Spotting a phishing attempt in five seconds
ost phishing emails fail three quick tests. If you can check the sender, peek at the link, and smell the urgency in five seconds, you’ll dodge almost all of what actually hits normal inboxes.
Five-Second Phishing Filter
- Five-second filterask
- Check senderpractice
- Peek at linkfails?
- Spot urgencyfails?
- Ignore official-lookingbuild habit
- Practice own inbox
- If uneasy, stop
- Make checks automatic
Article mapOpen the visual summary
Five-Second Phishing Filter
- Five-second filterask
- Check senderpractice
- Peek at linkfails?
- Spot urgencyfails?
- Ignore official-lookingbuild habit
- Practice own inbox
- If uneasy, stop
- Make checks automatic
Table of Contents10 sections
- Key takeaways· 1 min
- Check your starting point· 1 min
- The real threat model: what actually breaks households· 1 min
- The three glance-checks: your five-second filter· 1 min
- Live practice: three emails from your own inbox· 1 min
- The hover test: the safest click you can make· 1 min
- Why "official-looking" is almost worthless· 1 min
- What to do when something smells off· 1 min
- Modern phishing tricks; and what still gives them away· 1 min
- Upgrade your habits: making the checks automatic· 1 min
Key takeaways
- Judge emails by sender domain, link target, and urgency framing—not by logos or how “official” they look.
- Hover (or long‑press) links to see where they really go before you ever click, especially for money or account access.
- If anything feels off, don’t negotiate with the email—go to the official site or app yourself and act from there.
- Already clicked? Close the page, change passwords, and watch for follow-up fraud; embarrassment is common, damage is optional.
Check your starting point
Before you learn a new habit, you need to see the one you already use.
Think about the last time you hesitated over an email that asked you to click something, pay something, or "verify" something. How did you decide? Was it the logo, the writing quality, or just a gut feeling?
If your main filter is “it looks official” or “it came to my real address”, you’re in the same place as most people—and that’s exactly where modern phishing wins.
By the end of this article, your default will be different: every risky email will pass through three tiny checks before your finger hits the link.
The real threat model: what actually breaks households
You don’t need to defend against spy agencies. You do need to defend against criminals sending millions of cheap, automated messages.
Their goal is simple: get you to enter a password, card number, or code into a fake site. Then they use that data in credential stuffing attacks (trying your password on big sites), emptying accounts, or taking over your email.
Most of the damage in normal households starts with exactly that kind of small mistake: one rushed click on a fake login page.
So we’ll focus on defenses that work against:
We’re not trying to make you perfectly safe from every exotic attack. We’re trying to make it very hard to trick you, personally, into handing over the keys.
The three glance-checks: your five-second filter
- Check sender domainPeek at the part after the `@` in the sender’s email.
- Check link targetHover (desktop) or long-press (phone) the main button or link without clicking.
- Check urgency framingAsk: Are they trying to rush or scare me into clicking?
You don’t need a forensics degree. You need three questions you can answer in seconds, before you click.
Use these only for emails that touch money, accounts, or identity (logins, payments, tax, shipping, subscriptions). For newsletters and memes, you can relax.
| Glance-check | What you do in 1-3 seconds | What a fail usually looks like |
|---|---|---|
| Sender domain | Peek at the part after the @ in the sender’s email. |
Slightly-wrong domains: secure-paypal.com, apple-support.io, free accounts pretending to be companies. |
| Link target | Hover (desktop) or long-press (phone) the main button or link without clicking. | Link goes somewhere that doesn’t match the real company, or to a random URL shortener. |
| Urgency framing | Ask: Are they trying to rush or scare me into clicking? | Threats like “account will be closed today” or “pay now or legal action,” especially if you weren’t expecting anything. |
If an email fails even one of these checks, slow down. The right move usually isn’t to “investigate more” inside the email—it’s to go around it via the official app or website.
Live practice: three emails from your own inbox
Time for a real attempt.
- Open your inbox on a laptop or phone.
- Find three recent emails that ask you to click a button or link about money, shipping, or login; examples: “Your package is waiting,” “Unusual sign-in,” “Payment failed,” “Verify your account.”
- For each email, give yourself ten seconds max to run the three checks:
- Sender domain
- Link target on hover / long-press
- Urgent or threatening wording
- Label each email in your head or on paper as:
Confident safeConfident scamNot sure
Now look at your decisions.
Good feedback signals: you can point to concrete reasons like "sender is [email protected] and link matches https://bank.com/..." or "sender is [email protected] and the link goes to dhl-track-login.com; not right." You also caught the emails that shout deadlines or threats.
Weak feedback signals: you’re mostly saying "it looks professional" or "they used my name," or you don’t know how to see the full sender or link target. That just means you’re ready for the next pass.
The hover test: the safest click you can make
- Hover or long-press link
- See the full address
- Check the domain
- Domain match the brand?
- Stop or go yourself instead
The single most useful move is also one of the safest: revealing where a link really goes without visiting it.
On a computer, move your mouse over the button or link, but don’t click. In most email apps and browsers, the true web address (URL) appears at the bottom of the window or in a small preview.
On a phone:
- In many email apps, long-press the link or button. A small panel should show the full address.
- If you only see a short preview, look for a “Copy link” option; paste it into a note to see the whole thing.
What you’re looking for is the domain—the core part before the first single slash.
https://www.paypal.com/..., https://accounts.google.com/...https://paypal.com.security-checks.info/..., https://googIe.com-reset.co/... (note the extra words or misspellings)Think of domains like street addresses and everything after the first slash like apartment numbers. If the street name is wrong, it doesn’t matter how nice the apartment number looks. Criminals bury fake sites in long, confusing addresses because they know most people never read past the logo and the first line of text. You’re going to be the small minority who actually glances at the street name.
If the domain doesn’t clearly match the brand you expect, stop. Don’t click through “just to see.” Go to the site or app yourself instead.
Why "official-looking" is almost worthless
Modern phishing kits copy real emails perfectly. Logos, colors, layout, even footers with addresses and copyright lines—all trivial to steal.
Attackers also use AI-written text, so the old “look for bad grammar” rule isn’t reliable anymore. Many fake emails now read better than genuine ones.
What’s still hard to fake is control of the real domain. Criminals can’t send from @hmrc.gov.uk or @apple.com at scale, so they use lookalikes: extra words, strange endings, or free webmail accounts.
When you judge an email by its design, you’re playing on their field. When you judge it by domain and hovering the link, you’re playing on yours.
What to do when something smells off
If an email fails your glance-checks, or you just feel uneasy, your next steps are simple.
- 1Do nothing inside the email. Don’t reply, don’t click, don’t open attachments.
- 2Go around it. Open the official app or type the website address you already know into your browser. If there’s really an issue, it will be visible there (e.g., a notification in your bank app).
- 3Check another channel. For deliveries, use the courier’s official tracking page or app and your tracking number. For banks, call the number on the back of your card, not in the email.
- 4Let it sit. Real problems don’t vanish if you wait an hour. Scams often rely on you acting before you can think.
If you confirm it’s fake, delete it. If your provider supports it, use the “Report phishing” option so their filters get smarter.
Modern phishing tricks; and what still gives them away
Today’s phishing campaigns often live on real infrastructure:
So what’s left for you to spot?
1. Domain mismatches. Even if the email comes through something that looks clean, the link may take you to an unrelated domain or a long, messy URL that hides the real host.
2. Context problems. "Your package is waiting" when you ordered nothing. A tax refund notice out of season. A bank you don’t use.
3. Overlapping urgency and access. The most dangerous emails combine scary time pressure with a request for login, payment, or document upload.
Whenever you see that combo, rush + login/payment, treat it as high risk, and move straight to the official site or app.
Upgrade your habits: making the checks automatic
The goal isn’t to think hard forever. It’s to make the three glance-checks automatic in the high-risk cases.
For the next week, any time you see an email about money, accounts, or identity, pause and run this mini-sequence in your head:
- 1Sender domain? Does it match the brand exactly?
- 2Hover / long-press link? Does the domain match what I expect?
- 3Urgent or threatening? Are they trying to rush me?
If you notice that you keep forgetting to hover links, that’s useful feedback. Adjust your retry: for the next day, every time you open an email on your computer, practice hovering every link, even in harmless newsletters, just to build the muscle.
Judge your progress by fewer impulse-clicks and more intentional "go around the email" moments, not by eliminating every uncertain feeling.
Cheatsheet: five-second phishing checks in the real world
⚡ Three glance-checks before you click
- Sender domain: In the From field, read what comes after
@. It should exactly match the real site (e.g.,@bank.com, not@secure-bank-login.comor@bank-support.info). 2) Link target: Hover or long-press. Trust only domains that exactly match the service, likehttps://accounts.google.com/for Google orhttps://www.paypal.com/for PayPal. Ignore everything after the first/when deciding. 3) Urgency framing: Be suspicious of "today only," "your account will be closed," or "legal action" pushed inside one message—especially if you weren’t expecting anything.
️ After a suspicious click or login
If you clicked a link and entered details, act within 15-30 minutes: 1) Close the tab immediately. 2) Go to the real site via your own bookmark or typed address. 3) Change the password on the real account, and if you reused that password, change it on other important sites too. 4) Turn on two-factor authentication (2FA) using an app (TOTP) or security key where available. 5) Watch for follow-up emails about new logins, password resets, or transactions for at least 48 hours and act fast if you see anything odd.
Common impersonation patterns
Delivery scams: claim a package is waiting or a fee is due; often use random tracking numbers and domains like -delivery-update.com. Bank or card alerts: "suspicious transaction" or "account locked" plus a button; sender is rarely your exact bank domain. Tax or government: urgent refund or legal threats out of season; links to long, unfamiliar domains. Subscription and app stores: fake receipts for big purchases; link goes to a sign-in page on a non‑Apple/Google domain. In every case, ignore the email button and instead use your bank app, courier app, or app store directly.
Reporting options for major providers
For Gmail: open the message, click the three dots near the reply button, choose Report phishing. For Outlook/Hotmail: open the message, choose Junk > Phishing. For Yahoo Mail: open the message, click the three dots, select Report a phishing scam. For iCloud Mail on the web: move it to the Junk folder and optionally forward to [email protected]. When in doubt, moving a suspected email to Spam/Junk and ignoring it is safer than interacting. Do not forward phishing to friends as a "warning"—you might encourage someone else to click.
Want a more guided way to practice this?
FAQ: common what-ifs
⚠️ What if I already clicked the link?
First, close the browser tab or app immediately so the site can’t run any more code in your session. If you did not enter any passwords, card numbers, or codes, your risk is lower, but you should still be alert for new phishing emails that reference what you saw. If you did enter a password, go straight to the real site, using your own bookmark or a fresh search, and change your password there, then on any other site where you reused it. If you entered card or bank details, call the number on the back of your card or visit your bank’s official site, explain that you may have given details to a phishing page, and ask them to watch or replace the card as needed. Finally, consider turning on two-factor authentication on the affected accounts so that a stolen password alone is not enough.
Are SMS phishing attempts handled the same way?
SMS (text) phishing, often called smishing, follows the same pattern: an alarming or tempting message plus a link, often about deliveries, refunds, or bank issues. You can’t hover links in SMS, so the safest rule is never tap login or payment links from text messages at all. Instead, open your bank or courier app directly, or type the website address you already know into your browser, and check there for any alerts. If an SMS claims to be from your bank or a government agency and you’re unsure, call the official number from their website or your card—not any number in the message. Deleting the message without interacting is always a safe choice.
How do I report a phishing email?
Reporting is useful because it trains your email provider’s filters and can protect other users. Most major providers have a built-in “Report phishing” or “Report scam” option in the message menu; use that instead of just deleting. If you’re at work, your company may provide a special “Report phishing” button or an address like [email protected]; check your internal IT guidance. For sensitive targets like banks or government, some organizations list a dedicated abuse or security email address on their websites, where you can forward suspicious messages. When reporting, you don’t need to write a story; just send the message intact and then delete it from your inbox.
Are work emails safer than personal?
Work systems usually have better spam filters and extra layers like URL scanning, so on average fewer malicious emails reach you there. But that doesn’t mean the ones that do are harmless. Criminals also target employees to reach company data or payroll systems. At work, you should still run the same three glance-checks and be especially cautious with anything about invoices, payroll changes, or document sharing. If a message seems odd but could be real, use a different channel: call the colleague, vendor, or HR using a known number, not the one in the email. And if you suspect a phishing attempt on your work account, report it to IT or security right away; early reporting can stop a wider incident.
Can I ever trust "verify your account" emails?
You will sometimes get real “verify your email” or “confirm your account” messages, especially right after you sign up for something. The key is context: did you just trigger this action yourself in the last few minutes? If yes, and the sender and link domain match the site you’re already on, it’s usually fine. If a verification email arrives out of nowhere, or for an account you don’t remember creating, treat it as suspicious and ignore it. When in doubt, skip the email link entirely and go back to the site or app where you started the signup; most services will show a banner like “Check your email to verify” and may let you request a fresh, known-good email from there.
️ Do spam filters and antivirus make this unnecessary?
Good spam filters and security tools remove a lot of junk before it reaches you, and they’re worth using. But they’re tuned to catch mass campaigns and known bad patterns; targeted or freshly created phishing runs often slip through for a while. Antivirus software mostly helps if a phishing email tries to deliver a file that contains malware, not if it’s just a clean-looking link to a fake login page. The glance-check habits in this article cover the gap: the small set of dangerous, realistic messages that tools can’t reliably judge yet. Think of tools as your first fence and your habits as the lock on your front door; both matter, and neither replaces the other.
Bringing it all together: five seconds that save you hours
You don’t need to memorize long lists of scam types or live in fear of your inbox. You just need a short, repeatable routine for the few emails that matter most—anything about money, accounts, or identity.
In those moments, do three things: glance at the sender domain, hover or long-press the link to read the real destination, and notice whether the message is trying to rush you. If any piece feels off, step outside the email and go to the official app or website yourself.
Phishing works best when you’re rushed, tired, or embarrassed to double-check. You’re allowed to slow down. With a week or two of practice, the checks become automatic, and the scams become obvious clutter instead of landmines.
Use this article as a reference as you practice. The goal isn’t to be un-hackable; it’s to be a hard, unprofitable target for the kinds of attacks that actually hit everyday people.