How to Recognise Phishing Emails

Phishing is the entry point for a huge share of security problems: stolen passwords, viruses, banking scams. Learning to spot it is probably the single most useful security skill you can have.

Easy 2 min read Published on 2026 By Equipo SolucionaPC

Phishing is the entry point for a huge share of security problems: stolen passwords, viruses, banking scams. Learning to spot it is probably the single most useful security skill you can have.

The simple explanation

A phishing email is a message pretending to be from a trusted company or person (your bank, the postal service, Netflix, even a coworker) to get you to click a fake link, download a malicious file, or hand over your details directly.

Signs that give away a phishing email

1. It creates urgency or fear

"Your account will be suspended in 24 hours," "Suspicious activity detected": the goal is to get you to act fast, without thinking or checking.

2. The sender's address doesn't add up

Look at the full email address, not just the display name. An email "from your bank" that actually comes from bank-notification@mail-send23.com is a clear sign.

3. Links that don't lead where they claim

Hover your mouse over the link (without clicking) and look at the bottom left of your browser or email client: that's where the real URL it would take you to shows up.

4. Spelling mistakes and odd wording

Serious companies take great care with their communications. Spelling errors, badly translated phrases, or a strange tone are red flags.

5. It asks for details a company would never request by email

No bank is going to ask for your full password or your card's security code by email. Never.

Typical example: "We've detected a suspicious payment on your account. Verify your identity here to avoid a block" + a link to a page mimicking the bank's real design.

What to do if you suspect an email

  • Don't click any links or download any attachments.
  • Don't reply to the email, not even to "confirm it wasn't you."
  • Go to the company's official website by typing the address yourself, never from the link in the email.
  • Mark the email as phishing or spam in your email client.

Tip: turn on two-step verification on your important accounts. That way, even if someone gets your password through phishing, they can't get in without the second code.

Warning: if you've already clicked and entered your details on a suspicious page, change that password immediately from the official website, and anywhere else you use the same one.

Common mistakes

Trusting an email just because "it knew my full name" is a common mistake: that information is often publicly available or leaked in earlier data breaches, and it's no guarantee the email is legitimate.

Frequently asked questions

Does phishing only happen by email?

No, it's also very common via SMS (known as smishing), WhatsApp or social media, with the same goal: getting you to click a fake link or hand over your details.

How do I report a phishing email?

Most email clients (Gmail, Outlook) have a 'Mark as phishing' or 'Report' option directly from the message, which also helps the system get better at detecting them.

Do antivirus programs detect phishing?

Many antivirus programs and modern browsers include protection against known phishing sites, but they're not foolproof against brand-new sites. Learning to identify it yourself is still the best defence.

Share: