Phishing has gotten harder to spot on sight. The days of obvious misspellings and broken logos are mostly gone — well-run phishing campaigns now use scraped brand assets, correct grammar, and sometimes AI-generated writing that reads naturally. What hasn't changed is the underlying mechanics of the attack, which is where the more reliable warning signs actually live.

What Phishing Is Actually Trying to Do

Every phishing attempt has the same basic goal: get you to take an action you wouldn't take if you had accurate information. That action is usually one of a few things — entering your password on a fake login page, opening an attachment that installs malware, approving a fraudulent payment or transfer, or replying with sensitive personal or financial information. Everything else in the message (urgency, authority, fear) exists to rush you past the moment where you'd normally stop and verify.

Signs in the Sender

  • Check the actual email address, not just the display name. "Amazon Support" as a display name can be attached to any email address at all — look at what's actually after the @ symbol.
  • Look-alike domains. Attackers register domains that look correct at a glance: micros0ft-support.com, paypal-secure-login.net, or a company name with an extra word tacked on. Legitimate companies communicate from their actual domain.
  • Unexpected contact for the claimed relationship. A message claiming to be from a service you've never used, or a bank you don't have an account with, is an immediate red flag.

Signs in the Message

  • Artificial urgency. "Your account will be suspended in 24 hours," "Unusual sign-in detected — verify now," or "Payment failed — update immediately." Legitimate account issues are rarely this time-pressured, and companies typically give you access to resolve issues by logging in directly rather than through an embedded link.
  • Requests for information a legitimate sender wouldn't need to ask for. Banks and most services never ask you to email or text your full password, PIN, or one-time verification code.
  • Generic greetings on messages that claim to be personal or urgent. "Dear Customer" or "Dear User" on a message claiming your specific account has a problem is a mismatch worth noticing — though sophisticated attacks increasingly do personalize the greeting, so this sign alone isn't conclusive.
  • Mismatched tone or formatting. Logos that look slightly off, unusual fonts, or a layout that doesn't quite match the company's normal emails.

On desktop, hover your mouse over a link (without clicking) and look at the URL preview that appears, usually in the bottom corner of the browser or email client. On mobile, a long-press on a link often shows a preview of the destination URL before you commit to opening it. Compare the actual destination against where the message claims it will take you — a link labeled "Sign in to your account" that actually points to an unrelated domain is a clear warning sign.

A note on shortened links

URL shorteners (bit.ly, tinyurl, and similar services) hide the true destination and are commonly used in both legitimate marketing and phishing. If a shortened link arrives in an unsolicited or urgent-sounding message, treat it with extra caution — you can use the shortening service's own "preview" feature (where available) to see the full destination before clicking.

Signs on a Fake Website

  • Check the address bar carefully once you land on a page, not just the link you clicked. Look for the correct domain, not just "https" and a padlock icon — phishing sites can and do use valid HTTPS certificates, since certificates only confirm an encrypted connection, not that the site is legitimate.
  • Login pages that ask for unusual extra information beyond your normal username and password, such as a full Social Security number or complete card details on what should be a simple sign-in screen.
  • Broken internal links or missing pages elsewhere on the site, which is common on quickly assembled fake sites that only fully build out the one page they need.

What to Do If You're Not Sure

Instead of clicking a link in a suspicious message, navigate to the company's website directly by typing the address yourself or using a bookmark you've saved previously, then check your account status from there. If the message claims to be urgent, a legitimate company will almost always still show the same issue when you log in independently. For messages claiming to be from a specific person, verify through a separate channel — a phone call to a known number, not one provided in the suspicious message itself.

If You've Already Clicked or Entered Information

  1. Change the password for the affected account immediately, and for any other account where you reused the same password.
  2. Enable multi-factor authentication on the account if it isn't already active.
  3. If financial information was entered, contact your bank or card issuer to flag the exposure and monitor for unauthorized activity.
  4. Report the phishing message to your email provider (most have a "Report phishing" option) and to the company being impersonated.

Acting quickly matters more than feeling embarrassed about it — phishing campaigns are specifically engineered to fool careful people, and reporting the incident promptly meaningfully reduces the damage.

Frequently Asked Questions

Can a phishing email really look identical to a real one?

Yes. Attackers can copy logos, formatting, and writing style directly from real company emails. This is exactly why sender-address verification and link-destination checking matter more than visual polish when judging whether a message is legitimate.

Does having HTTPS and a padlock icon mean a website is safe?

No. HTTPS only confirms the connection between your browser and the site is encrypted — it says nothing about whether the site itself is trustworthy. Phishing sites frequently use valid HTTPS certificates.

Why do phishing messages create urgency?

Urgency is designed to short-circuit careful thinking. When you feel rushed, you're less likely to pause and verify a sender's address or a link's real destination — which is exactly the moment where most phishing attempts would otherwise fail.

MyAVFee Editorial Team

Our editorial team writes explanatory technology and security guides for general readers, independent of any software vendor.