How to Spot a Phishing Email in Under 10 Seconds
The fastest checks anyone can do before clicking a link in an email — even from senders you 'know'.
Phishing is still the #1 way personal accounts get compromised. According to the FBI's IC3 2023 Internet Crime Report, phishing was the most-reported cybercrime in the US for the fifth year running, with over 298,000 complaints. The reason it works isn't because attackers are sophisticated — it's because the emails *feel familiar*.
Modern phishing emails mimic banks, delivery services (DHL, FedEx, USPS), your IT department, and even your CEO. The good news: 90% of them can be spotted in under 10 seconds if you know what to look for.
The 10-second checklist
- Check the sender's full address, not just the display name.
support@arn4zon-billing.comis not Amazon. Most mail clients hide the real address — tap or hover the name to expand it. The CISA Phishing Guidance explicitly calls this out as the first defense. - Hover over the link without clicking. If the preview URL doesn't match the brand exactly, it's a scam. Watch for lookalike domains (
paypaI.comwith a capital I) and free subdomains (yourbank.security-update.net). - Look for urgency or fear. "Your account will be closed in 24 hours", "Unusual sign-in detected", "Final notice" — urgency disables critical thinking. The UK's NCSC phishing guide flags this as the universal hallmark of a scam.
- Generic greetings like "Dear Customer" from a service that *knows* your real name = red flag.
- Unexpected attachments, especially
.zip,.html,.iso, or.exe, almost always mean malware. Even.pdfattachments can hide credential-stealer links. - Mismatched reply-to. Reply addresses that differ from the From field are a strong signal of a spoofed sender.
- Look at the email signature and footer. Legitimate companies have real postal addresses, unsubscribe links, and consistent branding.
What to do if you clicked
- Disconnect from Wi-Fi immediately if you downloaded anything.
- Change the password for the impersonated account from a *different* device, and enable an authenticator-app 2FA (not SMS).
- Report the email to your provider — Gmail and Outlook both have a one-click "Report phishing" button. In the US, you can also forward it to
reportphishing@apwg.org(see the APWG report process). - If you entered card details, freeze the card with your bank's app, not by calling the number in the suspicious email.
Train your eye, automatically
Even seasoned engineers fall for a well-crafted spear-phish. That's why ScreenConnect Shield runs every link you paste through a real-time phishing engine that cross-checks 40+ threat intelligence feeds, brand-similarity scoring, and AI page-cloning detection in under 200 ms. When in doubt, paste before you click.
Learn more & verify
Authoritative sources used in this article — open in a new tab.
Have a suspicious link? Don't click it.
Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.
Scan a link