Phishing email

Phishing email

Natalie Moore
April 23, 2026· Updated August 9, 2026· 5 min read

A phishing email is a fraudulent message that pretends to come from a trusted organization or person. Its goal is to make you click a link, reveal a password, download a malicious attachment, or send money. The key is not hunting for typos. It is verifying identity, domain, request, and process. For a broader framework, read the complete online security guide.

What Are the 9 Most Common Signs of a Phishing Email?

SignHow to check it
Odd sender domain spellingLook for paypa1.com, extra hyphens, or unfamiliar subdomains
Generic greeting"Dear user" without account or order details
Manufactured urgency"Act within 24 hours or your account will be closed"
Password or code requestLegitimate organizations usually do not ask for codes by email
Link text and real URL differHover or long-press to preview the actual domain
Suspicious attachment typeBe careful with .html, .js, archives, and macro documents
Unusual toneA familiar person changes greeting, language, or asks for secrecy
Payment details changedNew bank details must be confirmed independently
Normal process is bypassedNo ticket, approval, official app, or support channel

The FTC's phishing guidance focuses on the same themes: suspicious links, requests for sensitive information, impersonation of trusted organizations, and panic.[1]

Google's safety tips likewise recommend verifying the sender address, checking for look-alike domains, and thinking twice about urgent requests.[3]

Why Do Modern Phishing Emails Look So Real?

Attackers no longer rely only on rough templates. They use names from leaked databases, old order details, job titles, and realistic brand login pages and email layouts. Generative tools make the language more natural, so grammar mistakes are no longer a reliable test.

Many phishing emails also avoid sending malware directly. Instead, they send you to a page that looks like Microsoft, Google, your bank, or a courier portal. Once you enter a password, the attacker may try to log in immediately and may even ask you for an MFA code.

What Should You Do With a Suspected Phishing Email?

  1. Do not click the email button; type the official address into your browser instead.
  2. Do not use phone numbers in the email; use the website, app, or your saved contacts.
  3. For account alerts, open the official app directly and check notifications.
  4. Confirm payment and data-change requests through a second channel.
  5. Mark the message as phishing or spam to help the mail provider block similar samples.

What If You Already Clicked a Phishing Link?

First, identify what you did. If you only opened the page and did not enter information, close it, remove any downloads, and run a security scan. If you entered a password, change it on the real website immediately, sign out of all devices, and check account recovery email, phone number, forwarding rules, and connected apps.

If you entered card details, an ID number, or a verification code, contact your bank, the platform's support team, or company IT as soon as possible. If a work email account is involved, do not handle it quietly. The attacker may have already set forwarding rules or may impersonate you to target colleagues.


How Can You Reduce Phishing Email Risk Long Term?

First, use a password manager. It separates passwords for every site and uses domain matching to help reveal fake login pages. Second, turn on MFA for email, banking, cloud storage, and social accounts. CISA advises users to stay cautious with suspicious emails and report or handle them through official channels.[2]

Third, reduce email exposure. When signing up for one-time events, downloads, or trial services, use an email alias or temporary address. You can also read how to protect your email and how to stop getting spam emails.

Summary

  • The question is not whether an email looks official, but whether you can verify it independently.
  • Do not enter passwords, codes, or payment information through email links.
  • The sooner you change passwords, revoke sessions, and check forwarding rules after a bad click, the smaller the damage.
  • Password managers, MFA, email aliases, and secure connections are the baseline.

FAQ

FAQ 1: Do phishing emails always go to spam?

No. Some phishing emails bypass filters, especially targeted messages that impersonate colleagues, clients, or vendors.

FAQ 2: Can I get infected just by opening an email?

Modern email services usually restrict automatic execution, but do not download attachments, enable macros, or open unfamiliar links.

FAQ 3: How do I spot a phishing link on mobile?

Long-press the link to preview the domain, and do not trust only the button text. Short links, odd spelling, and unfamiliar subdomains deserve caution.

FAQ 4: Do banks really send security alert emails?

Yes, but you should not log in from the email link. Open the bank app directly or type the official website address.

FAQ 5: Why does a phishing email know my name?

Your name and email may come from public profiles, past breaches, marketing lists, or social platforms. That does not make the email trustworthy.

FAQ 6: What should I do first after a work email account is phished?

Notify IT or the security team immediately, change the password, revoke sessions, check forwarding rules, and investigate whether colleagues received follow-up phishing.


Disclaimer: This article provides general security education and does not replace company security procedures or professional incident response advice.

This guide comes from AethoVPN; VPN routing does not carry out the checks required for spot phishing emails.

Sources

[1]Federal Trade Commission — How to recognize and avoid phishing scams: https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams [2]CISA — Avoiding Social Engineering and Phishing Attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks [3]Google Safety Center — Tips to Help You Stay Safe Online: https://safety.google/safety/security-tips/

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

Phishing email | AethoVPN