12 Red Flags of Phishing Emails and Messages (and How to Check Any Link Safely)

Phishing is one of the most common ways scammers steal passwords, bank details, and identities. The messages keep getting more convincing — polished logos, personal details scraped from social media, even AI-generated voices. But underneath the polish, phishing attempts still follow recognisable patterns. Knowing the phishing red flags below will help you spot most attacks before you click, and the link-checking routine at the end gives you a safe way to handle anything that looks even slightly off.

The US Federal Trade Commission (FTC) puts it simply: phishing emails and text messages usually tell a story designed to trick you into clicking a link or opening an attachment — and spotting the story is the first step to stopping the scam.

The 12 Red Flags

1. Urgency, threats, and countdown pressure

“Your account will be suspended in 24 hours.” “Immediate action required.” “Final notice.” Scammers manufacture panic because panicked people do not stop to verify. The FTC notes that most unexpected emails demanding you act quickly, click a link, or call a number are phishing scams. Real companies rarely threaten account closure by email out of nowhere.

2. The sender address does not match the display name

Your inbox may show “Your Bank” or a colleague’s name, but the actual address underneath can be completely unrelated. Always expand the sender details and read the full address. A single altered character or an unfamiliar domain ending is easy to miss when you are reading quickly — and that is exactly what scammers count on.

3. Lookalike and misspelled domains

Closely related to the previous flag: domains engineered to look almost right at a glance — a well-known brand name with a letter swapped, an extra word, or an unexpected ending. Google’s phishing guidance warns that phishing content may look exactly like a message from an organisation you trust, so the domain itself has to be inspected character by character.

4. Generic greetings

“Dear customer,” “Dear user,” “Hello dear.” Legitimate companies you do business with usually address you by name. A generic greeting is not proof of phishing on its own, but combined with any other flag on this list, it strengthens the case.

5. Requests for passwords, PINs, or one-time codes

Google’s advice is direct: never respond to requests for private information over email, text message, or phone call — including usernames, passwords, PINs, bank account numbers, and government ID numbers. And the FTC adds a sharper rule: scammers try to trick you into sharing your verification passcode, so never share a one-time code with someone who contacted you first. No legitimate bank, government agency, or tech company needs you to read back a login code.

6. Links whose destination does not match the text

The clickable text says one thing; the real destination is something else entirely. Shortened links make this harder to judge at a glance. Never judge a link by its label — inspect where it actually goes before you touch it (see the safe-check routine below).

7. Unexpected attachments

An invoice you never ordered, a “document” you were not expecting, a compressed file from a stranger — attachments are a classic malware delivery method. The FTC warns that attachments and links in unexpected messages can install harmful malware. If you were not expecting a file, do not open it.

8. Too-good-to-be-true offers

“You’ve won a prize.” “Claim your government refund.” “Double your crypto.” The FTC lists fake government refunds and bogus coupons or free offers among the most common phishing stories. If you did not enter a contest or apply for a benefit, the message is not real.

9. Payment demanded by gift card, crypto, or wire transfer

Legitimate organisations do not ask you to pay overdue bills or “verification fees” with gift cards or cryptocurrency. A demand for an irreversible payment method inside an urgent message is one of the strongest phishing red flags there is.

10. QR codes that hide the destination

Scammers are now sticking their own QR codes over legitimate ones — on parking meters, in emails, and on flyers — to send victims to fake sites that steal money or personal information. The FTC advises inspecting the URL preview your QR reader shows before opening the link, and watching for spelling mistakes or switched letters in that address. A QR code is just a link you cannot read at a glance, so treat it with the same suspicion.

11. Demands for secrecy

“Do not contact anyone else about this.” “Keep this between us.” Whether the message claims to be from your boss, a government official, or a romantic partner, pressure to keep the conversation secret is designed to stop you from doing the one thing that would expose the scam: asking someone else.

12. Authority impersonation

Tax agencies, banks, law enforcement, delivery companies, tech support — scammers borrow credibility by pretending to be institutions people instinctively obey. Google notes that phishing messages may impersonate a reputable organisation or even someone you know, like a family member, friend, or coworker. Authority in a message is a claim, not a credential — verify it independently.

How to Check Any Link Safely

When a message contains a link you did not expect, run this routine instead of clicking:

  1. Stop and ask the FTC’s question: Do I have an account with this company, or do I know this person? If the answer is no, treat it as phishing — report it and delete it.
  2. Hover before you click (desktop). Rest your cursor over the link without clicking to preview the real destination. On a phone, long-press the link to preview it — but do not tap through.
  3. Read the domain, not the label. Ignore what the link text says. Look at the actual address: is it the company’s real domain, spelled correctly, with no extra words or odd endings?
  4. Go direct instead. If the message claims a problem with your account, open a new browser tab and type the company’s real address yourself, or open its official app. Never use the link, phone number, or reply button inside a suspicious message.
  5. Verify the sender separately. If it appears to come from a colleague or friend, contact them through a channel you already trust — not by replying to the suspicious message. If the account was compromised, replying just talks to the attacker.
  6. Treat attachments the same way. Unexpected file? Confirm with the sender through a separate channel before opening. When in doubt, delete it.

Red Flags Checklist

A quick-reference summary. If a message ticks several of these boxes, do not engage with it.

  • Urgent threats, deadlines, or pressure to act immediately
  • Sender address does not match the displayed name or the real company
  • Lookalike, misspelled, or unfamiliar domain
  • Generic greeting instead of your name
  • Asks for a password, PIN, or one-time verification code
  • Link destination does not match the link text, or uses a URL shortener with no context
  • Unexpected attachment, invoice, or “document”
  • Prize, refund, or investment offer you never signed up for
  • Payment demanded via gift cards, crypto, or wire transfer
  • QR code hiding where it really leads
  • Told to keep the message secret or not contact anyone
  • Claims to be from a bank, government agency, or tech company but arrived unexpectedly

What to Do If You Clicked

Mistakes happen — what matters is acting quickly:

  1. Do not enter any information. If a fake login page opened, close it immediately without typing anything.
  2. Disconnect and scan. If you opened an attachment or downloaded something, update your computer’s security software and run a full scan to remove anything malicious, as the FTC recommends.
  3. Change your passwords — starting with your email account, which is the master key to password resets everywhere else. Do this from a device you trust.
  4. Turn on multi-factor authentication on every important account if you have not already.
  5. If you shared personal or financial information, visit IdentityTheft.gov for step-by-step recovery guidance based on what was exposed.
  6. Report it. Forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, forward phishing texts to SPAM (7726), and report the attempt to the FTC at ReportFraud.ftc.gov. Reporting helps authorities track and shut down these operations.

Conclusion

Phishing works by rushing you past your own judgement. The phishing red flags in this guide — urgency, mismatched senders, lookalike domains, code requests, hidden links, QR-code tricks, and secrecy demands — are the patterns scammers return to again and again because they work. Slow down, check the sender, inspect the link without clicking, and verify through official channels. A thirty-second pause is all it takes to turn a convincing trap into an obvious fake.

Sources

  1. US Federal Trade Commission — “How To Recognize and Avoid Phishing Scams”: https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams
  2. Google Gmail Help — “Avoid & report phishing emails”: https://support.google.com/mail/answer/8253
  3. US Federal Trade Commission — “See a QR code parked somewhere? Don’t scan it…yet!”: https://consumer.ftc.gov/consumer-alerts/2026/09/see-qr-code-parked-somewhere-dont-scan-ityet
  4. US Federal Trade Commission — “Those urgent emails from MetaMask and PayPal are phishing scams”: https://consumer.ftc.gov/consumer-alerts/2023/05/those-urgent-emails-metamask-paypal-are-phishing-scams?page=0

Last reviewed: October 2026

This article is for education only and is not financial or legal advice.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top