Advertising disclosure: this site contains partner (affiliate) links. DAR STAR s.r.o. may earn a commission if you buy through them, at no extra cost to you. How we are funded

How to spot a phishing message

Phishing messages try to trick you into revealing a password, paying money or installing malware. They arrive as emails, text messages (sometimes called "smishing"), social-media messages or phone calls. This guide lists the most common warning signs.

Annotated mock email showing warning signs: a sender address that does not match the brand, an urgent subject line, a generic greeting, a link whose real address differs from its text, and an unexpected attachment.
The typical warning signs of a phishing email. The sender and brand are fictional. Original illustration by kinetis.online.

Warning signs

  • Pressure and urgency. "Your account will be closed today", "Payment failed – act now".
  • Mismatched sender. The display name says your bank, but the actual address is from an unrelated domain.
  • Links that do not go where they say. On a computer, hover over a link to see the real address. On a phone, press and hold the link. Look closely at the domain name, the part just before the first single "/".
  • Requests for credentials or codes. Legitimate organisations do not ask you to send passwords or one-time codes.
  • Unexpected attachments, especially archives (.zip), Office files that ask you to "enable content", or files with double extensions.
  • Generic greetings and odd wording, although modern phishing can be well written, so do not rely on spelling mistakes alone.

What to do instead

  1. Do not use the link in the message. Open the organisation's app, or type its address yourself.
  2. If a message claims to come from someone you know and asks for money, contact them through another channel you already trust.
  3. Report the message using your email provider's "report phishing" option.

If you already clicked

  1. If you entered a password, change it straight away on the real site, along with any other account where you used the same password.
  2. Turn on two-step verification for that account.
  3. If you shared card or bank details, contact your bank immediately using the number on your card.
  4. If you opened an attachment, run a full scan with your security software and keep your system updated.
  5. Consider reporting the incident to your national cyber-security or police reporting service.

Sources

  • ENISA, phishing and social-engineering awareness material. enisa.europa.eu
  • UK National Cyber Security Centre, "Phishing: spot and report scam emails, texts, websites and calls". ncsc.gov.uk
  • Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB), Czech Republic. nukib.gov.cz

This page contains no partner links. Illustrations are original works by kinetis.online.