Advertising disclosure: radovian.online is an independent site funded by affiliate commission. Links marked partner link earn us a commission if you buy. You pay the vendor’s normal price. How this works.
radovian.onlinePlain-language technology guides

HomeGuides › Phishing

How to spot a phishing message

Filters catch most of it. The ones that get through are the ones designed to get through, and they all share the same five parts.

No partner links on this page

This guide is purely informational and carries no commercial links. The site as a whole is funded by affiliate commission — see the affiliate disclosure — but nothing below earns us anything, whatever you decide to do.

Phishing works on attention, not on ignorance. The messages that succeed arrive when you are busy, refer to something plausible, and ask for one small action. Knowing the anatomy helps, but the habit at the end of this guide helps more, because it works even when you are tired.

A mock message window annotated with five numbered callouts: a sender address close to the real domain but not it, a subject line manufacturing urgency with a 24-hour deadline, a greeting that avoids your name, a button whose visible text differs from the address it leads to, and a message that pushes you away from normal contact routes.
The five parts almost every phishing message has. Original diagram drawn for this site; the message shown is fictional.

1. A sender address that is close, but not right

Look at what comes after the final @ sign, and read it right to left. yourbank-alerts.com is not yourbank.com, and yourbank.com.secure-login.net belongs to secure-login.net. The display name is worth nothing: anyone can put any name on a message.

2. Manufactured urgency

A deadline exists to stop you checking. “Within 24 hours”, “your account will be closed”, “final notice”, “unauthorised payment of €499 — cancel now”. Real organisations do send time-sensitive messages, but they do not depend on you acting inside the message itself. Treat urgency as the signal to slow down, not to hurry.

3. No name, or the wrong name

“Dear customer” from a company that has known your name for years is a poor sign. Be aware that the opposite is not reassurance: after a data breach, attackers often do know your name, your address and what you bought. A message that knows something about you is not thereby genuine.

4. Link text that does not match its destination

Hover over the link on a computer, or press and hold on a phone, and read where it actually goes before tapping. Watch for bare IP addresses, unfamiliar top-level domains, long strings of random characters, and shortened links that hide the destination entirely. On a phone this is harder and that is why phones are targeted.

5. A demand to act inside the message

The whole scheme depends on you using the attacker’s route rather than your own. Anything asking you to sign in, confirm details, pay an invoice or install something, all without leaving the message, deserves suspicion regardless of how well it is written.

The habit that works

Never use the link. Go to the organisation yourself. Open your bank, your parcel carrier or your tax office from your own bookmark, from the app you already have, or by typing the address. If the message is genuine, whatever it refers to will be waiting for you there. If there is nothing there, you have your answer and you have lost fifteen seconds.

This works even when you are tired, even when the message is well written, and even when it correctly knows your name and your last purchase. It is the only defence on this page that does not depend on you spotting something.

Variants worth knowing about

If you have already clicked

  1. Do not panic, and do not delay. Speed limits the damage more than anything else.
  2. If you entered a password, change it immediately on the real site, and change it anywhere else you reused it. Reuse is what turns one mistake into several.
  3. Turn on multi-factor authentication on the affected account if it is not already on.
  4. If you entered card details, contact your bank now and ask them to block the card.
  5. If you installed something, disconnect from the network and run a full scan with the protection already on the machine.
  6. Check the account’s recovery settings — alternative e-mail addresses, forwarding rules, app passwords. Attackers add their own so they can return after you change the password.
  7. Report it to the organisation that was impersonated; most have an address for this.

What actually reduces the risk over time

Security software contributes: web filtering blocks known malicious sites and mail filters remove most attempts before you see them. Neither is a substitute for the habit above, because the messages that reach your inbox are precisely the ones the filters did not recognise.