Received an email from your bank threatening to close your account, unless you immediately log in and change your password? This is a common method used by scammers to fish for information.
At first glance, these emails can seem quite convincing, but if we look a little closer, we may be able to tell whether they are genuine or not.
In this short lesson, you will learn about some of the signs that may reveal an email phishing attempt.
The classic signs of phishing
Your name is missing
In spearphishing or whaling attacks, the attack is targeted and the scammer will address the intended victim by name and title. But most phishing emails are generic, and mailed to thousands of recipients, so they rarely address the person by name.
Instead, they may use generic terms and greetings, such as:
- Dear customer
- Mr./Mrs.
- To whom it may concern
Language
Scammers may not speak your language, and AI tools now let them write in yours with near-native fluency. The old tell of awkward machine-translated phrasing like: “To confirm account of yours, click suddenly this link” , still shows up, but is now far less common.
The language marker that still works is the fit question: does the content match what you have come to expect from that source?
Check the tone, the specific details, and whether the request makes sense in context. An email that is grammatically flawless but references a project you don’t recognise, or asks you to skip a step you’d normally follow, deserves a second look.
Sender’s email and display name
If you receive an e-mail that appears to be from HSBC but the sender’s address shows up as roginator96@hotmail .com, a scammer is at work. That’s the easy version.
The harder version, and the one that’s getting more common, is an address that looks almost right: alerts@hsbc-verify .com, support@hsbc0 .com, or a domain where one letter has been swapped for a similar character. AI tools can now generate thousands of these lookalike domains in minutes, like the one below which could be used to scam users of the blog platform Blogger.

Also keep in mind that the name shown in your inbox (“PayPal Customer Service,” “Your CEO,” “IT Support”) is just a label. The attacker can set it to anything they want while sending from a completely different address. On a phone, most inboxes hide the actual address and show only the name, which is exactly why this works.
To keep yourself safe from these attacks, tap and hold (on mobile) or hover the mouse pointer on the sender to reveal the full address, every time. Then ask yourself these three questions:
- Does the domain match the organisation’s real domain, letter for letter?
- Has this person or company used this address before?
- Does the Reply-To address match the From address?
If you answer ‘no‘ to any of these, or if you are unsure, treat the email as untrusted.
Attachments
We still send documents by email, and the request itself often looks completely normal: a spreadsheet to fill in, an invoice to review, or a PDF to sign. The problem is that the file you open may not be what it claims to be.
Attachments are no longer the main vector, but they haven’t disappeared. Malicious emails are more likely to use links rather than files, but attachments remain a reliable delivery method for the most targeted attacks.
A good rule of thumb here is to treat all attachments as suspicious until you are certain the sender is who they claim to be. If you are unsure, it is better to spend 30 seconds calling the sender to verify the message than to walk straight into a trap.
Links
Checking links on your PC is usually easier than on mobile.
The trick is to hover above the link with your mouse pointer to see where it goes. If you receive an e-mail from the bank, asking you to login to accept your car loan, but the link goes to an unknown website such as greenpenguins .club or hsbc-verify.com, that is a sure sign of phishing.
Mobile is where most people get caught. With only a small screen and a truncated address bar, it’s easy to click while distracted. On a phone, you can’t hover, but you can do the equivalent: press and hold the link for a couple of seconds. A preview will appear showing the full URL.
If you are at all unsure, open the official app or website. If the email claims to be from your bank or delivery company, ignore the link. If the message is real, you will find it again in the official channels.
Shortened links
You have probably seen plenty of these before, both on social media and in emails. Bitly and TinyURL are among the most widely used link shorteners. They are used by both legitimate businesses and spammers. Therefore, it is a good idea to find out more about the link before clicking on it.
Unshorten.me is one of several services you can use to discover where these shortened links actually lead.
QR Codes
QR codes are being used in an increasing number of areas. Restaurant menus, payment solutions, and authentication are just a few examples. They are convenient, but can also easily be exploited by scammers.
For instance, hackers and scammers might send you an email containing a QR code and ask you to scan it, often under the pretext that you need to verify your identity or confirm a login. The malicious QR code will typically take you to a fake website that looks like your bank or a trusted service, where you’re asked to enter your login details, or it may prompt your phone to download an app.
But, scammers don’t just send QR codes via e-mail. You could also run across them in the physical world. Scammers can place their own QR code sticker over a legitimate one, on a parking meter, restaurant menu, or fuel pump.
What to do:
- Preview before you open. Most phone cameras and scanner apps show the web address before it loads.
- Investigate the link that the QR code leads to. Does it match the company you expect?
- If it prompts an app download, cancel. A legitimate bank or delivery service won’t ask you to install an app via a QR code.
Domains and subdomains
A website can have many subdomains, just as a company has multiple departments. One example is the online newspaper Der Spiegel (spiegel .de), which has its own sports data section on a subdomain with the web address sportdaten.spiegel .de.
Take note of what the latter address looks like before moving on.
Guidelines: read the address from right to left.
The part that actually matters (the main domain) is the bit just before the ending (.de, .com, .co.uk). Now look at these two addresses:
- wpb.hsbc.co.uk
- wpb-hsbc.co.uk
The first one is a real subdomain of HSBC. The second is a completely different domain that anyone can register for a small fee. The only difference is a dot versus a hyphen, and it’s easy to miss.
You may also come across examples that look like this: account-security.microsoft.com.verify-login .net
Your eye jumps to microsoft.com and stops. But if you remember to read the site address fromright to left:, you’ll see that the domain is verify-login .net. The microsoft .com portion is just a label the attacker put in the middle to make it look familiar.
What to do:
- Indentify the real domain (the part just before .com, .co.uk, etc.).
- Ask yourself: “Does the domain match the business? And is this the address that the sender usually sends from? “
- If it’s not, or if you’re not sure, don’t click.
Results
Well done!
Not quite there yet. You might want to read the lesson again.




