How to Spot a Fake Email
Here’s the thing about phishing emails: the ones that actually catch people are not the obvious, typo-riddled ones with subjects like “URGENT!!! Your account will be DELETED!!!” Those are easy to laugh off. The dangerous ones are polished, they look legitimate, and they come at a moment when you’re distracted or stressed. That’s by design.
So let’s talk about what to look for.
The Sender’s Address Is Where You Start
The display name - the “from” label you see in your inbox - can say anything. “PayPal Support”, “Apple ID Security Team”, your bank’s name. That part is trivially easy to fake and tells you nothing.
What matters is the actual email address. Click or tap on the sender’s name to reveal it. A real email from PayPal comes from @paypal.com. Full stop. Not @paypal-support.net, not @paypal.accounts.info, and definitely not @gmail.com.
Some things to watch for:
- The domain doesn’t match the organisation’s website (e.g.
support@amazon-billing.comvsamazon.com) - Subtle misspellings -
micros0ft.com,arnazon.com- designed to look right at a glance - Long strings of random characters before the
@ - Free email services for anything claiming to be an official company
Be Suspicious of Generic Greetings
Legitimate companies that hold your account know who you are. They’ll use your name. If an email from your bank opens with “Dear Valued Customer” or “Hello Account Holder”, that’s a signal - they’re sending this to thousands of people and don’t actually have your details.
Urgency Is a Red Flag, Not a Reason to Act
Scammers are in the business of making you panic before you can think clearly. Phrases like these are designed to do exactly that:
“Your account will be permanently closed within 24 hours if you do not verify your details immediately.”
No legitimate company communicates with you this way. If you’re worried the email might be real, go directly to the company’s website by typing the URL yourself - not by clicking anything in the email.
Hover Before You Click
Before clicking any link, hover your mouse over it and look at the destination URL in your browser’s status bar. On mobile, press and hold to preview it.
Ask yourself: does the domain actually match the company? A common trick is to make the real domain look like a subdomain - accounts.microsoft.com.verify.ru looks almost right at a glance, but the actual domain there is verify.ru.
When in doubt, navigate to the company’s website yourself. Type it in. Don’t follow the link.
Unexpected Attachments Are a No
Real organisations rarely send you attachments out of nowhere. If an email you weren’t expecting arrives with a file attached - especially something like .exe, .zip, .doc, or .pdf - don’t open it.
If the email claims to be an invoice or important document, log in to the company’s website directly to find it there. If it’s real, it’ll be in your account.
What to Do If You’re Not Sure
- Don’t click anything or open any attachments until you’ve verified the email is legitimate
- Contact the company directly using contact details from their official website, not anything in the email
- Report it to your email provider’s spam or phishing reporting tool
- Delete it
If you did click something before reading this - change your passwords immediately and enable two-factor authentication on any accounts that might be affected.
Everyone can be caught off guard. Scammers are good at what they do, and they put a lot of effort into making things look real. Being cautious is not paranoia - it’s just good practice. When in doubt, don’t click~
