A Phishing101 resourceBack to the Scam Field Guide

Anatomy of a Phishing Email

A fake email has to fake something: who sent it, where its link goes, how much time you have. Here are eight places to look, marked on a real-looking example, so you know what to check before you click.

This email is a made-up example. Every address in it ends in .example, a name reserved for examples that can never be registered or visited, and the phone number uses the 555-01 range kept for fiction. Nothing in it leads anywhere.

The email, with eight red flags marked

From
Your Bank Security <security-team@y0urbank.example>1
Reply-To
account-review@secure-mailbox.example1
Subject
URGENT: Your Account Will Be Suspended!!!!2

Dear Valued Customer,3

We have detected unusual activity on your account. Your account will be SUSPENDED within 24 hours unless you verify your information immediately.4

We have recieved reports that your account have been comprimised.5

Please click the link below to secure your account:

Verify Your Account Now6 Where it really goes: https://secure-yourbank.login-verify.example/account

You must complete this verification within 24 hours or your account will be permanently closed.7

Questions? Call our Security Desk at 1-800-555-0142.8

Sincerely,
Your Bank Security Team

What each flag means

One flag on its own proves little. Several together, in a message you were not expecting, is the pattern to stop for.

  1. The sender's real address

    The name Your Bank Security is just a label, and anyone can type any label they like. The address after it is what matters, and it is fake: y0urbank.example uses a zero where the real name has the letter o.

    Check the address, not the name. On a phone, tap the sender's name to see the full address.

    Even the right address can be faked. This is called spoofing: the sender forges the From line so it shows the exact address of a real company or person.

    Signs to look for: a Reply-To address that is different from the From address, like the one in this email, so your reply goes to the scammer; your email app showing "via" or "on behalf of" next to the sender; or a warning banner at the top of the message, such as "Be careful with this message." Take that banner seriously.

    A correct-looking address is never proof on its own. Contact the company or person yourself, using details you already have.

    Back to the email

  2. An urgent, scary subject line

    Capital letters, words like URGENT and SUSPENDED, and a row of exclamation marks are there to make you act before you think. Real companies rarely write like this.

    Back to the email

  3. A generic greeting

    "Dear Valued Customer" is what you write when you are sending the same email to millions of people. A company you actually do business with usually knows your name, and a friend or coworker would use it too.

    But seeing your own name is not proof. Names and email addresses leak in data breaches, and scammers use them.

    Back to the email

  4. Threats and fear

    A threat to suspend or close your account is meant to frighten you, because a frightened person acts first and checks later, if at all. Real companies do sometimes warn you about consequences, and debt collectors can be blunt. But a real warning leaves you time and lets you check it through a route you choose. A threat that demands you act right now, using the link or number in the message itself, is the scam's signature.

    One firm line: under federal law, a debt collector cannot threaten to have you arrested for an unpaid debt. A judge can act if you ignore an order in a court case, but a threat of arrest in a call, text or email is itself a warning sign.
    https://www.consumerfinance.gov/ask-cfpb/can-i-be-arrested-for-an-unpaid-debt-en-1537/

    And a friend or relative in real trouble can wait the minute it takes you to call them back.

    Back to the email

  5. Spelling and grammar errors

    "Recieved" should be received, and "your account have been comprimised" should be has been compromised. Companies proofread what they send.

    This is now a weak sign. Scammers use the same writing tools everyone else does, including AI, so many phishing emails are written perfectly. Clean writing proves nothing.

    Back to the email

  6. The link says one thing and goes somewhere else

    The button says Verify Your Account Now, and the address behind it starts with "secure-yourbank" to look official. But the name just before the first single slash is login-verify.example, and that is who owns the page. Your bank does not.

    Before you click anything, hover your mouse over it and read the address that appears. On a phone, press and hold the link instead, read the address, then slide your finger away to cancel. Better still, skip the link and type your bank's address yourself.

    Back to the email

  7. An artificial deadline

    "Within 24 hours" is there to stop you checking, calling someone, or talking it over with family. A real problem will still be real after you take ten minutes to confirm it.

    Back to the email

  8. Contact details you cannot trust

    A phone number in a suspicious email goes to the scammer, not the company or person the email claims to be from. Some scams are built entirely around getting you to call. Security professionals call it callback phishing.

    Never use a number, address or link from the message itself. Look it up on your own: the back of your card, a statement, the company's website typed in by you, or, for a friend or coworker, the number already saved in your phone.

    Back to the email

Six questions before you click

If an email looks suspicious

  1. Do not click links or open attachments. Not even to see what happens.
  2. Do not reply, and do not call any number in it. Anything in the message may lead straight back to the sender.
  3. Go to the company or person yourself. For a company, type its address into a new browser window or use its own app. For a friend or coworker, call or text them on the number you already have.
  4. Call using a number you already trust, from the back of your card, a statement, the company's website, or your own contacts.
  5. Report it, then delete it. At work, report it to your IT or security team.
  6. Tell someone. A friend or family member may spot what you missed, and they may get the same email next.

Where to report it

Anti-Phishing Working Group

The Federal Trade Commission's advice is to forward phishing emails here. Forward the whole email to this address:

reportphishing@apwg.org
Federal Trade Commission

Report the attempt to the FTC as well, especially if you lost money or gave out information.

https://reportfraud.ftc.gov
Your email provider

Use the "Report phishing" or "Report spam" button in your email app. It helps block the same message for other people.

The real company

Many companies explain how to report phishing that uses their name. Find it on their own website, typed in by you, never through the email.

FTC advice on phishing

Where the reporting advice above comes from.

https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams