What Is Phishing?

Phishing is when someone sends you a fake email designed to look like it's from a company or person you trust. The goal is to get you to click a link that takes you to a fake website, where you'll be asked to enter your password, credit card number, or other personal information.

The word "phishing" comes from "fishing" — the scammer is casting a line and hoping you'll bite. And just like real fishing, they send out thousands of lines at once.

The Sender Name vs. the Actual Address

This is the single most important thing to check. Every email has two parts to the "From" field: the display name (what you see) and the actual email address (what's behind it).

A scammer can set their display name to anything — "PayPal," "Your Bank," "Amazon Support." But the actual email address behind it will be something completely different, like "support@paypa1-secure.com" or "amazon@customer-alert.xyz."

If you're ever unsure about an email address, search for the company's official contact page. Their real email domains will be listed there.

  1. On a computer: hover your mouse over the sender's name to see the full email address.
  2. On a phone: tap the sender's name to expand the address.
  3. Check the domain (the part after the @). It should match the real company. PayPal emails come from @paypal.com, not @paypal-support.com.
  4. Watch for misspellings: microsft.com, arnazon.com, gooogle.com.
  5. Watch for lookalike characters: using the number "1" instead of the letter "l", or "rn" to look like "m".

The Greeting

Legitimate companies usually know your name because you have an account with them. So their emails will say "Dear John" or "Hi Sarah." Phishing emails that are sent to millions of people at once often use generic greetings like "Dear Customer," "Dear User," or "Dear Account Holder."

However, more sophisticated phishing emails do include your real name — especially if your information was exposed in a data breach. So a personalised greeting doesn't automatically mean the email is safe. Always check the other signs too.

The Body — Urgency and Fear

The body of a phishing email almost always tries to create a sense of urgency or fear. Common phrases include:

Real companies do send security alerts, but they never threaten to close your account within hours. If you're concerned, go directly to the company's website by typing the address in your browser — never click the link in the email.

  1. "We've detected unusual activity on your account"
  2. "Your account will be suspended within 24 hours"
  3. "Verify your identity immediately to avoid losing access"
  4. "Your payment method has been declined"
  5. "You have an unpaid invoice — action required"

The Link — Where It Really Goes

The centrepiece of every phishing email is the link. It might be a button saying "Verify Your Account" or "Update Payment Method," or it might be a text link that looks like a real URL.

Before clicking any link in an email, hover your mouse over it (don't click). You'll see the real URL appear, usually at the bottom of your email window or in a tooltip. If the URL doesn't match the company's real website, don't click it.

Real-world example

How link tricks work

The email might show "https://www.paypal.com/verify" as clickable text, but when you hover over it, the real link goes to "http://paypa1-verify.suspicious-site.com/login." The display text of a link can be set to anything — only the actual URL matters.

Attachments

Some phishing emails include attachments — PDF "invoices," Word "documents," or ZIP files. These can contain malware (harmful software) that installs itself on your computer when you open the file.

Never open an attachment from an unexpected email. If your bank or a company needs to send you a document, they'll usually make it available through your account on their website, not as an email attachment.

Be especially cautious of .zip, .exe, .scr, and .docm files. But even PDF and regular Word documents can contain harmful content. When in doubt, don't open it.

Spelling and Grammar

Phishing emails used to be easy to spot because they were full of spelling mistakes and awkward grammar. That's becoming less reliable as scammers use AI to write more polished messages.

Still, many phishing emails do contain small errors — especially in the domain name, the company name, or the specific terminology the company uses. If something reads slightly "off," trust your instinct.