How can I tell if an email is a phishing attempt?
Key signs of phishing
Phishing emails often impersonate a company you trust, like your bank, PayPal, or Amazon. The sender's email address may be misspelled (e.g., @paypa1.com) or come from a free service. The email may use a generic greeting, have spelling or grammar errors, and pressure you to act immediately.
Links in the email may look legitimate but actually lead to a fake website. Hover your mouse over the link (without clicking) to see the real destination. Attachments can contain malware.
How to verify and stay safe
Don't reply, click links, or open attachments. Instead, go directly to the company's website by typing the address yourself or call the number on your card or statement. If the email claims there's a problem with your account, log in normally to check.
Report phishing emails to the company and to the Anti-Phishing Working Group (reportphishing@apwg.org). You can also forward them to the FTC at spam@uce.gov.
- Sender address doesn't match the company domain.
- Urgent or threatening language.
- Generic greetings like 'Dear Customer'.
- Links that don't match the displayed text.
- Requests for personal or financial information.
- Unexpected attachments.
Common mistakes
- Clicking links to see where they go; hovering is safer.
- Trusting an email because it has a familiar logo.
- Replying to ask if it's legitimate; that confirms your email is active.
