How to Recognize Phishing Emails, Texts and Websites
A practical phishing inspection routine for email, text, QR codes, fake invoices, login pages and modern CAPTCHA scams, plus immediate recovery steps.
By TechniaHQRobot
Key points
Unexpected urgency and credential requests are strong warning signals.
Inspect the real sender and destination, not only the displayed name or link text.
Open the company through a known app or typed address instead of the message link.
If credentials were entered, change them from a clean device and revoke active sessions.
Phishing is a request designed to make you surrender access, money or information. Pause when a message creates urgency, inspect the real sender and destination, and verify the request through a known app, website or phone number that did not come from the message. A familiar logo is not evidence.
The FTC warns that phishing messages commonly tell a story to make people click a link or open an attachment. They may claim a payment failed, an invoice is overdue, a package is waiting or an account will be closed.
The seven checks to make before clicking
| Check | What to inspect | Warning example |
|---|---|---|
| Context | Were you expecting this request? | Password reset you did not request |
| Sender | Full address or number, not display name | bank-security at unrelated domain |
| Destination | Actual domain behind the link | brand name appears only in a subdomain or path |
| Request | What action is demanded? | Enter password, card, recovery code or crypto payment |
| Urgency | Is there artificial pressure? | “Account closes in 15 minutes” |
| Attachment | Was a file expected? | Invoice ZIP, HTML login form or executable |
| Verification | Can you confirm independently? | Call known number or open official app |
One sign is not a verdict. A real company can send an urgent message, and a criminal can write perfect grammar. The decision comes from context and independent verification.
Inspect the sender beyond the display name
Email clients prominently display a friendly name such as “Microsoft Support” or “Your Bank.” Expand the sender details and read the complete address.
Look for:
- misspelled domains
- unrelated free-mail addresses
- extra words around the brand
- reply-to address different from the sender
- a message sent to many hidden recipients
A compromised legitimate account can send phishing from a real domain. The sender check is necessary but not sufficient. An unusual payment request from a colleague still needs a separate confirmation.
Read domains from right to left
In login.example.com, the registered domain is generally example.com. In example.security-check.com, the domain is security-check.com; “example” is only a subdomain chosen by the attacker.
Watch for character substitutions and lookalikes: lowercase L, uppercase I and the number 1 can appear similar. Internationalized domain names can also imitate familiar text.
HTTPS and a padlock mean the connection to that site is encrypted. They do not prove that the site belongs to the company shown in the page design.
Do not trust the visible link text
On desktop, hover over a link without clicking and inspect the destination shown by the browser or mail client. On mobile, a press-and-hold preview may show the address, but interface behavior varies and an accidental tap is possible.
The safer method is to ignore the message link. Open the official app, use a bookmark or type the known domain. If there is a real account problem, it should appear there.
Shortened links hide the destination. QR codes do the same. A QR code on a parking meter, invoice, restaurant table or email can direct to a fake payment or login page. Inspect the preview and verify the physical or organizational context.
Common phishing stories
Account suspension
The message claims that unusual activity or a failed payment requires immediate login. Open the official app separately. Never provide a one-time code to a caller or chat agent who initiated contact.
Package delivery
The text requests a small redelivery fee or address confirmation. Search the tracking number on the carrier’s official site. A tiny payment can be a path to card theft.
Fake invoice or bank-detail change
A supplier appears to send a new account number. This is common in business email compromise. Confirm the change by calling a known contact using an existing number, not the number in the message.
Executive or colleague request
A message asks for gift cards, a secret transfer or an urgent document. Contact the person through another channel. Attackers exploit hierarchy and the desire to respond quickly.
Shared document
The link opens a fake Microsoft, Google or Dropbox login. Check whether the sharing notification appears in the real service. A login page reached from an unexpected document should be treated as hostile.
Job or recruitment scam
A recruiter requests identity documents, banking details, payment for equipment or installation of remote-access software before a verified interview and contract. Confirm the vacancy on the company’s official careers page.
Modern fake CAPTCHA scams
The FTC reported a scam in which a fake CAPTCHA tells the user to press Windows+R, paste a command and press Enter. That sequence runs attacker-supplied instructions. A legitimate CAPTCHA does not require you to open a system run dialog or execute commands.
If a web page asks you to paste a command into PowerShell, Terminal, Command Prompt or the browser developer console, stop. Text copied from a page can contain hidden or different content.
Attachments that deserve caution
Unexpected ZIP archives, HTML files, macro-enabled Office documents, disk images and executables are high risk. PDFs can also contain malicious links or exploit unpatched software.
Do not enable macros or “content” because a document says it is protected. Confirm the sender and business purpose independently. Keep the operating system, browser and document reader updated.
Cloud file links are not automatically safe. Attackers use legitimate storage services to host malicious pages and files.
Login-page checks
Before entering a password:
- confirm the complete domain
- confirm you intentionally navigated there
- use a password manager
- inspect whether the expected account and security flow appear
- reject any request for a recovery code or MFA code from another person
Password managers provide a useful warning because they normally fill credentials only on the stored domain. Do not override that signal casually.
Multi-factor authentication reduces risk, but phishing kits can proxy a real login and steal a session. Hardware security keys and passkeys provide stronger phishing resistance when the service supports them.
What to do if you clicked or entered information
You clicked but entered nothing
Close the page. If a file downloaded, do not open it. Update security software and run a scan. Check the browser downloads list and remove the file.
If the page instructed you to run a command or install software, disconnect the device from the network and seek technical help.
You entered a password
From a clean trusted device:
- change the password immediately
- change it anywhere it was reused
- enable or reset multi-factor authentication
- sign out other sessions
- review recovery email, phone and forwarding rules
- inspect recent login activity
Email accounts deserve priority because they can reset other accounts.
You entered payment or identity information
Contact the bank or card issuer using the number on the card or official site. Ask about blocking transactions and replacing credentials. Monitor accounts and follow the identity-theft process available in your country.
The FTC directs US users who exposed identity information to IdentityTheft.gov. Other countries have their own cybercrime and consumer-protection reporting channels.
You approved a transfer
Contact the financial institution immediately. Speed matters. Preserve the message, headers, account details, transaction reference and time. Report the fraud to the appropriate local authority.
Report and preserve evidence
Use the mail provider’s phishing-report button. The FTC advises forwarding phishing email to the Anti-Phishing Working Group and reporting fraud through the FTC system in the United States. Mobile carriers may accept scam texts forwarded to a reporting number, depending on country.
At work, report the message to the security team before deleting it. They may need headers, attachment hashes or the destination URL to protect other users.
Do not publicly repost an active phishing link as a clickable URL. Share screenshots or defanged text according to the reporting team’s process.
Build habits that remove rushed decisions
- use a password manager
- enable multi-factor authentication or passkeys
- keep software updated
- use bookmarks for financial services
- prohibit payment-detail changes by email alone
- train staff with realistic examples
- back up important data
- review account sessions regularly
The strongest rule is simple: a message can request attention, but it does not control the path you use to verify it.
Frequently asked questions
What is the clearest sign of phishing?
An unexpected message that pressures you to click, open an attachment, enter credentials, send money or change payment details is a strong warning. Verify the request through a known contact method.
Can a phishing email have perfect grammar?
Yes. Modern scams can copy brand design and use polished language. Sender identity, destination domain, request context and independent verification matter more than spelling.
What should I do after clicking a phishing link?
Close the page, disconnect if malware may have run, scan the device, change exposed passwords from a clean device, enable multi-factor authentication and review account sessions and transactions.
How do I check a suspicious link safely?
Do not open it. On desktop, hover to inspect the actual destination. On mobile, press and hold without opening when the device supports preview. Better still, open the organization through its known app or type the official address.
Editor : @techniahqrobot
TechniaHQRobot editorial coverage on AI, robotics, automation and Physical AI.