How to Spot and Avoid Phishing Emails and Texts

Tap an item for practical ways to recognize and avoid a phishing email or text before it costs you anything.

What phishing actually is

Phishing impersonates a trusted organization β€” a bank, delivery company, or government agency β€” to trick you into handing over personal or financial information. Attackers often copy the real organization's design almost exactly in a fake email or website.

Check the sender and URL carefully

Look for a domain that's been altered just slightly, like yourbank-secure.com instead of yourbank.com. Hovering over a link on desktop (or long-pressing it on mobile) shows you where it actually leads before you tap it.

Be wary of urgent, pressuring language

Phrases like "your account will be suspended" or "verify within 24 hours" are a classic manipulation tactic meant to rush you past careful thinking. A legitimate organization doesn't typically pressure you into clicking immediately.

Types of links you should never click

Never click a link that launches an attachment, asks you to type login credentials directly, or hides its destination behind a shortened URL β€” unless you're certain of the source.

Go straight to the official app or site instead

If a message looks suspicious, don't click the link inside it. Open your bookmarked official site or the official app directly and check there instead β€” that's the safest way to confirm whether something is real.

Think before opening an attachment

An unexpected invoice, shipping notice, or zip file is a common way to deliver malware, so don't open one unless you're confident about who sent it.

Report a suspected phishing email or text

Rather than just deleting a suspicious message, use your email provider's spam or phishing report feature, or report it to your country's cybersecurity or consumer protection agency β€” doing so helps prevent further damage to others.

Why phishing never seems to go away

Phishing isn't a technical hack β€” it preys on trust and a moment of distraction, so no amount of security software makes it disappear entirely. Attackers impersonate organizations that almost everyone deals with regularly, banking on the small chance you'll let your guard down, which is why building a habit of checking the sender and link is the most reliable defense.

Not every phishing attempt looks the same

Mass phishing casts a wide net with generic messages sent to huge numbers of people, but spear phishing targets a specific individual using real details about their job or coworkers, making it far more convincing. If you receive a message that references accurate personal or work details, treat it with even more suspicion and verify through a separate channel before responding.

Frequently Asked Questions

Is it dangerous if I just opened a phishing email without clicking anything?

Simply opening and reading the message carries low risk on its own. But if you ran an attachment or entered information on a linked page, change the password on that account right away and run a security check.

What should I do if I already clicked a link and entered some information?

Change the password for that account immediately, turn on two-factor authentication if it isn't already on, and keep an eye on the account for any unfamiliar activity over the following days.