← Back to Blog Computer Tips

How to Spot Phishing Emails in 2026

· Tân IT365
Person carefully checking a suspicious email on a laptop before clicking any link

A message that looks exactly like your bank, a delivery notice for a parcel you did not order, an invoice that matches last month's bill almost to the cent — phishing emails no longer rely on obvious typos. They rely on you being busy, opening mail on a phone, and clicking before you look.

This guide covers the warning signs that actually matter, how to check a sender address and a link in under a minute, the five phishing scenarios small businesses see most often, and exactly what to do if you already clicked or typed a password. Everything here works with Gmail, Outlook and the default mail app on a phone.

This article contains affiliate links. If you buy through them, Tân IT365 may earn a small commission at no extra cost to you and it does not affect our advice.

1. What phishing actually attacks

Phishing does not break into your computer. It borrows the trust you already have for a brand you deal with, then asks you to do one small thing: click a link and sign in. The fake page that opens looks like the real one — same logo, same colours, same layout — because copying a login page takes minutes.

Once you type your credentials into that page, they go straight to the attacker. From there the usual sequence is:

Three families of attack are worth separating, because the right response differs:

  1. Credential phishing — a fake login page. The target is your password.
  2. Payment phishing — a fake invoice or a fake support agent pushing an urgent transfer.
  3. Malware delivery — an attachment or download link that installs something on your machine.

All three share one ingredient: manufactured urgency. Real organisations rarely require you to act within hours. Phishing mail almost always does.

2. Seven warning signs that survive a quick glance

No single sign proves a message is fake. Two or more together is close to certain.

  1. The address is almost right. The display name can say anything — it is free text. Only the part after the @ is real. A slightly misspelled domain, an extra hyphen, or a completely unrelated string is the giveaway.
  2. The greeting is generic. Companies you actually pay know your name. "Dear valued customer" from your own bank is a warning sign.
  3. Deadline pressure and threats. "Your account will be suspended in 24 hours", "your domain expires today", "unusual sign-in detected" — the goal is to make you click before you think.
  4. The link text does not match the destination. Hover on a desktop, or press and hold on a phone, to reveal the real URL. If the domain does not match the brand, stop.
  5. It asks for something no legitimate sender asks for by email. Passwords, one-time codes, full card numbers, PINs, photos of ID documents — none of these arrive as an email request from a real provider.
  6. The attachment is the wrong type. Invoices arrive as PDFs, not as archives containing executables, and not as documents that demand you "enable content" before they display.
  7. The polish is off. Blurry logo, mismatched fonts, awkward phrasing, a footer with the wrong company address. Large senders test their templates; phishing mail is assembled in a hurry.

A useful reflex: if a message makes you feel anxious or unusually lucky, pause and run the three checks in the next section before doing anything else.

3. Three checks that take under a minute

Check 1 — read the full sender address. In Gmail, click the sender name to expand the details. In Outlook, double-click the name. Compare the domain after the @ with the official one you already know. A bank email from a free mail domain or an unfamiliar domain is not from your bank.

Check 2 — inspect the destination before clicking. On desktop, hover over the button or the link text and read the status bar at the bottom of the browser. On a phone, press and hold the link until the full address appears. The domain shown must match the official one — the visible link text means nothing.

Check 3 — do not click; open the service yourself. This is the strongest habit. Close the email, open the official app or type the official address by hand, sign in there, and look for the notice. Real notices about an account, an order or a payment appear inside the account. If nothing is there, the email was fake.

For services with their own app, check 3 is even stronger: nobody can inject a notification into your banking or delivery app. Anything genuinely important shows up there.

This is also where a password manager pays for itself. It fills credentials only when the domain matches the one saved, so a lookalike domain gets nothing. If you keep a short list of official addresses for the services you use most, store it in the manager instead of a text file.

4. Five scenarios small businesses see most

ScenarioHow to recognise itThe right response
Fake bank alert about an unusual transaction No personal name, asks you to "verify" by signing in, link goes to a lookalike page Open the bank app directly; call the number printed on your card
Overdue utility or telecom invoice Plausible amount, wrong issuer details, pressure to pay today Check the bill inside the provider's own portal or app
Courier says delivery failed and asks for a fee You never ordered anything; small payment requested to "hold" the parcel Look the tracking number up on the carrier's real site
Recruiter offering a role at an attractive rate No prior conversation; asks you to complete paperwork through a link Verify the company domain; contact the recruiter through the official posting
Fake tax authority or pension notice Threatens penalties, tells you to install an app to "sync" your records Check the official government portal; never install apps outside official stores

The response is the same in all five: never use the link in the message; open the organisation's own channel yourself. You lose nothing by double-checking. You lose a lot by following the mail.

Be especially careful with any request to install software. An app installed from outside the official stores can read messages, contacts and keystrokes. No legitimate institution asks you to sideload an app to update a profile.

5. If you already clicked or typed your password

Speed matters more than perfection. Work through this order:

  1. Change the password now on the official site — type the address yourself, never use the link in the mail. If the account is already locked, use account recovery through your recovery email or phone number.
  2. Sign out of all other sessions. Gmail, Outlook and most services show active sessions with a remote sign-out button.
  3. Turn on two-factor authentication if it was off. Even with a stolen password, the attacker still needs the second factor.
  4. Check forwarding rules and the recovery address. Attackers routinely add their own address as a hidden copy or change the recovery email so they can come back later.
  5. Review transactions and account activity in banking, e-commerce and social accounts for anything you did not do.
  6. Scan the device if you opened an attachment. Run a full scan and review recently installed apps and browser extensions.
  7. Report it to the impersonated organisation through its official support channel so it can flag the campaign.

If money moved, call the bank immediately to report a fraudulent transaction and file a report with the police — the sooner the transfer is flagged, the better the chance of freezing it. Stop replying to the sender; a common follow-up is an offer to "recover your funds" for an extra fee, which is the same scam continuing.

Once the immediate steps are done, check that your important data exists somewhere outside the affected machine. A separate copy turns a ransomware demand from a crisis into an inconvenience.

6. Four habits that make the next attempt fail

One password per account. Attackers replay stolen credentials everywhere. Reuse converts one breach into a full compromise. A password manager makes unique passwords practical instead of aspirational.

Two-factor on the accounts that matter most. Prioritise in this order: primary email, banking, social accounts, cloud storage. Your primary email comes first because it is the recovery key for everything else.

Keep a copy of critical data. Ransomware and account takeover both end in the same question: do you still have the files? Keep at least two copies in two places, and make one of them a copy that is not permanently connected to the machine you work on.

Separate your work inbox from your signup inbox. An address used only for services, shops and suppliers makes it obvious when a message does not belong. When the main inbox contains only people and organisations you actually deal with, fake mail stands out immediately.

None of this requires a big budget. Password managers, authenticator apps and cloud storage all have free tiers that are enough to start today.

7. A 30-second checklist before you click anything

QuestionIf the answer is no
Do I recognise the domain in the sender address? Do not click; open the official site yourself to check
Does it use my name and the service I actually use? Treat it as fake until proven otherwise
Does the real link match the official domain? Do not click; type the address or use the official app
Does it ask for a password, code, card number or ID photo? Stop — no legitimate sender asks for these by email
Does it demand action within hours? Slow down and verify through an official channel
Was I expecting this specific notice? Confirm inside the app or your account first

One "no" is enough to justify stopping. A minute of verification is always cheaper than a week of cleanup.

The underlying rule is simple: treat email as a notification channel, not a verification channel. Anything that matters — moving money, changing a password, sending documents — should happen inside an app you opened yourself or at a counter you walked into, never at a destination someone else chose for you.

Frequently Asked Questions

How can I tell if a bank email is fake?

Check three things: the sender address after the @ must match the official domain, the message must use your real name, and the actual link destination must point to that same domain. The most reliable test is to ignore the link entirely — open the bank app or call the number printed on your card and check the transaction there.

I typed my password into a phishing page. What first?

Change the password immediately on the official site by typing the address yourself, then sign out of all other sessions and enable two-factor authentication. Also check forwarding rules and the recovery email address, since attackers often add a backup way back in. If the account was a bank account, call the bank and review recent transactions.

Can phishing emails get past my spam filter?

Yes. Filters improve every year, but attackers keep rotating message content and sending domains, so some mail always gets through. That makes your own quick check still necessary: the filter is the first layer, not the only one.

Is it dangerous to open a phishing email without clicking?

Opening and reading is low risk, but do not click links, do not download or open attachments, and consider disabling automatic image loading so that simply opening the mail does not confirm your address to the sender. Then mark the message as spam and delete it.

What should I set up now to limit the damage later?

Three things: unique passwords for every account (a password manager makes this realistic), two-factor authentication on your primary email and banking, and a copy of important data kept somewhere separate. With those three in place, even a mistaken click leaves you time and options.

Related reading

Comments

Share your experience or ask a question about this article — we usually reply within one business day.

✓ Thanks for your comment!

No comments yet. Be the first!