How to Spot a Phishing Email
Phishing emails try to trick you into sharing information or clicking something you'd rather not. The good news: most of them give themselves away if you know what to look for. Here's a calm, plain-English guide.
What is phishing?
Phishing is when someone sends a message, usually by email, but also by text or chat, pretending to be a trusted person or organisation. Their goal is to get you to do something: hand over a password, click a link, open an attachment, or send money or personal details.
It's incredibly common, and it happens to careful, sensible people every day. Spotting one isn't about being clever, it's about pausing for a moment before you act.
The warning signs to look for
A sense of urgency or pressure
"Your account will be closed in 24 hours." "Action required immediately." Real organisations rarely rush you. If a message is pushing you to act fast or threatening consequences, slow down, that pressure is the trick.
A strange or slightly-off sender address
The display name might say "Royal Mail" or "Microsoft", but the actual email address tells the truth. Look at the part after the @, does it match the real organisation's website? Watch for tiny misspellings (rnicrosoft.com, paypa1.com) or random extra words.
Suspicious links
Hover your mouse over a link (or press and hold on a phone) to see where it really goes, without clicking. If the destination doesn't match the company it claims to be from, don't click. When in doubt, go directly to the organisation's website by typing the address yourself.
Spelling, grammar and odd phrasing
Real companies proof-read their emails. Awkward sentences, missing words, generic greetings like "Dear Customer", or strange formatting are all worth a second look. AI is making phishing emails cleaner, so this is no longer a guarantee, but it's still a useful clue.
Requests that don't quite add up
Your bank won't ask for your full password. HMRC won't ask for payment in gift cards. Your CEO probably isn't emailing on a Sunday asking you to buy vouchers. If a request feels unusual, that feeling is worth listening to.
What to do if you receive one
- Don't click any links or open attachments. You don't need to in order to deal with it.
- Don't reply. Even saying "stop" confirms your address is real and active.
- Report it. Forward suspicious emails to report@phishing.gov.uk (the National Cyber Security Centre's reporting service). Report scam texts by forwarding them to 7726.
- Delete it. Once reported, you can safely delete the email.
- Tell someone. If it arrived at work, let your IT or manager know, others may have received it too.
If you clicked a link or shared details
First, don't panic. Lots of people do this, and there are clear steps you can take to limit the impact.
- Change your password for the affected account straight away. If you reuse that password anywhere else, change it there too.
- Turn on two-step verification (2FA) on the account if it's available, it adds a second check beyond your password.
- If you shared bank or card details, contact your bank immediately. They have processes for exactly this and can freeze cards or refund fraudulent transactions.
- Run a scan with the antivirus or security software on your device.
- Watch your accounts for unfamiliar activity for the next few weeks.
- Report it to Report Fraud if money was lost or your details were used.
How safe are your online habits?
Take the free 5-minute CyberSafe Coach check and get a personalised score with clear, practical next steps. No jargon, no scare tactics.
Start my free safety checkYour one habit from this lesson
When a message pushes you to act quickly, stop and check it through a channel you already trust before you click or reply.
Track your progress and earn XP
Sign in to mark this lesson complete and add +25 XP to your safety score.
Sign in or create a free account