Advertising disclosure: this site is funded by affiliate commissions. Links marked “Partner link” are advertisements; we may earn a commission if you buy through them, at no extra cost to you. How we are funded
celenoPractical home cyber-security
Guide

How to spot a phishing message

Phishing messages try to get you to hand over a password, payment details or access to your device by pretending to come from someone you trust. They are the starting point of many account takeovers and malware infections. The good news is that most share a few recognisable signs.

By Susan Smith, responsible editorPublished Last reviewed
Diagram of a fictitious phishing email from a made-up bank with four numbered warning signs: a look-alike sender address, an urgent threat in the subject, a button asking you to log in, and a link pointing to a different domain.
Four common warning signs, shown on a fictitious example. The company and addresses are invented. Original illustration by celeno.online.

The warning signs

1. The sender is not quite right

The display name may say “Your Bank” or “Delivery Service”, but the actual address uses a different or slightly misspelled domain, or a free webmail account. On a phone, tap the sender name to see the full address.

2. Urgency, threats or prizes

“Your account will be closed today”, “Unpaid customs fee”, “You have won”. Pressure is designed to make you act before you think. Real organisations rarely set deadlines of a few hours by email or text.

3. A request for credentials, codes or payment

Be very wary of any message that asks you to log in through a link, confirm card details, or read out a one-time code. A legitimate bank will never ask you for a one-time code that you received to approve a transaction.

4. Links that go somewhere else

Hover over a link on a computer, or press and hold it on a phone, to preview the real address before opening it. Look at the part just before the first single slash: yourbank.example.login-check.example belongs to login-check.example, not to your bank. When in doubt, do not use the link at all. Type the address you know, or use the official app.

Other clues

What to do with a suspicious message

  1. Do not click, reply or call numbers in it.
  2. Check independently. Contact the organisation using details from its official website, your card or a previous statement.
  3. Report it. Most email services have a “Report phishing” option. Banks usually have a dedicated address for forwarding phishing.
  4. Delete it.

If you have already clicked or entered details

  1. Passwords: change the password of the affected account straight away, from a device you trust, and anywhere else you used the same password.
  2. Bank or card details: call your bank using the number on your card. Ask it to block the card or watch for fraudulent transactions.
  3. Two-step login: switch it on for the affected account if it is not already on, and check for unknown devices or forwarding rules.
  4. Downloads: if you opened an attachment or installed something, disconnect from the internet and run a full scan with your security software.
  5. Report fraud: if you lost money, report it to the police. In the Czech Republic, the national cyber-security agency NÚKIB and the national CSIRT also publish current warnings.

Security software with web protection can block many known phishing pages, but new ones appear constantly. Your own checks remain the most reliable defence.

Sources

This guide contains no partner links. The illustration is an original drawing using a fictitious company.