Email Phishing Myths I Hear All the Time in Liverpool
I get asked about phishing emails more than almost anything else I do. Everyone's heard of them, but the myths around what they actually look like and who they actually target are still doing a lot of damage across Liverpool. So let's clear a few things up.
Myth One: Phishing Emails Are Badly Written
That was true a decade ago. These days the scam emails landing in Liverpool inboxes are polished, on brand, and often better formatted than the genuine emails they're copying. I've seen fake Royal Mail and DPD messages that used the correct fonts and logos down to the pixel. Spelling mistakes are a nice bonus clue when you get them, but you cannot rely on them anymore. What actually gives a phishing email away is the sender's domain, the urgency in the subject line, and a link that doesn't quite match where it claims to go. I go through the red flags I always check first in a lot more detail if you want the full checklist.
Myth Two: Only Older People Fall For This
I wish this one was true, because it would make my job easier. In reality I see just as many students and young professionals get caught out, usually because they're moving fast on their phone between apps and don't give a message a second look. Scammers know this, which is why so many phishing attempts now arrive as texts and app notifications rather than plain emails. Confidence with technology doesn't protect you from a message designed to make you panic first and think second. If anything, I've noticed the scams pushing AI scams and deepfake voice notes hit younger people hardest, simply because that's where they spend their time.

Myth Three: My Email Provider Catches Everything
Spam filters are genuinely good these days, and they do stop a huge volume of junk before it ever reaches you. But treating your inbox filter as a security system is where people come unstuck. New scam domains get registered every single day, faster than any filter can catalogue them, so a fresh phishing campaign will often slip through in its first few hours simply because nothing has flagged it yet. A password manager like NordPass helps here too, because it won't autofill your login on a lookalike site even if the email itself gets past your filter. That mismatch is often the first sign something's wrong.
Myth Four: If I Don't Click Anything, I'm Safe
Mostly true, and it's still the best rule of thumb I can give anyone. But it's not quite the full picture. Some phishing emails use tracking pixels that confirm your address is active the moment you open them, even without a click, which is enough to get you added to a list for the next wave of attempts. It's a good reason to turn on two factor authentication on your main accounts, so that even if a password does leak somewhere down the line, it isn't enough on its own to get anyone in. Belt and braces, as my old boss used to say.
The Real Test I Use Instead
Forget trying to spot bad grammar. I ask myself one question with every unexpected email: would this organisation actually contact me this way, about this, right now? A bank will never ask you to confirm your password by email. A delivery company won't threaten to bin your parcel in six hours. Once you start asking that question automatically, most phishing emails fall apart in about two seconds. If you're ever unsure, report it to Action Fraud rather than just deleting it, since that helps track patterns across the whole city. And if you want a proper walkthrough of every safeguard I recommend in one place, my Safety Toolkit covers all of it. I'm always happy to look at a suspicious email if you get in touch and aren't sure either way.
