Unmasked

← Resource library

How to spot a phishing email

Four checks, in order, that catch nearly all phishing emails. No technical knowledge needed.

Phishing emails are designed to make you act quickly. Slowing down is most of the defense. These four checks take under a minute.

1. What is it asking you to do?

Almost every phishing email wants one of three things: click a link, open an attachment or reply with information.

An email that asks nothing of you is rarely a threat. Start there, because it tells you how much attention the rest deserves.

2. Look at the real address, not the name

The sender name is typed in by whoever sent it and can say anything. Tap or hover on it to reveal the actual address behind it.

Chase Bank <alerts@chase-secure-message.net> is not Chase.

3. Check where the link goes

Hover over a link without clicking, or press and hold on a phone, and the true destination appears.

Read the part immediately before the first single slash. That is the real site:

  • chase.com/login is Chase.
  • chase.com.verify-account.io is verify-account.io.

4. Notice the pressure

Your account will be closed today. Unusual activity detected. Confirm within 24 hours or lose access.

Urgency is a manufactured feeling, and it is there to stop you from doing the first three checks. When a message makes you feel rushed, that is the moment to slow down.

What to do instead of clicking

If the message might be real, go to the organization yourself. Type the address, use a bookmark or open the app. If there is genuinely a problem with your account, it will be waiting for you there.

Two things worth knowing

  • Spelling is not a reliable test anymore. Well-written phishing is now the norm, so a flawless email proves nothing.
  • A reply is a signal. Even replying "stop emailing me" confirms a real person reads that address. Delete instead.

Last updated Sep 7, 2026, 5:02 PM. Free to print and hand out. No permission needed.

Related