The One Habit That Stops Me Falling for Phishing Emails
The One Habit That Stops Me Falling for Phishing Emails
I've read a lot of guides on spotting phishing emails, and most of them give you a long checklist. Check the sender address, look for spelling mistakes, check the urgency, check the links, check the attachments. It's good advice, but in the moment, standing in a queue with my phone in one hand and a coffee in the other, I'm not running through a five-point checklist. I've got one habit that catches almost everything, and I built the rest of my defences around it rather than trying to remember a list.
Why I Stopped Trusting the Sender Name
The sender name is the first thing most people look at, and it's also the easiest thing to fake. Any email client will display whatever name the sender wants next to the actual address, so "Royal Mail" or "HMRC" or your own bank's name can sit right above an address that has nothing to do with them. I used to glance at the display name and move on. Now I don't trust it at all, because it tells you what the sender wants you to believe, not who they actually are.
That shift mattered more than anything else I changed. Once I stopped treating the display name as evidence, the rest of my approach got much simpler, because there was only one thing left worth checking properly.
The One Thing I Check Before I Click Anything
Before I click a link or open an attachment in any email that's asking me to do something, I check where the link actually goes. On a phone, that means holding the link down until a preview address pops up. On a laptop, it means hovering over it and reading the address that shows in the corner of the screen, not the text of the link itself. If the visible text says "royalmail.com" but the actual address is something like royalmail-redelivery.info or a string of random characters, that's the whole story right there. I don't need to check spelling or tone or urgency after that, because a mismatched link address is close to a guarantee.
This one check does more work than any other single thing I do, because it doesn't depend on the email looking convincing or not. A well-written scam email with a mismatched link still fails the check. A badly-written genuine email still passes it. Everything else is secondary to this.
What Convinced Me This Habit Actually Matters
The moment this really landed for me was an email that looked, on every visible measure, completely genuine. Correct logo, correct tone, no spelling mistakes, referencing a real delivery I was actually expecting. If I'd been judging it on how convincing it looked, I'd have clicked without a second thought. But the link, when I checked it, went to a domain I didn't recognise at all, nothing close to the courier's actual site. That's when it clicked for me that the quality of a phishing email tells you almost nothing about whether it's real. The link does.

I've written before about how bad grammar no longer gives these messages away, and this is the other half of that same problem. As scam emails get better written, checking how something looks or reads becomes less and less reliable, and checking where it actually points becomes the thing that still works.
The Other Habits I've Built Around It
The link check is the core of it, but I've added a few smaller habits on top that catch the cases where a link check alone isn't enough. I never enter a password by following a link in an email, even if the link checks out, because I'd rather type the site's address in myself or use a saved bookmark. I look at whether the email is addressed to me by name or with something generic like "Dear Customer," since genuine companies I have accounts with almost always use my actual name. I also treat urgency as a signal to slow down rather than speed up, since "your account will be suspended in 24 hours" is doing exactly the job it's designed to do if it gets me clicking fast. I also use a password manager for logins, since it simply will not offer to autofill my details on a lookalike site even if everything else about the email fooled me.
None of these are complicated, and none of them require remembering a long list under pressure. They're small, specific checks that layer on top of the main one, rather than a separate system I have to run through every time.
What I Do When I'm Not Sure
Even with all of that, some emails still leave me genuinely uncertain, usually because the sender is a company I do actually deal with and the request isn't obviously outlandish. In those cases, I don't click anything in the email at all. I open a browser separately, go to the company's site directly, or call them using a number I already have on file, not one from the email itself, and ask them directly whether they sent it. It takes an extra two or three minutes, and it has never once been a wasted two or three minutes.
That's really the whole approach. One habit that catches most things on its own, a few smaller habits that catch what it misses, and a fallback for the cases where I'm still not certain. If you want the fuller version of what I've put in place across every account, I've pulled it together in a free Safety Toolkit, and Action Fraud has clear guidance on reporting phishing attempts if you've had one land in your own inbox.
