How to recognize phishing

Three checks catch most phishing: who really sent it, where the link really goes, and what the message is actually asking you to do. The advice to look for bad spelling is obsolete - modern phishing is well written, and grammar is no longer a signal.

What to check, in order

The reliable signals are structural, not stylistic. A well-resourced attacker will write flawless Slovak, use correct branding and get the tone right. What they cannot easily fake is the sending domain, the link destination, and the fact that the request itself is unusual.

Check the sender, not the display name

The display name is free text. Anyone can set theirs to your CEO or to a bank. The domain after the @ is the part that costs money and leaves a trail, so that is the part to read.

  • Expand the sender to see the full address. On mobile clients the domain is often hidden behind a friendly name by default.
  • Read the domain right to left, starting from the final dot. An address at bank.secure-login.example is not the bank - it is the example domain.
  • Watch for lookalikes: a swapped letter, an added hyphen, .co instead of .com, or a Cyrillic character that renders identically to a Latin one.
  • Be suspicious of a reply-to address that differs from the sender address, which is how conversation hijacking usually shows itself.
  • Remember that a genuine domain does not prove a genuine sender: a compromised supplier mailbox passes every sender check there is.
  • On a computer, hover over the link and read the destination in the status bar before clicking anything.
  • On a phone, press and hold the link to preview the URL rather than tapping it.
  • Read the domain, not the path. Anything can appear after the slash - the part immediately before the first single slash is what matters.
  • Treat shortened links as unknown. A shortener hides the destination entirely, and legitimate corporate email rarely needs one.
  • Be wary of a QR code in an email or an unexpected letter - it exists precisely to move you to a device with weaker filtering.
  • If a link opens a login page, stop. Navigate to that service yourself instead and check whether the same notification is waiting there.

Check what it is asking for

Channel and sender can both be faked convincingly. The request itself is much harder to disguise, because the attacker needs a specific action and that action is always one of a short list.

  • Credentials, a card number, or a one-time code. No bank, no IT department and no service will ever ask for these by message or phone.
  • A change of bank details on an invoice or a payroll record. Always verify by calling a number you already had, never one from the message.
  • An approval prompt you did not trigger. Deny it and report it - see MFA fatigue for why repeated prompts are an attack in progress.
  • Urgency attached to any of the above. The deadline exists to remove the pause in which you would otherwise check.
  • Secrecy. A request not to discuss it with colleagues is a fraud indicator on its own.

Worked examples of these patterns are in phishing email examples. If a message already got past you, I clicked a phishing link covers what to do next, and the underlying definition is in what is phishing.

Next step

Ready to measure your phishing and training program?

Book a demo and see how PhishGun can support your simulation and training program, reporting needs, and compliance evidence.