Guide · 8 min read

How to Spot a Phishing Email Before You Click

The old tells got filtered out. These are the checks that still work when the forgery is good, including one test that needs no judgement at all.

YeyMail Team ·

Most advice on spotting phishing was written for an easier decade. Check the spelling, look for a generic greeting, distrust anything that opens with 'Dear Customer'. Those tells were real, which is exactly why they are vanishing: a message that fails the obvious tests is a message your spam filter already caught. What reaches your inbox is, by definition, the mail that passed.

The UK's National Cyber Security Centre no longer leads with spelling mistakes. Its current guidance acknowledges that while scams used to give themselves away through bad spelling and grammar, 'scams are getting smarter and some even fool the experts'. A well-made phishing email has clean grammar, your real name, a convincing logo and a sender that looks right at a glance. If your detection method depends on the forger being sloppy, it stops working the moment the forger is not.

So this guide is built on checks that keep working when the message is well made. The first one requires no judgement at all, which is why it comes first.

Start with the address it arrived at

Before you read a single word of the message, look at which of your addresses received it. A message claiming to be from your bank that lands at an address you never gave your bank is fake, and you know that with complete certainty, without weighing logos or tone or grammar. The forgery can be perfect; it was still sent to the wrong door. Bulk phishing works from leaked and traded address lists. They know an address of yours exists, but they rarely know where you actually use it.

The honest caveat is that this check only exists if you gave different addresses to different services in the first place. If every account you own shares one address, delivery tells you nothing, because every message, genuine or fake, arrives at the same place. This is why per-site addresses, usually set up as email aliases, are a detection tool and not only a privacy one. When your bank has an address used nowhere else, any 'bank' message arriving anywhere else is disqualified on arrival. The same structure tells you who leaked your address when scams start reaching an alias you only ever gave to one shop.

A worked example. Suppose your electricity account was signed up with an address used nowhere else. A message about an unpaid bill that arrives at your general shopping address is settled before its first sentence: whatever it says, however it looks, the supplier does not have that address. No expertise was involved. The check also degrades gracefully. Even two or three separated addresses, one for money, one for shopping, one for everything else, rule out whole categories of forgery.

Two limits, stated plainly. The check does nothing for the address you have used everywhere for fifteen years; it protects the accounts you have moved to their own address, and only those. And it filters in one direction: a message at the wrong address is certainly fake, but a message at the right address is not certainly real, because the right address can leak too. Wrong address ends the analysis. Right address means you keep checking.

Read the real sender, not the display name

Your mail app shows a display name, and the display name is whatever the sender typed. 'Barclays Support' proves nothing; anyone can set it to anything. Tap or click the name to expand the actual address, then ignore everything before the @ and read the domain. That is the only part of the sender line that costs an attacker any effort.

Even the domain needs careful reading. Attackers register lookalikes, swapping characters, adding plausible words, or moving the real brand into a subdomain of a domain they own. An address at yourbank-security-team.com is not an address at yourbank.com, however official it sounds; the attacker owns it outright. The plainer failure is the brand writing from a free webmail address. A bank does not correspond from a gmail.com account, and no display name changes that.

That attacker-owned domain leads to the point most guides get exactly backwards. A message can pass SPF, DKIM and DMARC and still be a scam. Together, those checks prove the message genuinely came from the domain in the sender line (that tie to the visible sender is DMARC's contribution); they say nothing about whether that domain is honest. The DMARC specification itself is explicit that it does not address visually similar 'cousin domains' or abuse of the display name, and that a passing check does not tell the receiver the mail is good. A scammer who registers yourbank-billing.com and configures its records correctly will pass all three cleanly, and nothing in your inbox will look any different from the real thing. Authentication answers 'did this really come from that domain', never 'should I trust that domain'. We walk through what the records do and do not prove in SPF, DKIM and DMARC explained.

Read the link's real domain, right to left

Hover over a link on a computer, or press and hold on a phone, and read the URL that appears rather than the text of the link. Then read the domain the only reliable way: find the first slash after the protocol and read the hostname from its right-hand end. The owner's name is the last two labels, or the last three where the ending itself has two parts, as it does in .co.uk. That is the registered domain, and it names the owner. Everything to the left of it is a subdomain the owner invented, and an attacker controls everything to the left of a domain they own.

So https://yourbank.com.account-check.net/login is not your bank. Read left to right, it starts reassuringly; read from the right-hand end, it is account-check.net, with 'yourbank.com' as a decorative subdomain. The same trick appears as long strings of plausible words: secure-login.yourbank.verify-session.net belongs to verify-session.net and nobody else.

Shortened links and QR codes deserve the same treatment with less patience, because both exist to hide the destination until you have already committed. If you cannot see the registered domain before visiting, treat the link as unreadable and use the front-door route described below instead. And if parsing URLs under pressure feels error-prone, that instinct is correct; the strongest option is never to click at all.

Pressure is the constant

The story changes constantly; the pressure does not. The NCSC's guidance on spotting scam messages lists the same levers across every variant: authority, someone important instructing you; urgency, a deadline of hours or minutes; emotion, engineered panic, fear, hope or curiosity; scarcity, something about to run out; and current events, the news story of the week repurposed as a hook. A parcel fee, a tax refund, a suspended account and a chief executive who suddenly needs gift cards are different costumes on the same skeleton.

The deadline deserves particular suspicion, because it exists to stop you doing everything else on this page. Checking the recipient address, expanding the sender, reading a URL and phoning your bank takes a few minutes, and the attacker cannot afford minutes. Almost nothing genuine is undone by waiting an hour; real institutions send reminders, not ultimatums. Treat the demand for speed as a signal in itself, independent of everything else in the message.

TellWhat it looks likeHow reliable it is
Wrong recipient addressBank mail at an address the bank was never givenConclusive when it fires; requires per-site addresses to exist
Spelling and grammarTypos, odd phrasingWeak; well-made phishing reads cleanly
Generic greeting'Dear Customer'Weak; leaked data lets attackers greet you by name
Display nameA trusted brand as the visible senderNone on its own; anyone can set it
Sender domainLookalike or unrelated registered domainStrong, if you expand and read the real address
SPF, DKIM, DMARC passA pass in the headers; most clients show nothingProves the sending domain, not its honesty
Link destinationThe registered domain, read from the right-hand endStrong, read right to left; ignore the link text
Urgency and authorityDeadlines, threats, an important senderConstant across variants; a flag to slow down

Refuse the decision

The strongest move of all is to not decide whether the message is genuine. Both agencies give the same instruction. The NCSC says that if you have any doubts about a message you should contact the organisation directly, using details from its official website and never the numbers or addresses in the message itself. The FTC's advice matches: reach the company through a phone number or website you already know to be real, not through anything the email offers you. In practice, that means typing your bank's address into the browser yourself or opening its app, and phoning the number printed on your card or a paper statement. If your account really is suspended, the real organisation will tell you so through the front door.

Notice what this sidesteps. You never evaluate the forgery, parse the URL or judge the tone. The attacker spent their effort building a convincing message, and you declined to read it as evidence.

The case where every check fails

None of this defeats a compromised account. If an attacker takes over your colleague's mailbox, or a supplier's, the mail arrives from the genuine address, at the address you expected, passing every authentication check, sometimes as a reply inside a real thread. Recipient address: correct. Sender: real. Links: occasionally to legitimate shared documents. Account takeover is the case these checks were never going to catch, and it is worth saying so plainly rather than pretending the list above is complete.

Here the defence shifts from inspecting the message to verifying the request. Certain asks justify a second channel no matter how legitimate the mail looks: changed payment details, gift cards, credentials, anything that moves money or secrets. Phone the person on a number you already had, not one the email supplies. A genuine colleague is never offended by a thirty-second call, and an attacker is defeated by one.

Report it, then delete it

Reporting takes a minute and feeds the systems that get phishing sites taken down. In the UK, forward suspicious emails to report@phishing.gov.uk, the NCSC's reporting service. In the US, the FTC's advice is to forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, forward phishing texts to 7726, and report the attempt at ReportFraud.ftc.gov. Then delete the message. You do not need to keep it, and you certainly do not need to answer it.

The order matters. Recipient address first, because it needs no judgement. Sender domain and link domain next, read right to left. Pressure as the standing flag across everything. Out-of-band verification instead of a verdict whenever anything is unclear. And a second channel for money and credentials regardless of how the mail looks, because the one attack that beats the whole list is the one that arrives from a real account.

The YeyMail takeaway
One address per sender turns delivery into a tell

The first check in this guide only exists if your accounts do not share one address. YeyMail gives every service its own alias on a shared domain or on a domain you own, so a message claiming to be your bank that arrives anywhere else disqualifies itself before you read it, and an alias that starts receiving scams tells you exactly who leaked it. If an address is burned, you can turn it off: the kill switch rejects mail at SMTP time, so senders get a rejection rather than silence, and it keeps working even if you cancel. There is a free 7-day trial with no card, with 25 shared-domain aliases, one custom domain, and up to 20 forwarded messages a day; paid plans start at $0.99 a month.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Can an email that passes SPF, DKIM and DMARC still be a scam?

Yes. Together those checks prove the message came from the domain shown in the sender line (the tie to the visible sender is DMARC's contribution), not that the domain belongs to anyone honest. An attacker who registers a lookalike domain and configures its records correctly passes all three. The DMARC specification itself states that it does not address visually similar 'cousin domains' or display-name abuse.

Is bad spelling still a reliable sign of phishing?

No. It only ever identified the clumsy attempts, and filters catch most of those before you see them. The NCSC's current guidance notes that scams are getting smarter and some fool even experts. Treat clean, professional writing as no evidence in either direction.

What should I do if I am not sure whether an email is genuine?

Do not decide from the email. Contact the organisation through a route you already know: type its web address yourself, open its app, or phone the number on your card or a statement. Never use the contact details the message supplies, because those belong to whoever sent it.

Where do I report a phishing email?

In the UK, forward it to report@phishing.gov.uk. In the US, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org and file a report at ReportFraud.ftc.gov; phishing texts can be forwarded to 7726. Then delete the message.

How do separate email addresses help detect phishing?

If each service has its own address, the recipient address becomes a test that needs no judgement: a bank message arriving at an address the bank was never given is fake no matter how convincing it looks. The check only covers accounts that actually have their own address, and a message at the correct address still needs the ordinary checks, since the correct address can leak too.

What if a phishing email comes from someone I actually know?

Then their account may be compromised, and the sender, recipient and authentication checks all pass because the mail is technically genuine. Verify the request instead of the message: confirm anything involving money, credentials or changed payment details by phoning the person on a number you already had.

Keep reading

Guide
SPF, DKIM and DMARC, Explained Without the Jargon
Privacy guide
How to Find Out Which Company Leaked Your Email
Privacy guide
Should You Use an Email Alias for Your Bank Account?