How to Spot a Phishing Email in 30 Seconds

By EP Guard Editorial · Updated Oct 5, 2026 · 3 min read
How to Spot a Phishing Email in 30 Seconds

Phishing remains the most common way attackers break into accounts, and learning to spot a phishing email takes less than a minute once you know what to look for. This quick guide gives you a repeatable checklist you can apply to any suspicious message.

Check the sender, not just the name

Display names are easy to fake. Look at the actual email address, and watch for lookalike domains with swapped letters or extra words. Be wary of messages from free webmail addresses that claim to represent a bank or vendor. If an email appears to come from a coworker but feels odd, confirm through another channel.

Look for pressure and unusual requests

Attackers rely on urgency: accounts will be closed, invoices overdue, packages undeliverable. Requests for gift cards, wire transfers, or login details are major red flags. Legitimate organizations rarely demand immediate action through an unexpected email.

Inspect links and attachments safely

Hover over links to preview the destination, and be cautious with shortened links. Never open unexpected attachments, particularly zip files, macros, or invoices you did not request. When in doubt, type the website address yourself or use a bookmark instead of clicking.

Notice the details

Poor grammar is less reliable now that attackers use AI, so also check for generic greetings, mismatched logos, odd formatting, and unexpected context. Compare the message with previous genuine emails from the same sender if you have them.

What to do next

Do not reply or click. Report the message using your email provider’s button or your company’s security address, then delete it. If you already clicked or entered a password, change it immediately and tell IT so they can check for further compromise.

Examples of common phishing themes

Watch for fake delivery notices, password expiry warnings, shared document invitations, payroll or HR updates, and invoices from unfamiliar vendors. Business email compromise messages often appear to come from an executive asking for an urgent favor or a payment change. Each theme works because it exploits routine tasks, so training that uses realistic examples is far more effective than generic warnings.

Building a reporting habit

Make it effortless to report suspicious messages with a single button or a dedicated address, and thank people who do. Quick reports let security teams remove the same email from every mailbox and block the sender. Run occasional simulated phishing exercises, share results without blame, and celebrate improvement. Over time a culture of cautious checking becomes the strongest filter you have.

Key takeaways

  • Check the sender, not just the name: Display names are easy to fake. Look at the actual email address, and watch for lookalike domains with swapped letters or extra words.
  • Look for pressure and unusual requests: Attackers rely on urgency: accounts will be closed, invoices overdue, packages undeliverable. Requests for gift cards, wire transfers, or login details are major red flags.
  • Inspect links and attachments safely: Hover over links to preview the destination, and be cautious with shortened links. Never open unexpected attachments, particularly zip files, macros, or invoices you did not request.
  • Notice the details: Poor grammar is less reliable now that attackers use AI, so also check for generic greetings, mismatched logos, odd formatting, and unexpected context. Compare the message with previous genuine emails from the same sender if you have them.
  • What to do next: Do not reply or click. Report the message using your email provider’s button or your company’s security address, then delete it.
  • Examples of common phishing themes: Watch for fake delivery notices, password expiry warnings, shared document invitations, payroll or HR updates, and invoices from unfamiliar vendors. Business email compromise messages often appear to come from an executive asking for an urgent favor or a payment change.
  • Building a reporting habit: Make it effortless to report suspicious messages with a single button or a dedicated address, and thank people who do. Quick reports let security teams remove the same email from every mailbox and block the sender.

Frequently asked questions

Can phishing happen by text or phone?

Yes. Smishing and voice phishing follow the same patterns of urgency and impersonation.

Does multi-factor authentication help?

Yes, it greatly reduces damage, though real-time phishing kits can still trick some users.

Final thoughts

Pause, check the sender, question the urgency, and verify before you click. These simple habits stop the vast majority of phishing attempts.

Keep reading

  1. Threat Intelligence

    Professors Targeted in North Korean Espionage Emails

    Sep 26, 2026 · 3 min read
    Professors Targeted in North Korean Espionage Emails
  2. Threat Intelligence

    Agent Tesla and Formbook Hit Polish Businesses

    Oct 4, 2026 · 2 min read
    Agent Tesla and Formbook Hit Polish Businesses
  3. Threat Intelligence

    Lessons From the Fake IT Worker Hired by a Security Firm

    Oct 3, 2026 · 2 min read
    Lessons From the Fake IT Worker Hired by a Security Firm
  4. Threat Intelligence

    Kimsuky Phishing Campaign Targets University Researchers

    Sep 8, 2026 · 2 min read
    Kimsuky Phishing Campaign Targets University Researchers