The Phishing Myths I Still Hear All the Time
I get asked about phishing emails more than almost anything else I deal with. Everyone's heard of them by now, but the myths around what they actually look like and who they actually target are still doing a lot of damage, and they're the reason so many otherwise careful people end up caught out. So let's clear a few of them up properly.
Every one of these myths made sense once. The trouble is the scams moved on years ago and a lot of the advice floating around never caught up with them. I want to go through the ones I hear most often, why each one is more dangerous than it sounds, and the one question I actually ask myself now instead of ticking off a checklist.
The Myth That Phishing Emails Are Badly Written
That was true a decade ago. These days the scam emails landing in inboxes are polished, on brand, and often better formatted than the genuine emails they're copying. I've seen fake delivery company and bank messages that used the correct fonts and logos down to the pixel, right along with a footer that matches and an unsubscribe link that even works. Spelling mistakes are a nice bonus clue when you happen to get them, but you cannot rely on their absence to mean an email is safe anymore. What actually gives a phishing email away is the sender's domain, the urgency baked into the subject line, and a link that doesn't quite match where it claims to go. I go through the red flags I always check first in a lot more detail if you want the full checklist rather than just this one myth.
The Myth That Only Older People Fall For This
I wish this one was true, because it would make my job a lot easier. In reality I see just as many students and young professionals get caught out, usually because they're moving fast on a phone between apps and don't give a message a second look before tapping it. Scammers know this, which is part of why so many phishing attempts now arrive as texts and app notifications rather than plain emails sitting in an inbox. Confidence with technology doesn't protect you from a message specifically designed to make you panic first and think second. If anything, I've noticed the newer wave of AI-written scams and deepfake voice notes hits younger people just as hard, simply because that's where they spend most of their time and attention.
The Myth That My Email Provider Catches Everything
Spam filters are genuinely good these days, and they do stop a huge volume of junk before it ever reaches you. But treating your inbox filter as a complete security system is where people come unstuck. New scam domains get registered every single day, faster than any filter can realistically catalogue them, so a fresh phishing campaign will often slip through in its first few hours simply because nothing has flagged it as suspicious yet. A password manager like NordPass helps here too, because it won't autofill your login details on a lookalike site even if the email itself gets past your filter completely. That mismatch, where your saved login just doesn't appear, is often the first real sign something's wrong.
The Myth That I'm Safe As Long As I Don't Click Anything
Mostly true, and it's still the best rule of thumb I can give anyone in a hurry. But it's not quite the full picture. Some phishing emails use tracking pixels that confirm your address is active the moment you open them, even without a click anywhere in the message, and that alone is enough to get you added to a list for the next wave of attempts. It's a good reason to turn on two factor authentication on your main accounts regardless, so that even if a password does leak somewhere down the line, it isn't enough on its own to get anyone into your account. Belt and braces, as my old boss used to say, and it costs you nothing once it's set up.
The One Question I Ask Instead of Chasing Red Flags
Forget trying to spot bad grammar or a slightly-off logo. I ask myself one question with every unexpected email: would this organisation actually contact me this way, about this, right now? A bank will never ask you to confirm your password by email. A delivery company won't threaten to bin your parcel in six hours flat. Once you start asking that question automatically, most phishing emails fall apart in about two seconds flat, no checklist required. If you're ever unsure, report it to Action Fraud rather than just deleting it and moving on, since that helps build the wider picture that stops the next wave landing in someone else's inbox too.
Where This Leaves You
None of these myths are stupid to believe, they're just out of date, and the scams have quietly moved on while the old advice stayed still. If you want a proper walkthrough of every safeguard I recommend in one place, my Safety Toolkit covers all of it in plain English, free to browse any time. And if a message ever lands in your inbox that you're genuinely not sure about, get in touch with me directly and I'm always happy to take a look.
