How to identify a phishing email in under ten seconds
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
The short answer
- Read the domain after the @, not the display name. The display name is free text that anyone can set.
- Treat manufactured urgency as a prompt to slow down, not a reason to hurry.
- The visible text of a link and its actual destination are unrelated - check where it really goes.
- Ask what is being requested underneath the branding. It is always a credential, a code, a payment or an installation.
- Perfect spelling and correct branding are no longer evidence of legitimacy.
Phishing works because it is skimmed. The message arrives while you are between two other things, it looks like something you were half-expecting, and it asks for one small action. Nobody is fooled by a careful reading — they are fooled by a glance.
So the defence is not to read more carefully. It is to run the same four checks every time, in the same order, until it becomes automatic.
1. Read the sender's domain, not their name
The display name on an email is free text. Anyone can set it to anything. What
cannot be faked in the same way is the domain after the @.
Watch for the substitutions that survive a glance: rn for m, the digit 1
for a lowercase l, and a legitimate brand name placed before the real
domain — apple.support-billing.com is a support-billing.com address, and the
word "apple" is decoration.
2. Notice what the urgency is for
Almost every phishing email creates a deadline. Your account will be suspended, a payment failed, someone logged in from another country, the document expires today.
The point of the deadline is to stop you doing exactly what you are doing now: thinking about it. Real organisations do impose deadlines, but they rarely measure them in hours, and they never depend on you acting from inside the email.
3. Check where the link actually goes
Hover a link on a desktop and the destination appears in the corner of the browser. On a phone, press and hold until a preview appears — do not tap.
You are looking for a mismatch between the visible text and the real target. A
link that reads https://hsbc.co.uk/login can point anywhere at all; the text
of a link and its destination are unrelated.
| What the link says | Where it goes | Verdict |
|---|---|---|
hsbc.co.uk/login | hsbc.co.uk/login | Consistent |
hsbc.co.uk/login | hsbc-secure.co/login | Mismatch |
Click here | bit.ly/3xK9pQ | Unverifiable |
Shortened links are not automatically malicious, but they hide the destination, which means you cannot run this check at all. In an unexpected email, that is reason enough to stop. The same applies to a QR code, which is a link you cannot read by design.
4. Ask what is actually being requested
Strip away the branding and the formatting, and every phishing email asks for one of four things: a credential, a one-time code, a payment, or the installation of something.
New scams appear constantly and the pretexts change every year. What does not change is the request underneath, which is why this check ages better than any list of red flags.
What no longer works as a signal
Two traditional tells have expired, and continuing to rely on them is actively risky.
Spelling and grammar. Fluent, well-punctuated phishing is now standard. Absence of errors tells you nothing.
Visual accuracy. Modern phishing frequently proxies the genuine login page rather than copying it, so "it looked exactly right" is expected rather than reassuring. See how phishing works for what that means for one-time codes.
When you cannot tell
Sometimes all four checks come back clean and you still are not sure. That is not a failure of the checks — a well-made spear phishing message can pass all of them.
The fallback does not depend on judgement at all: close the message and reach the organisation yourself. Type the address, use the app, call the number on your card. If the notice was real, it will be waiting for you there. If it was not, you have lost thirty seconds.
When something does get through
If you have already clicked, the useful order is: change the password for that account first, then any account sharing that password, then turn on two-factor authentication, then check the account's recent activity or sign-in history.
Speed matters more than thoroughness here. A password changed in the first ten minutes usually ends the incident — the full sequence is in I clicked a phishing link.
Practise on real examples
Our phishing inbox drill puts you in front of genuine scam emails and asks you to sort them — the fastest way to make these checks automatic.
Try it freeFrequently asked questions
- What is the fastest way to spot a phishing email?
- Expand the sender's real address and read the domain after the @ sign. The display name can say anything, but the domain cannot be faked in the same way. Lookalike domains — an extra word, a hyphen, a swapped character — are the single most reliable tell available in under two seconds.
- Do spelling mistakes still indicate phishing?
- Not reliably. Generative writing tools removed most language errors from phishing, so fluent, correctly branded messages are now normal. Absence of mistakes is no longer evidence of legitimacy, which is why the four structural checks matter more than they used to.
- How do I check where a link goes on a phone?
- Press and hold the link rather than tapping it. A preview of the real destination appears, and you can read the domain before committing. On a desktop, hovering shows the destination in the corner of the browser window.
- What if the email looks completely legitimate?
- Then apply the rule that does not depend on appearance — do not act from inside the message. Close it, go to the organisation the way you normally would, and check whether the thing it described is real. A genuine notice will still be there; a fake one will not.
Sources
- Phishing attacks - defending your organisation — UK National Cyber Security Centre, 2025
- 2025 Internet Crime Report — FBI Internet Crime Complaint Center (IC3), 2026
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Phishing
What is phishing? How it works, and how to recognise it
Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.
- Phishing
Phishing email examples, annotated
Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.
- Phishing
I clicked a phishing link. What should I do?
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.