Technology

How to Spot a Phishing Email

The signs experienced security teams look for — header tells, link tricks, urgency cues — and the simple habits that block almost every attempt.

By NewsClair Editorial TeamTechnology 4 min read 863 wordsPublished June 10, 2026

Researched and written with AI assistance, reviewed by the NewsClair editorial team.

A laptop showing an email inbox with a suspicious message flagged at the top.
A laptop showing an email inbox with a suspicious message flagged at the top.

Published .

Contents(6 sections)
  1. 1. What phishing actually is
  2. 2. What to check, in order
  3. 3. Common pretexts in 2026
  4. 4. When in doubt, go to the source directly
  5. 5. Defenses that protect you even if you slip
  6. 6. If you clicked something

Phishing is still the most common entry point for cybercrime against ordinary households. The FBI's Internet Crime Complaint Center (IC3) reports phishing as the most-reported cybercrime type year after year, well above ransomware or identity theft. The good news is that the techniques don't change much — a small set of checks catches the vast majority of attempts.

This guide walks through what phishing looks like in 2026, the specific tells that a message is not what it claims to be, and the few habits that protect you even when an attack slips past the obvious checks.

What phishing actually is

Phishing is any message that impersonates a legitimate sender to get you to click a malicious link, open a malicious attachment, hand over a password or one-time code, or send money. It arrives by email, SMS ("smishing"), voice call ("vishing"), and increasingly in messaging apps and direct messages on social platforms.

The most damaging version is "spear phishing," which targets a specific person and uses real details — your boss's name, a real invoice number, a service you actually use — to look legitimate. Generative AI has made spear phishing easier to produce at scale, which is one reason the volume has risen.

What to check, in order

The single highest-value check is the sender's actual email address (not the display name). Click or hover on the From field to see the real address. "Amazon Support <support@amaz0n-billing.com>" is the kind of mismatch that gives away most attempts. On mobile, this is harder to see — long-press the sender on most clients to reveal it.

Second, hover over every link before clicking. Real URLs and displayed text often don't match in phishing. Look at the actual domain at the start of the URL: "amazon.com" is legitimate, "amazon.com.account-secure.io" is not — the real domain in that example is "account-secure.io."

  • Real sender domain (not just the display name)
  • Actual link destination (hover before clicking)
  • Spelling and grammar — though AI has made this less reliable
  • Urgency cues ("Verify within 24 hours or your account will be locked")
  • Requests for credentials, codes, or payment outside the normal channel

Common pretexts in 2026

The most common pretexts haven't changed much: package delivery problems (USPS, FedEx, UPS), bank or credit-card fraud alerts, IRS or tax-refund messages, streaming-service billing issues, password resets you didn't request, and Microsoft or Google "account security" warnings. Each impersonates a service you probably use.

A newer category: "MFA fatigue" attacks where attackers spam you with multi-factor authentication prompts hoping you'll approve one out of frustration. If you didn't initiate a login, deny the prompt — every time.

When in doubt, go to the source directly

If a message says there's a problem with an account, do not click the link in the message. Open a new browser tab, type the company's URL yourself (or use a bookmark), and log in normally. Legitimate alerts will appear in the account; phishing pages will not exist there.

For phone calls claiming to be from your bank, hang up and call the number on the back of your card. Caller ID can be spoofed; the number you dial yourself cannot.

Defenses that protect you even if you slip

Two safeguards matter more than any other and should be set up before you need them. First, use a password manager so every account has a unique password — that way, a stolen password from one site cannot be reused on others (credential stuffing). Second, turn on multi-factor authentication (MFA) for every important account, preferring app-based or hardware-key methods (which are phishing-resistant) over SMS where possible. CISA, the federal cybersecurity agency, considers MFA the single highest-leverage individual control.

Together, a password manager plus hardware-key MFA on email and financial accounts defeats the vast majority of real-world phishing — even when the user is fooled.

If you clicked something

Most clicks alone are recoverable. If you entered a password, change it immediately on the real site and anywhere else you've reused it. If you entered an MFA code, treat the account as compromised — change the password, revoke active sessions, and review recent login activity. For financial accounts, contact your bank's fraud line. Report the phishing message to the company being impersonated and to reportphishing@apwg.org or via the FTC at reportfraud.ftc.gov.

SignalPhishingLegitimate
Sender domainMisspelled or unrelatedMatches the company's real domain
Link destinationDifferent from displayed textMatches displayed text and real domain
Urgency"Within 24 hours or else"Reasonable timeframe, no pressure
Credential requestsPassword / code via linkLog in directly at the site you know
AttachmentsUnexpected ZIP, ISO, or macro-enabled docRarely needed in routine messages
Red flags vs legitimate behavior

Frequently asked questions

How can I tell a fake login page from the real one?
Check the URL bar carefully and look for a subtle domain swap. Bookmark login pages for important accounts and use the bookmark rather than search results.
Is SMS-based MFA worth using?
It's better than nothing, but it's vulnerable to SIM-swap attacks and certain phishing. Prefer an authenticator app or a hardware security key for high-value accounts (email, banking).
Are password managers safe?
Reputable password managers use strong encryption and have never been the weak link in major breaches in recent years. The much bigger risk is password reuse across sites.
What if a phishing email got through to my work account?
Most workplaces have a "Report Phishing" button in their email client. Use it instead of just deleting; that lets IT block the sender for everyone.

How we researched this

This article was researched and drafted with AI assistance using primary sources — regulator publications, official guidance, peer-reviewed research, and reporting from established outlets — and reviewed by the NewsClair editorial team before publishing. Where data shifts quickly, we date each claim. This article does not provide individualized medical, legal, or financial advice.

Sources

  1. Recognize and Report Phishing Cybersecurity and Infrastructure Security Agency (CISA)
  2. Multi-Factor Authentication CISA
  3. Internet Crime Report FBI Internet Crime Complaint Center (IC3)
  4. How to Recognize and Avoid Phishing Scams Federal Trade Commission

Related reading

Found this useful? Share it with a friend.

This article is informational and not a substitute for professional advice. NewsClair does not provide medical, legal, or financial services.