ScreenConnect Shield
All articles
Phishing 6 min read

How to Spot a Phishing Email in Under 10 Seconds

The fastest checks anyone can do before clicking a link in an email — even from senders you 'know'.

Phishing is still the #1 way personal accounts get compromised. According to the FBI's IC3 2023 Internet Crime Report, phishing was the most-reported cybercrime in the US for the fifth year running, with over 298,000 complaints. The reason it works isn't because attackers are sophisticated — it's because the emails *feel familiar*.

Modern phishing emails mimic banks, delivery services (DHL, FedEx, USPS), your IT department, and even your CEO. The good news: 90% of them can be spotted in under 10 seconds if you know what to look for.

The 10-second checklist

  1. Check the sender's full address, not just the display name. support@arn4zon-billing.com is not Amazon. Most mail clients hide the real address — tap or hover the name to expand it. The CISA Phishing Guidance explicitly calls this out as the first defense.
  2. Hover over the link without clicking. If the preview URL doesn't match the brand exactly, it's a scam. Watch for lookalike domains (paypaI.com with a capital I) and free subdomains (yourbank.security-update.net).
  3. Look for urgency or fear. "Your account will be closed in 24 hours", "Unusual sign-in detected", "Final notice" — urgency disables critical thinking. The UK's NCSC phishing guide flags this as the universal hallmark of a scam.
  4. Generic greetings like "Dear Customer" from a service that *knows* your real name = red flag.
  5. Unexpected attachments, especially .zip, .html, .iso, or .exe, almost always mean malware. Even .pdf attachments can hide credential-stealer links.
  6. Mismatched reply-to. Reply addresses that differ from the From field are a strong signal of a spoofed sender.
  7. Look at the email signature and footer. Legitimate companies have real postal addresses, unsubscribe links, and consistent branding.

What to do if you clicked

  • Disconnect from Wi-Fi immediately if you downloaded anything.
  • Change the password for the impersonated account from a *different* device, and enable an authenticator-app 2FA (not SMS).
  • Report the email to your provider — Gmail and Outlook both have a one-click "Report phishing" button. In the US, you can also forward it to reportphishing@apwg.org (see the APWG report process).
  • If you entered card details, freeze the card with your bank's app, not by calling the number in the suspicious email.

Train your eye, automatically

Even seasoned engineers fall for a well-crafted spear-phish. That's why ScreenConnect Shield runs every link you paste through a real-time phishing engine that cross-checks 40+ threat intelligence feeds, brand-similarity scoring, and AI page-cloning detection in under 200 ms. When in doubt, paste before you click.

Learn more & verify

Authoritative sources used in this article — open in a new tab.

Have a suspicious link? Don't click it.

Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.

Scan a link