How to Spot a Phishing Email in 30 Seconds

Key takeaways:
  • Most phishing emails can be spotted in under a minute with a few quick checks.
  • The strongest signals are the real sender address, hidden link destinations, and pressure to act fast.
  • Hover over links to see where they really go, and never open unexpected attachments.
  • Polished writing no longer proves an email is safe, so judge it on the whole picture, not grammar alone.
  • When in doubt, don’t click. Go to the company’s website or app directly to check.

We have all had this moment. You open your inbox and something looks slightly off. An email from your bank warns of a problem with your account, or tells you that you have won a prize. It feels urgent and wants you to click a link right now. So what do you do? Click, or pause for a second?

Phishing emails are one of the most common ways attackers try to trick you into giving away personal information: passwords, card numbers, or access to your device. The good news is that most attempts give themselves away, and you can usually catch them in under 30 seconds. Here is exactly what to look for.

1. Check the sender’s real email address

The first thing to check is the actual email address, not just the display name. Phishing emails often come from an address that looks close to a real one but is subtly wrong.

  • A message claiming to be from your bank might come from [email protected] instead of [email protected]. The extra words are a red flag.
  • An email that says it is from Amazon but ends in @amazonsupport.co rather than @amazon.com is not from Amazon.

2. Be wary of spelling and grammar, but don’t rely on it

Sloppy writing has always been a classic tell. A line like “Urgent! Your accout has been suspened” is a strong warning sign. That said, this signal is weakening: attackers now use AI to write clean, professional-sounding emails. So poor grammar still suggests a scam, but perfect grammar no longer proves an email is safe. Weigh it alongside the other checks.

3. Look at the greeting

Phishing emails often open with vague greetings like “Dear customer” or “Dear valued user” because the sender does not actually know who you are. A company you have a real account with will usually address you by name. A generic greeting on an “important” message is worth a second look.

4. Check the link without clicking it

Before you click any link, hover your mouse over it (on a phone, press and hold) to reveal the real destination. Attackers disguise links that look right at a glance but lead somewhere else.

A message that appears to be from PayPal might show paypal.com as the text, while the actual link points to paypa1.com, using the number one in place of the letter L. That single swapped character is the whole trick.

5. Watch for urgency and pressure

Phishing thrives on panic. Lines like “Immediate action required”, “Your account has been compromised”, or “You must update your details within 24 hours” are designed to make you act before you think. Genuine organisations rarely rush you like this. If a message insists you hurry, that pressure itself is the warning sign. You can always visit the company’s website or app directly to check whether anything is actually wrong.

6. Be careful with attachments

Unexpected attachments are a common way to deliver malicious software. Do not open an attachment unless you are genuinely expecting it from someone you trust. When in doubt, confirm with the sender through another channel before opening anything.

7. If it seems too good to be true, it is

The classic bait is the prize you never entered for: a lottery win, an unexpected refund, a large sum waiting for you. If you did not sign up for a contest, there is no prize. Legitimate companies do not hand out money out of nowhere.

What to do now

Next time an email feels off, run these checks before you touch anything. If it still seems suspicious, do not click the link or open the attachment. Open a new browser tab, go to the company’s official website or app yourself, and check your account there. If the email is a scam, report it to the real organisation and delete it.

Stay safe, stay calm

The next time a suspicious email lands, there is no need to panic. A few seconds of checking is usually all it takes. Remember the pattern: a genuine company will not pressure you into acting instantly, will not ask you to confirm passwords or full card details through an email link, and will not send you strange attachments out of the blue. Run through these checks a few times and spotting a phishing email quickly becomes second nature.

Good to know

A strong, unique password and two-factor authentication are your safety net. Even if a convincing phishing email does catch you out one day, they make it much harder for an attacker to actually get into your account.