How phishing actually works, and the two checks that catch most of it
Most advice about phishing is a list of clues: bad spelling, odd greetings, a sense of urgency. That advice is getting less useful every year, because the spelling is fine now and the logos are correct. Plenty of phishing messages are flawless.
So stop trying to win on inspection. Win on structure instead.
What every phishing message needs
Whatever it looks like, a phishing message has to do two things. It has to get you to act inside the message, using its link, its phone number, or its attachment. And it has to get you to act now, before you check.
That is the whole mechanism. Urgency exists to stop you verifying. The link exists because the attacker cannot control where you go if you navigate yourself.
Check one: never use the contact details in the message
This one habit defeats almost every phishing attempt, including the ones you could never have spotted.
If a message appears to be from your bank, do not tap its link and do not ring its number. Open your banking app the way you normally do, or ring the number printed on your card. If the message was real, the same information will be waiting for you there. If it is not there, it was not real.
This works because it does not require you to judge the message at all. A perfect forgery and an obvious fake both fail the same test.
Check two: slow down when someone creates urgency
Real organisations cope with delay. Your bank can wait twenty minutes. The tax office writes letters. A delivery company will try again.
Treat urgency itself as the warning sign, not a reason to hurry. "Your account will be closed in 24 hours" is doing a job, and the job is stopping you from checking.
The specific tricks worth knowing
- Lookalike web addresses. Attackers register domains that read correctly at a glance. Read the address from the right: the real domain is the part immediately before the first single slash.
- Reply-chain hijacking. If someone's email is compromised, the attacker replies inside a real conversation you were already having. The context is genuine. The link is not.
- Attachments that ask you to enable something. A document that wants macros enabled, or content unblocked, is asking permission to run code. Close it.
- Codes you did not request. If a verification code arrives out of nowhere, somebody is trying your password right now. Never read it to anyone. No real company will ever ask you for it.
If you already clicked
Do not spend time being embarrassed. Speed matters more than dignity.
- If you entered a password, change it now, on that site and anywhere you reused it.
- Turn on two-factor authentication on that account.
- If you entered card or bank details, ring your bank on the number on your card.
- Tell someone. Scams continue because people go quiet.
Last checked 2026-09-23. Prices, dates, and bank policies change; verify anything time-sensitive against the linked source.