9sBlog

How to spot a phishing email or scam link

A practical routine for spotting phishing: check the real sender, read a link before clicking, ignore the padlock, and recover fast if you clicked.

Hands using a tablet at a table, an open email inbox visible on a laptop screen behind it

Phishing works by getting you to trust something you should check. This guide gives you a repeatable routine: read the real sender address, inspect a link before you touch it, recognize the pressure tactics scammers reuse, and know exactly what to do if you already clicked. None of it requires special software, and most of it takes a few seconds once it becomes a habit.

Start with the sender, not the message

Most email clients show a friendly display name, like “IT Help Desk” or a person’s name, before the real address. Attackers set a familiar display name while sending from an unrelated free account, a lookalike domain, or a spoofed address. The name alone proves nothing. Expand or tap the sender to reveal the actual From address, and judge that.

Some clients help you here. In Outlook, when the sender’s real address differs from the one shown in the From field, Outlook appends an underlined “via” tag showing the true sending domain, and a question mark on the sender image means Outlook could not verify the sender through email authentication. Those are signals worth slowing down for.

If you want to go further, you can read the full message headers to see where a message actually originated. In Gmail, open the message, click More (the three-dot menu) and choose “Show original.” In classic Outlook desktop, open the message and use File > Properties to read the “Internet headers” box. Exact wording varies between new Outlook, Outlook on the web, and classic Outlook, and across Gmail on the web versus the app, so treat these as the general path rather than a fixed sequence.

The single most useful habit is checking a link’s real destination before you open it. On a desktop, rest your cursor over the link without clicking and read the URL that appears, usually in the status bar at the bottom of the window. If the address does not match the text you can see, the link may be spoofed.

On a phone you cannot hover. Instead, press and hold (long-press) the link until a preview bubble or dialog appears showing the full destination URL, read it, then lift your finger without opening it. Boston University notes this press-and-hold preview method is the same on iOS and Android.

Once you can see the real address, you need to read it correctly, because the way it is written is often the trick.

Read the domain from right to left

The real domain is the part immediately to the left of the top-level domain, such as .com, not the leftmost words. A link like www.paypal.com.somerandomservice.com actually belongs to somerandomservice.com; the paypal.com piece is only a subdomain the attacker controls. Your eye tends to fixate on the start of a URL, and that is exactly what this exploits. Find the top-level domain, then read one label to its left.

Watch for lookalike letters

IDN homograph attacks register domains using Unicode characters that look identical to Latin letters, for example a Cyrillic a swapped in for the Latin a in paypal.com. Because the code points differ, it is a genuinely different domain that looks the same to your eye. A documented 2005 proof of concept used a paypal.com spelling with a Cyrillic first a to reach a spoofed site. Internationalized domains are encoded in Punycode with an “xn—” prefix, and modern desktop browsers defend against this by showing such mixed-script domains in that xn— form in the address bar. That protection is a browser behavior, though; email clients and pasted content may still render the deceptive Unicode version, so the encoded name is not guaranteed to show before you click.

The padlock is not proof

An HTTPS padlock only means the connection is encrypted, not that the site is honest. Free domain-validation authorities like Let’s Encrypt issue certificates in seconds with no identity check, so phishing sites routinely show the padlock. Per APWG data cited widely, the large majority of phishing sites now use HTTPS, up from roughly 25% in Q3 2017 per PhishLabs. Treat the padlock as meaningless for deciding whether to trust a site.

Recognize the pressure tactics

Phishing leans on the same emotional levers again and again. CISA lists the core red flags: urgent or emotionally appealing language warning of dire consequences, requests for personal or financial information, and links whose real destination does not match the visible text.

The FTC describes the pretexts that wrap around those levers. A message may claim suspicious activity or login attempts, say there is a problem with your account or payment information, ask you to confirm personal details, include a fake invoice, push you to click a link to make a payment, or dangle a coupon or refund for free money. Microsoft gives concrete examples in the same spirit: an email promising a reward such as “Click this link to get your tax refund,” a document that appears to come from a friend, bank, or reputable organization asking you to sign in, and an invoice for a purchase you never made.

One principle cuts through all of it. Legitimate organizations, including Google, will not ask for your password by email, and the OCC states plainly that financial institutions never ask you to provide your password over the phone or in response to an unsolicited request. If a message asks for a password or a one-time code, that is close to a decisive tell on its own.

Be careful with attachments

Unexpected attachments are a primary way malware spreads. CISA warns that an unsolicited email asking you to download and open an attachment is a common delivery method, often paired with a manufactured sense of urgency. Treat an attachment you did not expect with suspicion even when it appears to come from someone you know, and verify through a separate channel before opening it. Keeping a working backup of your files also means a bad attachment that slips through does far less damage.

When in doubt, verify independently

Across FTC, CISA, and OCC guidance, the same rule holds: do not act on contact details supplied inside a suspicious message, including its links, phone numbers, and unsubscribe options. If a message might be real, look up the organization’s genuine website yourself, or use the number on the back of your card or on a statement, and reach them that way to confirm before you provide any information or payment.

If you already clicked or entered credentials

Do not submit anything further, and close the page. Then change the affected passwords as soon as you can from a device you trust, not the one that may be compromised. Turn on multi-factor authentication where it is available, and scan the device for malware.

Multi-factor authentication raises the bar sharply, because a stolen password alone is no longer enough, but not all MFA is equal. CISA identifies FIDO/WebAuthn methods, including passkeys and hardware security keys, along with PKI-based authentication, as phishing-resistant, while SMS codes, authenticator-app codes, and push approvals can still be phished or relayed. The practical framing: any MFA beats none, and FIDO or passkeys are the strongest. Layering that on top of basic security hygiene like unique passwords and prompt updates is what limits the damage when one link gets through.

If you gave out banking information, contact your financial institution immediately. In the US, you can also reach the credit bureaus directly; the OCC lists Equifax at 800-525-6285, Experian at 888-397-3742, and TransUnion at 800-680-7289, and points identity-theft victims to the FTC at 1-877-IDTHEFT and IdentityTheft.gov. Verify current numbers before relying on them, since these are the ones the OCC page lists.

Report it, so it works on someone else less often

Reporting is quick and it feeds the systems that block these campaigns. In Gmail on a computer, open the message, click More (the three-dot menu next to Reply) and choose “Report phishing.” In Outlook, select the message and, above the reading pane, choose Report > Report phishing; note that reporting flags the sender but does not automatically block them.

Beyond your mail client, the FTC advises forwarding phishing emails to the Anti-Phishing Working Group at [email protected] and reporting to the FTC at ReportFraud.ftc.gov. If credentials or money are involved, you can also file with the FBI’s Internet Crime Complaint Center at ic3.gov. For scam text messages, forward the message to 7726, which spells “SPAM” on the keypad; major US carriers use that shortcode to collect spam reports, and forwarding to it is generally free and does not count against your plan. The FCC and FTC both advise not clicking links or replying first.

The short version

Trust the address, not the display name. Read every link before you touch it, from the top-level domain leftward, and ignore the padlock as a sign of safety. Slow down whenever a message manufactures urgency or asks for a password, and verify anything important through a channel you looked up yourself. Do those few things by reflex and the vast majority of phishing simply stops working on you.

Discussion

    Leave a comment