Someone reading a short email on a phone, seen over their shoulder.

Guides Threats

How to spot phishing

Bad spelling stopped being the giveaway years ago. These are the checks that still work.

6 min read  ·  Last reviewed 11 August 2026  ·  Written for people looking after their own devices

Reading a link before you click it https:// protocol secure-login. anything at all attacker.com the real domain /yourbank path
Hover on a computer, press and hold on a phone. The domain is the part immediately before the first single slash - and the padlock says nothing about it, because a certificate for any domain is free and automatic.

Link text can say anything. On a computer, hover and read the address in the status bar; on a phone, press and hold to preview. Read the domain from the right: the part immediately before the first single slash is the real one.

So "yourbank.example.com" is a page on example.com, not on yourbank. This one habit defeats a large share of attempts.

Treat urgency as the signal

Account suspended, payment failed, parcel held, unusual sign-in, respond within 24 hours. Urgency exists to stop you checking. Real organisations rarely need an answer in the next few minutes, and none of them lose your business because you logged in through their app instead of their link.

Notice what is being asked of you

Legitimate messages rarely ask for a password, a card number, or a code sent by SMS. A code request is worth particular alarm: those codes exist to stop someone who already has your password, so a person asking for one usually has it.

Be sceptical of attachments you did not expect

Especially documents asking you to enable content or macros, archives containing a single file, and anything with a double extension. An invoice from a company you have never dealt with is not an invoice.

The move that works regardless of how good the fake is Do not use the link however plausible Open the app or type the address Check the account it will be waiting Ten seconds lost if it was genuine
This defeats every version of the attack at once, including the ones that come from a genuinely compromised account.

A convincing message can come from a real address

If a colleague's or supplier's account has been compromised, the message genuinely comes from them, in a real thread, in their writing style. This is why sender address alone is not a sufficient check, and why unexpected requests to change bank details should always be confirmed by other means.

The reliable move

Do not use the link. Open the app, or type the address you already know. If the message was genuine, whatever it wanted will be waiting for you inside your account. If it was not, you have lost ten seconds.