How to Spot a Phishing Email
(7 Red Flags a Technician Checks First)
A phishing email has one job: to get you to click, sign in, or hand something over before you stop to think. In over 30 years of fixing computers, I've watched sharp, careful people get caught — not because they're foolish, but because a good fake catches you on a busy day when you're half-paying-attention. The good news is that almost every phishing email trips over the same handful of tells. Learn to check these seven, in order, and you'll catch nearly all of them in a few seconds flat.
1 The Sender's Real Address (Not the Display Name)
This is the first thing I check, every time. The name shown at the top of an email is just a label — anyone can type "PayPal" or "Canada Revenue Agency" into it. What matters is the actual address behind that name. Click or tap on the sender name to expand the real email address and look hard at the part after the @ sign.
Real messages from a company come from that company's own domain — something like service@paypal.com. Fakes use lookalikes and add-ons: paypal@secure-billing.com, service@paypa1.com (that's a number one, not an L), or a random string of letters. If the domain isn't exactly the company's real website, stop right there.
2 Manufactured Urgency and Fear
Phishing runs on panic. "Your account has been suspended." "Unusual login detected." "Your payment failed — act within 24 hours or lose access." The whole point is to spike your heart rate so you click before your common sense catches up.
Real companies rarely threaten you with a countdown clock. When an email is pushing you to move right now, that pressure itself is the red flag. Slow down — that pause is exactly what the scammer is trying to rob you of.
3 Links That Don't Go Where They Claim
Before you click any link in an email, check where it actually leads. On a computer, hover your mouse over the link (don't click) and the true destination appears at the bottom of the screen. On a phone, press and hold the link to preview the address without opening it.
If an email wants you to log in somewhere, don't use its link at all. Open a new browser tab and type the company's address yourself, or use your own saved bookmark. It takes five extra seconds and it defeats almost every phishing link ever made, because you end up on the real site instead of a copycat.
4 Generic Greetings and Vague Details
Your bank knows your name. So does your email provider, your phone company, and the store you actually ordered from. When a message opens with "Dear Customer," "Dear User," or "Dear account holder," that's often because it was blasted out to thousands of addresses at once and the sender has no idea who you are.
Same goes for the details: a real receipt or account notice references something specific — an order number, the last four digits of a card, a real date. A vague message about "your recent transaction" with nothing to pin it to is fishing for a reaction, not reporting a real event.
5 Off Wording — But Don't Rely on This Alone
The old advice was "look for bad spelling and clumsy grammar," and for years that worked. Clunky English was a dead giveaway. I have to be straight with you, though: that tell has weakened a lot. Scammers now use AI to write clean, natural-sounding messages, so a polished email is no longer proof it's real.
Awkward phrasing is still worth noticing when you see it, but treat it as a bonus clue, not your main defence. This is exactly why the checks above — the real sender address and the real link destination — matter more than ever. If you want to see how far these scams have come, I broke it down in AI scams and deepfakes in 2026.
6 Any Request for Passwords, Codes, or Payment
Here's a line that doesn't move: a legitimate company will never email you asking for your password, your full card number, or the one-time security code sent to your phone. Not your bank, not Microsoft, not the government. Ever.
Watch especially for anyone asking for a verification code you just received by text. That code is the last lock on your account. A scammer who has your password but not the code will try to trick you into reading it to them or typing it into their fake page. Never share it — the real company already knows it and would never ask.
7 Unexpected Attachments
If you weren't expecting a file, don't open it — no matter how ordinary it looks. A surprise "invoice," "shipping label," "resume," or "scanned document" is one of the oldest ways to slip malware onto a machine. Be extra wary of files ending in .zip, .exe, or a document that demands you "enable content" or "enable macros" to view it. That prompt is the trap.
When in doubt, contact the sender through a channel you already trust — a phone number you look up yourself, not one from the email — and ask if they really sent it.
Already Clicked or Entered Something?
First: don't beat yourself up. It happens to careful people every single day. But do move quickly. Change the password for that account (and anywhere you reused it), turn on two-factor authentication, and watch for follow-up scams — because once you're on a "responsive" list, the next wave often follows. I've written the full recovery plan step by step in what to do after a data breach. And if you're worried something got onto the machine itself, a solid antivirus program and a full scan are the right next step.
Not Sure If It's Real? Ask Before You Click
If an email has you second-guessing — and the smart move is always to check before you act — you don't have to figure it out alone. I'd genuinely rather look at a suspicious message with you for two minutes than clean up an infected machine or a drained account afterward.
If you're in the Nanaimo, BC area, BigMike Computer Services can look over a questionable email, clean up a machine that already got hit, and get your accounts locked back down. A quick call or email beats a costly mistake every time.
Visit BigMike Computer Services →— BigMike | Computer Repair Technician, Nanaimo BC
📧 BigMikeNanaimo@gmail.com