Recognizing Phishing and Scam Messages

Phishing has moved well beyond obvious misspelled emails. Modern attempts are well written, visually accurate, and often reference real context. Recognizing them relies on structure rather than polish.
Urgency plus authority is the signature
Nearly every phishing attempt combines a claim of authority with time pressure. Your account will be closed. A payment failed. Suspicious activity was detected. Verify within twenty-four hours.
The urgency exists to prevent the pause where you would notice something is wrong. Any message creating pressure to act immediately deserves more scrutiny rather than less, and that instinct alone prevents most successful attacks.
Check the sender properly
Display names are trivially forged. The actual address matters, and it needs a careful look.
- Look for lookalike domains: a zero for an O, an added hyphen, a plausible subdomain on an unrelated domain, or a familiar brand name followed by an unfamiliar suffix.
- Legitimate companies send from their own domain, not from a generic mail provider.
- Reply-to addresses that differ from the sender are a strong signal.
Inspect links before clicking
Hover over a link on a computer, or press and hold on a phone, to see the real destination.
Read the domain from right to left. The important part is immediately before the first single slash. A link showing a familiar brand early in a long address means nothing if the actual domain is something else entirely.
Better still, do not use the link. Open a browser and navigate to the site yourself, or use the app. This single habit defeats nearly all phishing regardless of how convincing the message is.
Attachments and unexpected files
Be skeptical of unexpected attachments even from known senders, since compromised accounts send to their own contacts. Documents requesting that you enable content or macros are a common infection path. Invoices, shipping notices, and resumes are frequent lures because they are plausible and prompt opening.
Increasingly common variations
- Text message phishing, often about deliveries, tolls, or bank alerts, exploiting the brevity of the medium.
- Voice calls, sometimes claiming to be a bank or a technical support department, and increasingly using synthesized voices.
- Quishing, where a QR code hides the destination entirely, which is particularly effective on printed material in public places.
- Business email compromise, in which an attacker with access to a real mailbox inserts themselves into an existing conversation about a genuine payment. These lack the usual signals entirely, which is why payment detail changes should always be verified by a separate channel.
What legitimate organizations do not do
- Ask for a password. No legitimate support desk needs it.
- Ask for a two-factor code. Anyone requesting one is attempting to bypass your protection in real time.
- Demand payment in gift cards, wire transfers, or cryptocurrency.
- Insist you stay on the phone while you take actions, which is a pressure tactic to prevent verification.
Verify by an independent channel
The universal defense: contact the organization using a number or address you already have, from a statement, a card, or the official site. Never use contact information supplied by the message itself.
For anything involving money, particularly a change in payment instructions, call a known number and confirm verbally. This is inconvenient, and it defeats the most costly category of fraud.
If something was clicked
Act quickly rather than with embarrassment.
- Change the password for the affected account immediately, and anywhere the password was reused.
- Enable two-factor authentication if it was not already on.
- Check account activity and active sessions, signing out unrecognized ones.
- Contact the institution directly if financial information was involved.
- Run a security scan if a file was downloaded or opened.
Speed matters far more than perfect recall of what happened. These attempts are engineered by professionals to be convincing, and being deceived reflects the quality of the attack rather than a lack of care.
Article Was Generated By AI.