Skip to Main Content
Phishing

How to identify a phishing email in under ten seconds

Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.

Subash Poudel4 min read

The short answer

  1. Read the domain after the @, not the display name. The display name is free text that anyone can set.
  2. Treat manufactured urgency as a prompt to slow down, not a reason to hurry.
  3. The visible text of a link and its actual destination are unrelated - check where it really goes.
  4. Ask what is being requested underneath the branding. It is always a credential, a code, a payment or an installation.
  5. Perfect spelling and correct branding are no longer evidence of legitimacy.

Phishing works because it is skimmed. The message arrives while you are between two other things, it looks like something you were half-expecting, and it asks for one small action. Nobody is fooled by a careful reading — they are fooled by a glance.

So the defence is not to read more carefully. It is to run the same four checks every time, in the same order, until it becomes automatic.

1. Read the sender's domain, not their name

The display name on an email is free text. Anyone can set it to anything. What cannot be faked in the same way is the domain after the @.

Watch for the substitutions that survive a glance: rn for m, the digit 1 for a lowercase l, and a legitimate brand name placed before the real domain — apple.support-billing.com is a support-billing.com address, and the word "apple" is decoration.

2. Notice what the urgency is for

Almost every phishing email creates a deadline. Your account will be suspended, a payment failed, someone logged in from another country, the document expires today.

The point of the deadline is to stop you doing exactly what you are doing now: thinking about it. Real organisations do impose deadlines, but they rarely measure them in hours, and they never depend on you acting from inside the email.

Hover a link on a desktop and the destination appears in the corner of the browser. On a phone, press and hold until a preview appears — do not tap.

You are looking for a mismatch between the visible text and the real target. A link that reads https://hsbc.co.uk/login can point anywhere at all; the text of a link and its destination are unrelated.

What the link saysWhere it goesVerdict
hsbc.co.uk/loginhsbc.co.uk/loginConsistent
hsbc.co.uk/loginhsbc-secure.co/loginMismatch
Click herebit.ly/3xK9pQUnverifiable

Shortened links are not automatically malicious, but they hide the destination, which means you cannot run this check at all. In an unexpected email, that is reason enough to stop. The same applies to a QR code, which is a link you cannot read by design.

4. Ask what is actually being requested

Strip away the branding and the formatting, and every phishing email asks for one of four things: a credential, a one-time code, a payment, or the installation of something.

New scams appear constantly and the pretexts change every year. What does not change is the request underneath, which is why this check ages better than any list of red flags.

What no longer works as a signal

Two traditional tells have expired, and continuing to rely on them is actively risky.

Spelling and grammar. Fluent, well-punctuated phishing is now standard. Absence of errors tells you nothing.

Visual accuracy. Modern phishing frequently proxies the genuine login page rather than copying it, so "it looked exactly right" is expected rather than reassuring. See how phishing works for what that means for one-time codes.

When you cannot tell

Sometimes all four checks come back clean and you still are not sure. That is not a failure of the checks — a well-made spear phishing message can pass all of them.

The fallback does not depend on judgement at all: close the message and reach the organisation yourself. Type the address, use the app, call the number on your card. If the notice was real, it will be waiting for you there. If it was not, you have lost thirty seconds.

When something does get through

If you have already clicked, the useful order is: change the password for that account first, then any account sharing that password, then turn on two-factor authentication, then check the account's recent activity or sign-in history.

Speed matters more than thoroughness here. A password changed in the first ten minutes usually ends the incident — the full sequence is in I clicked a phishing link.

Practise on real examples

Our phishing inbox drill puts you in front of genuine scam emails and asks you to sort them — the fastest way to make these checks automatic.

Try it free

Frequently asked questions

What is the fastest way to spot a phishing email?
Expand the sender's real address and read the domain after the @ sign. The display name can say anything, but the domain cannot be faked in the same way. Lookalike domains — an extra word, a hyphen, a swapped character — are the single most reliable tell available in under two seconds.
Do spelling mistakes still indicate phishing?
Not reliably. Generative writing tools removed most language errors from phishing, so fluent, correctly branded messages are now normal. Absence of mistakes is no longer evidence of legitimacy, which is why the four structural checks matter more than they used to.
How do I check where a link goes on a phone?
Press and hold the link rather than tapping it. A preview of the real destination appears, and you can read the domain before committing. On a desktop, hovering shows the destination in the corner of the browser window.
What if the email looks completely legitimate?
Then apply the rule that does not depend on appearance — do not act from inside the message. Close it, go to the organisation the way you normally would, and check whether the thing it described is real. A genuine notice will still be there; a fake one will not.

Sources

  1. Phishing attacks - defending your organisation UK National Cyber Security Centre, 2025
  2. 2025 Internet Crime Report FBI Internet Crime Complaint Center (IC3), 2026

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.