Recognizing a phishing email

« Your account has been suspended, click here to reactivate it », « A package is waiting for you, confirm your details », « Your bank detected a suspicious transaction » : you probably receive these emails. These are PHISHING attempts — scams that impersonate a trusted organization to trick you and steal your information or money. It’s one of the most common threats today, and anyone can fall for it. Good news: a few simple reflexes help you spot them and avoid the trap. Here’s how to recognize a phishing email.

Phishing: what is it and why does it work?

Understanding the mechanism is the first line of defense. PHISHING (or « phishing ») is a scam technique where a fraudster impersonates a TRUSTED ORGANIZATION (your bank, a delivery service, an administration, a known website, your internet provider, a large company…) to TRICK you. The GOAL: to get you to reveal sensitive information (credentials, passwords, bank card number, personal data), to click on a link leading to a FAKE site (imitating the real one) where you would enter this information, to download a malicious file, or directly to make a payment. How it PRESENTS itself: most often by EMAIL (but also by SMS — then called « smishing » —, by message, by phone); the message IMITATES the communication of a legitimate organization: logo, layout, official tone; it asks you to take urgent action. Why it WORKS: scammers exploit effective PSYCHOLOGICAL triggers — URGENCY and FEAR (« your account will be closed », « fraudulent transaction detected », « last chance ») to make you act without thinking; the BAIT (a package, a refund, a win, a good deal); TRUST (by impersonating an organization you know); and the MASS EFFECT (they send millions of messages; it’s enough for a small fraction of people to be tricked). Messages are becoming more CAREFULLY CRAFTED: no more obvious scams full of mistakes; some are very credible, well imitated; hence the need for reflexes rather than relying solely on appearance. Anyone can be TRICKED: it’s not a matter of intelligence, but of vigilance at a given moment (you’re in a hurry, distracted, you’re actually expecting a package…); scammers count on these moments of lowered attention. What to remember for starters: phishing impersonates a trusted organization to trick you (steal your information, your money), playing on urgency, fear, and trust; it’s very common, increasingly credible, and no one is safe; but simple reflexes help you spot it: let’s learn them.

Phishing is when scammers pretend to be a company you trust (like your bank) to trick you into giving them your personal info or money. They use scary messages that say things like “your account is closed” to make you panic and click on fake links. The key is to never click without checking first, even if the email looks real.

You get an email saying “Your Amazon account is suspended, click here to verify your details.” The email looks real, with the Amazon logo and proper formatting. But when you hover over the link, it shows “amaz0n-verification.com” instead of “amazon.com” – that’s a phishing attempt trying to steal your login info.

Recognizing a phishing email

Warning signs

Several clues help you spot a phishing email; learn to recognize them. URGENCY and THREAT: a message that URGES you to act immediately, under threat of consequences (« your account will be closed within 24 hours », « react immediately », « last chance ») is very suspicious; legitimate organizations generally don’t put such pressure on you; urgency is the hallmark of the scam (to make you act without thinking). Request for SENSITIVE INFORMATION: a message asking you to enter or « confirm » your password, bank card number, codes, credentials; a serious organization NEVER asks for your passwords or confidential codes by email. DOUBTFUL SENDER’S ADDRESS: check the real email address of the sender (not just the displayed name); often, it DOES NOT match the claimed organization (a strange address, an odd domain, unusual characters); it’s a strong clue. SUSPECT LINKS: the message invites you to click on a link; WITHOUT clicking, hover over it (on computer) to see the real address it leads to: often, it DOES NOT match the official website (a strange address, misspelled, a domain that imitates but differs); beware of links. MISTAKES and tone: spelling errors, awkward phrasing, poor translation, strange tone; it’s a sign (even if scams are better written). A VAGUE greeting: « Dear customer », « Hello » without your name; an organization that knows you usually addresses you by name. AN UNEXPECTED or incoherent request: a package you weren’t expecting, a refund for a service you don’t use, a « bill » from an unknown organization; the inconsistency with your real situation is a warning. AN UNEXPECTED ATTACHMENT: an attached file you weren’t expecting may be malicious; don’t open it without certainty. A link to a FAKE site: the link leads to a page that IMITATES the official site to make you enter your credentials; beware of addresses that look similar but differ. A TOO-GOOD-TO-BE-TRUE offer: a win, an incredible deal, an unexpected refund; if it’s too good to be true, it’s probably fake. None of these signs is infallible alone, but their PRESENCE (especially several at once) should alert you. The general reflex: faced with a message that pressures, asks for sensitive information, contains suspicious links, or seems incoherent, BEWARE; don’t click, don’t reply, verify through another channel. Once known, these clues help you spot the vast majority of phishing attempts.

  • Urgency and threats (“act now or lose your account”)
  • Requests for sensitive information (passwords, bank details)
  • Suspicious sender addresses (doesn’t match the claimed company)
  • Links that don’t match the official website when hovered over
  • Spelling errors or awkward phrasing
  • Vague greetings (“Dear customer” instead of your name)
  • Unexpected requests or attachments
  • Too-good-to-be-true offers

The reflex that protects you: in doubt, don’t click — verify through another means. When faced with a suspicious message, the most effective and simple reflex is this: don’t click on ANYTHING, don’t reply, and VERIFY through an INDEPENDENT channel. In practice: if you receive a message « from your bank », a delivery service, an administration, asking you to act (click, confirm information, pay) — even if it seems credible — DON’T go through the link or the contact details in the message. Instead: contact the organization through a means YOU know and verify yourself: go DIRECTLY to the official website by typing its address yourself (or via your official app installed), or call the number on your bank card, an official letter, or the official website (never the number given in the suspicious message!). You’ll know if the request is real: if your bank really had something to tell you, you’ll see it in your official online space; if the « package » really exists, you’ll verify it on the official carrier’s website with your real tracking number. Nine times out of ten, you’ll find that there is NO real request: it was a scam. This reflex — « in doubt, I don’t click, I verify through another means » — protects you from the vast majority of phishing attempts, as it bypasses the trap: the scammer needs you to go through THEIR link and THEIR channel; by going through the official channel YOU choose, you escape them. Also remember these absolute rules: a legitimate organization NEVER asks for your password or confidential codes by email/SMS; NEVER share these information; beware of URGENCY (the scam wants you to act fast: take the time to think and verify instead); and don’t trust the polished appearance of a message (fakes are increasingly well imitated). In case of doubt, not clicking and verifying yourself through the official channel is the action that keeps you safe: simple, free, and extremely effective against phishing. Against these scams, vigilance and this reflex are worth all the software.

Recognizing a phishing email

What to do with a suspicious email (or if you’ve been tricked)

Here’s how to react to a phishing attempt, and what to do if you’ve fallen into the trap. With a SUSPICIOUS email: don’t CLICK on any link, don’t OPEN any attachment, don’t REPLY, don’t share ANY information; verify through another means if the request is real (official channel); then REPORT the message as phishing/spam (via your email’s button, which helps protect others), and DELETE it; you can also report the scam to official reporting platforms (depending on your country, there are platforms to report phishing attempts). Don’t UNSUBSCRIBE via a link in an email you suspect is fraudulent (this may confirm that your address is active); simply delete it. If you have DOUBTS but it could be real: always verify through the official channel (official website typed by yourself, official app, official number), never via the message. IF you’ve been TRICKED (you clicked and entered information, or made a payment), react QUICKLY: if you’ve given a PASSWORD, change it IMMEDIATELY (on the real site), and on all other accounts where you used the same one (our guides on managing passwords); enable two-factor authentication. If you’ve given your BANKING INFORMATION or made a fraudulent payment, contact your bank IMMEDIATELY (to block the card, dispute the transaction, monitor your account); time is of the essence. If you’ve downloaded a SUSPICIOUS attachment, beware of possible malware (our guides on what to do in case of a virus). MONITOR your accounts (banking, email) in the following days to spot any unusual activity. REPORT and possibly FILE A COMPLAINT depending on the severity (impersonation, financial harm). Don’t BLAME YOURSELF: getting tricked by a well-made scam happens to many people; the important thing is to react quickly. WARN your loved ones: share information about ongoing scams; less informed people (especially the elderly) are prime targets; explain the reflexes to them (our guides on protecting loved ones from scams). In short: with a suspicious email, don’t click, verify through another means, report and delete; if you’re tricked, react quickly (change passwords, contact the bank, monitor), report, and don’t blame yourself; and warn your loved ones. Knowing how to react limits the damage and protects your entourage.

Warning: a legitimate organization NEVER asks for your passwords or codes by email — and beware of urgency. Remember these absolute rules that protect you from the vast majority of phishing attempts. GOLDEN RULE: no serious organization (bank, administration, online service, operator) will EVER ask you, by email or SMS, to share your PASSWORD, your confidential codes, your bank card code, or your security codes; if a message asks for this, it’s a SCAM, guaranteed; NEVER share this information, and don’t enter it on a site reached via an email link. Second rule: beware of URGENCY and FEAR; scams play on « act immediately », « your account will be closed », « last chance », « fraudulent transaction detected » to make you react without thinking; take the time to THINK and VERIFY instead: a real organization gives you time; urgency is a warning sign. Third rule: don’t TRUST the appearance; fake emails and fake sites are increasingly WELL-CRAFTED (official logos, layout, tone); a credible message isn’t necessarily legitimate; always verify through another means rather than trusting « it looks real ». Fourth rule: don’t CLICK on the links in suspicious messages, and don’t open unexpected attachments; go through the official website you type yourself, or your official app. Fifth point: beware of VARIATIONS; phishing also comes by SMS (fake package, fake admin message), by phone (fake bank advisor, fake technical support — our guides on fake support scams), via social networks; the same reflexes apply; beware of urgent requests and links, whatever the channel. Sixth point: beware of TARGETED scams that use YOUR information (your name, a real order) to be more credible; even so, don’t let your guard down: verify through the official channel. Finally, PROTECT your VULNERABLE loved ones: the elderly or less informed are prime targets; explain these rules to them (never give your codes, beware of urgency, verify through another means, call a loved one in case of doubt); your vigilance can save them from heavy losses. By keeping these rules in mind — never your codes by email, beware of urgency, don’t trust appearance, don’t click, verify through another means — you’ll thwart the vast majority of phishing attempts, no matter how credible they seem.

Recognizing a phishing email

Frequently asked questions

How to know if an email is a phishing attempt?

Several signs should alert you; their presence (especially combined) is very revealing. URGENCY or THREAT: a message that pressures you to act immediately under threat of consequences (« account suspended », « 24 hours to react », « last chance ») is very suspicious: urgency is the mark of the scam. Request for SENSITIVE INFORMATION: you’re asked to « confirm » your password, credentials, bank card number; a serious organization NEVER does this by email: it’s a scam for sure. The SENDER’S ADDRESS: check the REAL email address (not just the displayed name); if it doesn’t match the claimed organization (strange address, odd domain), beware. LINKS: hover over them (without clicking, on computer) to see where they really lead; an address that doesn’t match the official website (misspelled, domain imitating but different) is a strong signal. TONE and MISTAKES: spelling errors, awkward phrasing, strange tone (even if scams improve). A VAGUE greeting: « Dear customer » without your name. INCONSISTENCY with your situation: a package you weren’t expecting, a bill from an unknown service, an unexpected refund. An UNEXPECTED ATTACHMENT. A TOO-GOOD-TO-BE-TRUE offer (win, incredible deal). No single sign is infallible, but their presence should make you suspicious. The decisive reflex: in doubt, DON’T CLICK and VERIFY through another means (the official website typed by yourself, the official app, the official number — never via the message). Often, you’ll find that there is no real request: it was a scam. Better to verify once too often than to be tricked; in doubt, consider the message suspicious.

A person is using a laptop in a dimly lit room, with the screen displaying a suspicious email.
Always check the sender before clicking links in an email.

I clicked on a phishing link: what to do?

React QUICKLY, but don’t panic; the measures depend on what you did after clicking. If you ONLY clicked on the link without entering anything or downloading: the risk is lower; close the page, don’t enter anything; as a precaution, don’t stay on the site, and monitor your device (if you notice unusual behavior, consider a check — our guides on what to do in case of a virus). If you ENTERED a PASSWORD / credentials on the fake site: change this password IMMEDIATELY on the REAL site (by accessing it yourself, not via the link), and change it on all other accounts where you used the same password; enable two-factor authentication on these accounts (our guides on managing passwords); monitor these accounts. If you gave your BANKING INFORMATION or made a payment: contact your bank IMMEDIATELY (make a stop payment/block the card, report, dispute the transaction, ask for advice); time is crucial to limit the damage; monitor your account closely. If you DOWNLOADED a file or installed something: beware of malware; don’t open it, delete it, and have your device checked if needed. In all cases: MONITOR your accounts (banking, email, others) in the following days and weeks to spot any suspicious activity; REPORT the scam (reporting button in your email, and official reporting platforms depending on your country); depending on the severity (harm, impersonation), you can FILE A COMPLAINT. Don’t BLAME YOURSELF: scams are increasingly credible, and getting tricked happens to many people; the important thing is to react quickly to limit the consequences. Finally, WARN your loved ones if the scam is circulating. Acting quickly (changing passwords, contacting the bank, monitoring) often helps limit, or even avoid, the damage; don’t stay passive, but don’t panic either.

Recognizing a phishing email

Aren’t phishing scams easy to spot?

Less and less so: that’s why you need reflexes, not just relying on appearance. There was a time when many scams were obvious (major mistakes, poor layout, implausibilities) and easy to spot. That’s no longer always the case: phishing attempts have become very WELL-CRAFTED; scammers perfectly imitate the logos, layout, and official tone of organizations; fake sites look indistinguishable from real ones; some messages are personalized with YOUR information (your name, a real order) to seem credible; and modern tools allow them to produce well-written, error-free texts. Result: you CAN’T rely solely on appearance or the absence of mistakes to distinguish real from fake; a very credible message can be a scam. That’s why you need to adopt REFLEXES that don’t depend on appearance: systematically beware of URGENCY and requests for sensitive information; NEVER share your passwords/codes (no legitimate organization asks for them); don’t click on the links in messages, but VERIFY through another means (official website typed by yourself, official app, official number); consider any unexpected request suspicious. These reflexes work no matter how good the imitation is, as they bypass the trap; they are your real protection. Moreover, anyone can be tricked, not just « less informed » people: it’s enough to have a moment of distraction, fatigue, or to come across a scam that fits your situation (you’re actually expecting a package…). So no, scams are no longer easy to spot at a glance; hence the importance of these verification reflexes, much more reliable than judging by appearance. Stay vigilant, even with a message that « looks real ».

What to remember

Phishing (phishing) is a scam that impersonates a TRUSTED ORGANIZATION (bank, delivery service, administration, known website) to TRICK you: steal your information (passwords, banking data), make you click on a fake site, or pay. It plays on URGENCY, FEAR, BAIT, and TRUST, comes mainly by email (but also SMS, phone, social networks), and is increasingly WELL-CRAFTED: anyone can be tricked. WARNING SIGNS: urgency/threat (« act within 24 hours »), request for sensitive information (password, codes — which a legitimate organization NEVER asks for by email), a doubtful sender’s address, suspicious links (hover over them to see where they really lead), mistakes or strange tone, a vague greeting (« Dear customer »), an incoherent request with your situation, an unexpected attachment, or a too-good-to-be-true offer. THE PROTECTIVE REFLEX: in doubt, DON’T CLICK, don’t reply, and VERIFY through another means (the official website typed by yourself, the official app, the official number — never via the message); this bypasses the trap. ABSOLUTE RULES: a legitimate organization NEVER asks for your passwords/codes by email; beware of urgency (take the time to verify); don’t trust the polished appearance (fakes are credible). If you’re TRICKED: react quickly — change compromised passwords (and everywhere they were reused), contact your bank immediately if you gave banking information, monitor your accounts, report the scam, and don’t blame yourself (it happens to many; the important thing is to act). WARN your vulnerable loved ones (especially the elderly — prime targets) by explaining these reflexes to them. Against phishing, no matter how credible, vigilance and the reflex « I don’t click, I verify through another means » are worth all the software: they protect you from the vast majority of these scams.

Recognizing a phishing email
Recognizing a phishing email
Recognizing a phishing email

Concerned about your security, need to check or clean a device? Our support service guides you step by step.

Request assistance →

Commentaires

Leave a Reply

Découvrez nos autres services

ElpisIA, c’est tout un univers — explorez nos autres services.