Research
How to Spot Phishing Emails in 2026: A 10-Point Checklist
- phishing
- email-security
- social-engineering
- awareness
Phishing now reads like real mail. A practical checklist for spotting phishing emails, verifying senders, reading headers, and knowing what to do after a click.
Phishing works because the message looks ordinary. You spot it by checking the parts an attacker can't fully control.
Searches for "how to spot phishing emails" rose more than 24,000% in the last three months (Cybermatch, Ahrefs US data). "What is phishing" is up about 200% over the same window. The demand is real. Most phishing emails no longer have spelling mistakes, and AI writing tools have made the old "look for bad grammar" advice obsolete.
This guide covers what still works.
Why the old advice stopped working
The classic red flags were broken English, a strange logo, and a Nigerian prince. None of those hold up anymore.
Modern phishing uses three things:
- Clean writing. Language models produce fluent, polite text in any tone.
- Real branding. Logos, footers, and layout are copied from genuine emails.
- Real context. Attackers reference actual vendors, invoices, or events from public data or earlier breaches.
The content now looks right. So the reliable checks are structural: who sent the email, where the link goes, and what the email is asking you to do.
The mental model: sender, link, ask
Every phishing email has three parts. Check each one on its own.
- Sender: is this really from who it claims? Easy to fake: display name, logo, signature.
- Link or attachment: where does this actually go? Easy to fake: button text, visible URL text.
- Ask: what does it want me to do, and how fast? Easy to fake: urgency, authority, story.
A legitimate email passes all three. A phishing email usually fails at least one, even when it looks polished.
The 10-point checklist
Sender
1. Read the actual address, not the display name.
The display name "Microsoft Account Team" can sit on top of any address. Tap or hover over the name. Look for lookalike domains such as rnicrosoft.com, micros0ft-support.com, or microsoft.account-verify.co.
2. Check the domain after the last dot.
In login.microsoft.com.secure-check.net, the real domain is secure-check.net. Everything to the left is decoration an attacker controls.
3. Watch for a mismatched Reply-To. If you hit reply and the recipient changes to a different address, the sender wants your answer somewhere else. Business email compromise often relies on this.
Link or attachment
4. Hover before you click. On desktop, hover over the link and read the URL in the status bar. On mobile, long-press to preview it. Button text like "View invoice" tells you nothing about the destination.
5. Be suspicious of link shorteners and redirects.
bit.ly, QR codes, and "secure document" portals hide the real destination. Legitimate services rarely need them for account actions.
6. Treat unexpected attachments as hostile.
Be careful with .html, .htm, .svg, .iso, .zip, and Office files that ask you to "Enable content." HTML attachments often open a fake login page stored on your own machine, which gets around link scanners.
7. Never sign in from an email link. If the email says there's a problem with your account, open a new tab and go to the site yourself. This one habit defeats most credential phishing.
Ask
8. Name the pressure. Phishing creates a reason to act before you think: account suspension, a failed payment, a legal notice, a CEO request, a package on hold. If the email pushes you to act within hours, slow down.
9. Flag requests that bypass normal process. Changing bank details, buying gift cards, approving an MFA prompt you didn't start, or sharing a one-time code. Legitimate organizations have processes for these things. Email alone isn't one.
10. Verify out of band. Call the person or company using a number you already have, not one in the email. The FTC's rule is simple: if you have an account with the company, contact it using a phone number or website you know is real (FTC).
Reading email headers (for the technical reader)
When an email is borderline, the headers show what actually happened. In Gmail use Show original. In Outlook use View message source.
Look at three results:
- SPF: was the sending server allowed to send for that domain?
- DKIM: was the message signed by the domain, and did the signature survive delivery?
- DMARC: do SPF or DKIM line up with the visible From domain?
A dmarc=fail on mail claiming to be from a major brand is a strong signal. A pass does not prove the email is safe. Attackers register their own domains and set up valid SPF, DKIM, and DMARC for them. Authentication proves who sent the email, not whether that sender is honest.
Phishing beyond email
The same model applies on other channels:
- Smishing (SMS): fake delivery, toll, and bank alerts with short links.
- Vishing (voice): calls pretending to be IT support or your bank, often combined with an MFA prompt.
- Quishing (QR codes): codes in emails, PDFs, or on physical posters that point to credential pages. Phones usually have weaker filtering than corporate email.
- MFA fatigue: repeated push prompts until someone taps approve. Never approve a prompt you didn't start.
What to do if you already clicked
Move quickly and don't be embarrassed. Speed matters more than blame.
- Disconnect the device from the network if you opened an attachment.
- Change the password for the affected account from a separate, trusted device. Change it anywhere you reused it.
- Sign out all sessions and review MFA methods for anything you didn't add.
- Report it to your security team, or forward the email to
reportphishing@apwg.organd report it at ReportFraud.ftc.gov (FTC). - Watch for follow-up activity, including new mail rules, forwarding settings, and unfamiliar sign-ins.
For teams: controls that remove the guesswork
People catch a lot of phishing, but controls should do most of the work:
- Phishing-resistant MFA (passkeys, FIDO2 security keys) stops stolen passwords and most proxy phishing kits.
- DMARC at
p=rejecton your own domains stops direct spoofing of your brand. - External sender banners and lookalike-domain detection make impersonation easier to see.
- A one-click report button with fast feedback turns every employee into a sensor.
- Simulations used for learning, not punishment. Measure report rate, not just click rate.
Keep learning
- Browse the resources library for training platforms and reference material.
- Look up terms like SPF, DKIM, and credential harvesting in the glossary.
- See how social engineering fits into broader attack patterns in techniques.
Sources
- Cybermatch, Cyber Search Trends (Ahrefs US data, updated September 28, 2026).
- Federal Trade Commission, How To Recognize and Avoid Phishing Scams.
A phishing email can copy how a real message looks. It still can't change where its link goes or who is really asking.