The tells that give away almost every phishing attempt
Phishing doesn't rely on sophisticated hacking — it relies on you not looking closely for about three seconds. Nearly every phishing attempt shares the same handful of tells once you know to check for them.
The core pattern
Phishing works by convincing you an urgent, legitimate-looking message requires you to click a link and log in, confirm payment info, or "verify your account" right now. The specific brand it impersonates changes — banks, delivery services, your employer's IT department, the IRS — but the mechanics are almost always the same.
The tells, in order of reliability
- Manufactured urgency. "Your account will be suspended in 24 hours." "Unusual sign-in detected — verify now." Real companies rarely demand immediate action through email or text, especially with a countdown attached.
- Sender address doesn't match. Check the actual email address, not just the display name —
support@amaz0n-security.comis not Amazon. On phones, tap or press the sender name to reveal the real address, since phones often hide it by default. - Links that don't go where they claim. On desktop, hover over a link (without clicking) to see the actual destination URL in your browser's status bar. On mobile, press and hold to preview it. If the visible text says "yourbank.com" but the actual link goes somewhere else entirely, that's the whole scam right there.
- Generic greeting. "Dear Customer" or "Dear User" instead of your actual name, from a company that should already know who you are.
- Requests that don't match normal behavior. A "CEO" emailing asking you to buy gift cards urgently, or a "bank" asking you to reply with your full account number — real institutions have specific, consistent channels for sensitive requests, and abandoning them is a red flag by itself.
What to do instead of clicking
- Go to the website or app directly, typing the address yourself or using your saved bookmark, instead of clicking the link in the message
- Call the company using a number from their official website or the back of your card — not a number provided in the suspicious message itself
- Report and delete — most email clients have a "report phishing" option, and it helps their spam filtering improve for everyone
Text and phone phishing work the same way
The same tells apply to "smishing" (text-based phishing) and vishing (phone-call phishing): manufactured urgency, a request to click a link or reveal information, and pressure to act before you have time to verify independently. A caller claiming to be your bank's fraud department who then asks you for your card number or a one-time code is not your bank — a real bank fraud department never needs the code that was just sent to you, because they're the ones who already have your account information.
Quick reference
- Urgency + a request to click/verify/pay is the core pattern, regardless of the brand impersonated
- Check the actual sender address, not just the display name
- Hover or long-press links to see where they really go before clicking
- Verify independently — go to the site directly or call a number from official materials, not the message
- No legitimate party ever needs a one-time code you were just sent — that code is proof of who you are, not who they are