The sender name can be misleading
Email apps often show a display name more prominently than the actual email address. A scammer can label an account “Medicare,” “Apple Support,” or a coworker’s name.
View the full sender address when the message matters.
Urgent account problems are common bait
Phishing messages claim a password expired, payment failed, package is held, account was suspended, refund is available, or suspicious activity requires immediate sign-in.
The story is designed to prevent you from slowing down.
Links can hide the real destination
A button can say “Secure My Account” while leading somewhere unrelated. On a computer, hovering may reveal the destination, but even that does not make a suspicious link worth visiting.
Use your own bookmark or type the known site address instead.
Attachments can be dangerous
Unexpected invoices, receipts, legal notices, shared documents, and security reports can contain malicious files or links.
If you were not expecting the attachment, verify the sender through another channel.
Professional formatting proves little
Scammers can copy logos, signatures, legal disclaimers, and email templates. AI can also improve grammar and personalization.
Judge the action requested and verify independently.
Report and delete
Use the provider’s phishing-report tool when available and report scams to the FTC when appropriate.
If you entered credentials, change them through the official service and review the account for unauthorized changes.
Quick Reference
| Email signal | What to do |
|---|---|
| Unexpected login request | Open service independently |
| Attachment you did not expect | Verify sender separately |
| Urgent payment demand | Do not pay from email link |
| Display name looks familiar | Check full sender address |
| Link text looks official | Do not rely on visible text |
| Asks for code/password | Do not provide it |
Check the Red Flags
Use the Scam Red-Flag Checker to review common warning signs without entering sensitive account information.
Read the real sender address, not only the display name
An email can display a trusted company or person’s name while the underlying address belongs to someone else. Expand the sender details when the message involves money, passwords, or account changes.
Even a plausible address is not enough by itself, so continue verifying through the official site or app when the request is important.
Hovering or previewing a link can help, but it is not required
On a computer, you may be able to point at a link and see its destination before clicking. On a phone, pressing and holding may show a preview. These techniques can be useful, but you do not need to inspect a suspicious link at all.
The safer habit for important accounts is to ignore the email link and navigate independently.
Treat unexpected attachments as separate risks
Invoices, shipping notices, scanned documents, and account forms can arrive as attachments. A familiar filename does not prove that the attachment is safe.
If you were not expecting the file, verify with the sender through another channel before opening it.
Professional design is easy to copy
Logos, colors, signatures, legal language, and polished formatting can all be copied from a real company. Good grammar does not make an email trustworthy, and poor grammar is not required for a scam.
Judge the request by what it wants you to do and whether you can verify the issue independently.
Use time and independent verification as your advantage
The person trying to scam you usually wants speed. Your advantage is that you can stop. You can hang up, close the message, call someone you trust, and verify the claim through an official route you choose yourself.
You do not have to identify the exact scam before protecting yourself. If an unexpected contact wants money, sensitive information, a security code, remote access, or secrecy, stop the interaction and verify before doing anything else.
Use the same verification routine every time
A consistent routine is easier to remember than a different response for every scam. Stop the interaction, identify what the person is asking for, and verify through a contact method you choose. Do not let the caller, text, or email supply the only route back to the organization.
For family emergencies, call the relative or another family member directly. For financial accounts, use the official app, card, or statement. For government or benefit questions, use the agency’s known website or published contact information.
Protect verification codes and remote access
One-time codes, password-reset links, security approvals, and remote-access permissions can give another person a direct path into an account or device. Treat them as highly sensitive even when the person asking sounds professional or urgent.
If you did not start the sign-in or support session yourself, do not approve it. A surprise request for a code or remote-control software is a reason to stop and verify independently.
Do not make payment while someone is pressuring you
Scammers often stay on the phone or in the chat while they tell you exactly how to buy gift cards, move money, use cryptocurrency, or complete a transfer. That constant contact prevents you from getting another opinion.
End the conversation before taking any payment step. A legitimate bill or emergency can be checked through another source, and a genuine organization will still be there after you verify the request.
Review what information may already be public
A caller knowing your name, address, relatives, former employer, or other personal details does not prove that the story is real. Some information is public, commercially available, or exposed in old data breaches.
Use privacy settings on social media where appropriate, but do not rely on secrecy alone. The stronger habit is independent verification whenever an unexpected contact asks for money, account access, or sensitive information.
Keep a short response script near the phone
If pressure makes it hard to think, keep one sentence ready: “I do not make payments or give account information on unexpected calls. I will contact the organization myself.” Then hang up.
You do not need to debate, accuse, or explain. A simple script gives you permission to end the interaction and move to a safer verification process.
Sources
Frequently Asked Questions
Can phishing emails have perfect grammar?
Yes. Grammar is not a reliable test.
Can a phishing email come from a real account?
Yes. Compromised accounts can send malicious messages.
Should I hover over links?
It can reveal a destination on desktop, but the safer response to a suspicious message is not to use the link at all.
What if an email says my password expires today?
Open the official service directly and check account settings there.
What if I already entered my password?
Change it immediately through the official service, review MFA and recovery settings, and check for unauthorized activity.
Keep this visual on Pinterest
Save the infographic so you can return to the checklist or comparison when you need it.
Save on Pinterest