How to Identify Email Phishing

Aug 11, 2026By Jay Kells
Jay Kells

Phishing isn't a technical attack, it's a psychological one. The email is designed to make you react before you think, using urgency, fear, or the promise of something good to short circuit your usual caution. That's why it catches out careful, switched on people just as often as anyone else. I've seen it happen to solicitors, accountants, people who spot scams for a living in every other part of their day. Knowing it's designed to rush you is half the defence.

Phishing is still the single most common thing people email me about, more than any other scam type, and the questions are almost always the same. Is this real. Did I just make a mistake clicking that. What do I do now. So I want to lay out exactly what I check, what a convincing fake actually looks like today, and what to do if you've already clicked something you shouldn't have.

The Three Things I Check Before I Trust Any Email

Before I do anything else with a suspicious email, I check three things, in this order. First, the sender's actual email address, not the display name, by tapping or hovering on it. A display name can say "Your Bank" while the address underneath is a string of random characters at a domain that's never been near a bank in its life. Second, whether the message is creating pressure to act right now, a locked account, a missed delivery, a suspicious payment that needs confirming within the hour. Third, where the links actually point, which you can usually see by hovering without clicking, or holding your finger on it a beat longer on a phone. If any of these feel off, the email goes straight in the bin, no further investigation needed.

What a Convincing Fake Actually Looks Like Now

Forget the old advice about spotting bad grammar and broken logos. Today's phishing emails are often pixel perfect copies of a real bank or delivery company's template, sometimes pulled directly from the real thing. AI has made this worse again, and I've covered some of the cybersecurity myths I keep hearing about how much that's changed the landscape. The only reliable tell left is the sender address and the destination of the links, everything else can be faked convincingly, right down to a footer that matches exactly and an unsubscribe link that even works.

The Lazy Ones Are Still Out There Too

Not every phishing attempt has had that much effort put into it, and it's worth saying so because people sometimes assume every scam email must be sophisticated now. Plenty still arrive as a bare link with almost no context, sent from an address that's obviously not who it claims to be, banking purely on volume rather than convincing any one person. It's part of a wider shift I've written about in the cybersecurity trends I'm actually seeing right now, where the sophisticated attacks and the lazy mass ones are both increasing at the same time, just aimed at different targets.

What I Do the Moment I Suspect Something's Off

I don't try to investigate a suspicious email inside the email itself. If it claims to be my bank, I open a browser and type the bank's website address in myself, or call the number on the back of my card, never a number given in the message. That single habit defeats almost every phishing attempt going, because the scam only works if you interact with it on its own terms. It takes an extra thirty seconds and it's saved me more than once from a message that looked, on first glance, completely legitimate.

What to Do If You've Already Clicked

Don't panic, and don't beat yourself up about it, it happens to careful people and it doesn't make you careless. Change the password for that account straight away, and for any other account using the same password, which is exactly why a password manager like NordPass earns its keep, since it makes giving every account its own password painless rather than a chore. Turn on two factor authentication if you haven't already. If you entered card details, ring your bank immediately using the number on your card. And if it's a work account, tell your IT contact even if it feels embarrassing, they would genuinely rather know now than find out later.

Reporting It Helps Everyone, Not Just You

Reporting a phishing email doesn't undo anything that's already happened, but it does help going forward, both for you and for whoever else was targeted in the same wave. If you want to report a phishing email you've received in the UK, Action Fraud is the place to do it, and most email providers also have a dedicated report button that feeds the same intelligence back into their filters. I report every one I get, even the obvious ones, because that reporting data is part of what makes spam filters better at catching the next wave before it lands in someone else's inbox.

Building the Habit That Actually Sticks

None of this needs to become a full time job. A five second pause before clicking anything, checking the sender, and having two factor authentication switched on everywhere it's offered will stop the vast majority of phishing attempts cold, no matter how convincing they've become. And if you're not sure where to start, my Safety Toolkit has the tools I use and recommend myself, free to browse any time.