How to Spot a Phishing Email (With Examples)
A good phishing email is built to look completely real, the right logo, a familiar sender name, a believable request. But almost every phishing email leaves fingerprints. Once you know the four places to look, you can spot them in seconds.
This guide walks through the anatomy of a phishing email, two worked examples, and a quick checklist you can use every time.
The four places to check
Before you click or reply, run your eyes over these four things:
- The sender: does the actual email address (not just the display name) match the real organization? Hover or tap to reveal it.
- The greeting: real companies that know you usually use your name, not "Dear Customer" or "Dear User".
- The message: is it creating urgency, fear, or a reward to make you act fast? That pressure is the tell.
- The links and attachments: hover over links to preview the real destination, and be wary of unexpected attachments.
Your 30-second phishing checklist
When in doubt, run this quick check:
- Do I actually have an account or a relationship with this sender?
- Does the real email address match the organization?
- Is it rushing me or threatening a consequence?
- Where does the link really go when I hover over it?
- When unsure, go to the site directly instead of clicking, or ask your IT/security team.
Real phishing emails, annotated
Illustrative training examples. Notice how the real sender address and the details give each one away.
Example 1: fake "unusual sign-in" alert (credential phishing)
We detected an unusual sign-in to your Microsoft 365 account from a new device (Windows - Kyiv, UA).
If this was not you, your account may be compromised. To keep your account active, you must verify your identity within 24 hours or your account will be temporarily suspended.
Verify my account- Check the real sender address, not the name. The display name says "Microsoft account team", but the actual address is no-reply@microsoft-account-verify.com. The real domain would be microsoft.com or accountprotection.microsoft.com, not a look-alike like microsoft-account-verify.com.
- Urgency and a threat. "Within 24 hours" and "temporarily suspended" exist to make you act before you think.
- It wants you to verify through a button. A genuine provider tells you to review activity by signing in yourself, never by clicking a "verify" button in an email. Hovering over the button reveals a non-Microsoft link.
Example 2: fake overdue invoice (payment / BEC lure)
Please find attached invoice #INV-90427 for $4,820.00, now 15 days overdue.
To avoid a late fee and a service interruption, submit payment today. Note our updated remittance and bank details are included in the attached file.
📎 Invoice_90427.html- Unfamiliar sender domain. billing@acme-invoices-portal.com is not your real vendor’s domain. Attackers register look-alike "portal" and "billing" domains.
- The attachment is not what it claims. It is presented as an invoice but the file is Invoice_90427.html, a web page, not a PDF. HTML attachments are a common way to open a fake login or run a script.
- "Updated bank details" plus urgency. A new account number combined with pressure to pay today is the classic signature of invoice fraud and business email compromise. Verify any bank-detail change by phone first.
Test yourself
Put your new skills to the test with a free quiz.
Frequently asked questions
How do I check where a link really goes?
On a computer, hover your mouse over the link (without clicking) and look at the address shown at the bottom of the screen. On a phone, press and hold the link to preview it. If it does not match the real site, do not click.
What if the email looks exactly like my bank?
Looks can be copied perfectly. Never log in through an emailed link. Open your browser and type the bank’s address yourself, or use their official app, and check for any real alerts there.
Is it safe to open attachments?
Only if you were expecting the file from a known sender. Unexpected attachments, especially HTML, zip, or files asking you to "enable content", are a common way to deliver malware.