Opened the Page but Entered Nothing

Close the page and do not continue interacting with it.

If You Entered a Password

Change the password through the legitimate service's official website or app.

Change the same password on other accounts where you reused it.

If You Shared a Verification Code

Secure the affected account immediately and review recent security activity.

Google recommends reviewing recent security events and securing the account when unfamiliar activity is detected.

If You Downloaded a File

Do not open it again. Follow your organization's security procedures or use trusted security tools to assess the device.

If Financial Information Was Shared

Contact the relevant bank or financial institution using a trusted contact method.


Phishing Email Checklist

Before responding to an unexpected email, ask:

  • □ Do I know the sender?
  • □ Does the actual email address match?
  • □ Does the domain look correct?
  • □ Was I expecting this message?
  • □ Is the message creating urgency?
  • □ Is it asking for sensitive information?
  • □ Is there a suspicious link?
  • □ Is there an unexpected attachment?
  • □ Is the request unusual?
  • □ Can I verify it independently?

A 10-Second Phishing Test

When you receive an unexpected message, ask these five questions:

1. Who sent it?

2. Why did I receive it?

3. What is it asking me to do?

4. Where does the link actually go?

5. Can I verify the request without using the email?

If several answers do not make sense, stop and investigate.


Phishing Emails Targeting Students

Students may receive messages pretending to be about:

  • Scholarships
  • University accounts
  • Exam results
  • Course registration
  • Internships
  • Job opportunities
  • Certificates
  • Fee payments

Example:

Congratulations!

You have been selected for a scholarship.

Pay ₹999 for verification and send your
bank details to complete the process.

Do not send money or personal information until the opportunity has been verified independently.


Phishing Emails Targeting Developers

Developers may encounter messages pretending to be:

  • Git hosting services
  • Cloud providers
  • Package repositories
  • Project-management tools
  • Code-review systems
  • Security teams

A fake message might ask you to:

  • Reset your password
  • Review a pull request
  • Download a project archive
  • Install a security update
  • Authenticate to a cloud account

Developers should verify domains and software downloads especially carefully.


Phishing Emails Targeting Employees

Employees should be alert to:

  • Urgent payment changes
  • Password-reset requests
  • Cloud-document shares
  • Unexpected invoices
  • IT-support messages
  • Executive impersonation
  • Vendor account changes

A company should have clear procedures for verifying sensitive financial and administrative requests.


How Organizations Can Reduce Phishing Risk

Individual awareness is important, but technical controls also matter.

Organizations can use:

  • Email filtering
  • SPF
  • DKIM
  • DMARC
  • MFA
  • Phishing-resistant authentication
  • Endpoint security
  • Web filtering
  • Security awareness training
  • Incident reporting procedures

CISA recommends layered defenses that include email-authentication controls, user education, reporting and phishing-resistant MFA.


Why Security Awareness Training Matters

Security tools cannot always recognize every social-engineering attempt.

Employees should know how to:

  • Recognize suspicious messages
  • Report suspicious emails
  • Verify unusual requests
  • Avoid sharing credentials
  • Handle suspicious attachments
  • Respond quickly after an accidental interaction

CISA recommends educating employees about common phishing indicators and creating clear reporting procedures.


Common Phishing Myths

Myth 1: "Bad Grammar Means Phishing"

Not always. Professional-looking messages can also be malicious.

Myth 2: "The Logo Looks Real"

Logos and visual layouts can be copied.

Myth 3: "The Email Uses HTTPS"

HTTPS does not prove that a website is legitimate.

Myth 4: "The Sender Is Someone I Know"

The person's account may have been compromised or impersonated.

Myth 5: "I Have MFA, So I Cannot Be Phished"

MFA improves account security, but attackers can still try to manipulate users into approving fraudulent requests or revealing authentication information.

Myth 6: "Antivirus Will Catch Everything"

Security software is useful, but it cannot replace careful verification and secure account practices.


Phishing Recognition Cheat Sheet

Warning Sign What to Do
Unknown sender Verify before responding
Unexpected urgency Stop and slow down
Suspicious link Do not click
Unexpected attachment Do not open
Password request Use official website independently
OTP/code request Do not share it
Unexpected payment request Verify through another channel
Account threat Check account directly

Final Thoughts

Recognizing phishing is less about finding one magical clue and more about developing a habit of slowing down and verifying unexpected requests.

Remember the most important warning signs:

Suspicious Sender + Urgency + Strange Link + Sensitive Request + Unexpected Attachment

When several of these appear together, treat the message with caution.

Google recommends checking the sender, authentication and URLs and avoiding requests for private information from suspicious messages.

CISA likewise recommends awareness of suspicious senders, spoofed hyperlinks, generic greetings, formatting problems and unexpected attachments, combined with reporting and other technical protections.

The safest habit is simple:

Don't trust the email. Verify the request.

When possible, open the official website or application yourself and confirm the information there.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.