Anatomy of a phishing email — the tells, and the one trick that still works
Phishing is the oldest trick on the internet and still the way most breaches begin. Here is how to read an email the way the attacker who wrote it wants you to — and the habit that beats it even when the email is perfect.
It is 4:54 on a Friday. An email lands: "Action required — your Microsoft password expires today." The logo is right. The formatting is clean. The link goes to a login page that looks identical to the one you use every morning. You are tired, you want to get out the door, so you click and you type your password. It is gone now — and depending on what that password unlocks, a lot more may be gone with it. That email cost nothing to send and went to a million inboxes at once. Here is how to take one apart.
Why phishing refuses to die
Every year brings better firewalls, better filters, and better software. And every year, phishing remains one of the most common ways attackers get their first foot in the door. The reason is simple: phishing does not attack your software. It attacks you.
You can patch a server. You cannot patch a tired human being who is in a hurry and wants to be helpful. Attackers know that a person under time pressure, facing what looks like a message from their bank or boss, will skip the careful thinking. It is cheap, it scales to millions of targets at once, and it only has to work on a handful of them to pay off.
The five classic tells
Most phishing emails still carry at least one of these. Learn to glance for them.
The sender address. The display name says "Microsoft Support," but the actual address is a string of nonsense, or a lookalike domain — micros0ft.com, microsoft-security.net. Click or tap the name to reveal the real address.
Manufactured urgency or fear. "Your account will be suspended." "Unusual login detected." "Payment failed — act now." Fear and time pressure are the attacker's main tools, because they push you to act before you think.
A link that is not what it claims. The text says one thing; the actual destination is another. On a computer, hover over the link without clicking and read the real address that appears.
An off greeting or odd phrasing. "Dear valued customer," slightly awkward wording, or a tone that is not quite how your bank or colleague writes. This tell is weaker than it used to be — more on that in a moment.
The ask. Every phish wants something: your password, a payment, a downloaded file, or a tap to approve a login. If an email is steering you toward one of those, slow down.
The one trick that still works: it looks completely right
Here is the hard truth that most "spot the phishing email" advice skips. The classic tells are fading. Attackers now use AI to write flawless, perfectly-toned messages with no typos in any language. They copy real branding pixel-for-pixel. They register convincing domains and even put a valid padlock on their fake sites.
The most dangerous phishing email is the one with none of the obvious flaws. It looks exactly like the real thing because the attacker put in the effort. Which means a defense built only on "does this email look suspicious?" will eventually fail. The visual tells help, but they are the first line, not the last.
When it is about you specifically
Mass phishing is a net thrown at millions. Spear phishing is a spear aimed at one person — and it is far more dangerous.
An attacker targeting you will do research first. Your role from LinkedIn, your manager's name, a project you are actually working on, a vendor you actually use. The email then references those real details, which makes it feel legitimate in a way a generic blast never could. This is how finance teams and executives get caught — and it is the same playbook that, taken one step further into a fake video call, cost one company 25 million dollars. The more an attacker knows about you, the less your instincts can be trusted.
What happens after you click
Say you click the link in that Friday email. You land on a page that looks exactly like your normal login. You type your username and password. Two things can happen, both bad.
The simple version: the fake page just records what you type and hands your credentials to the attacker. The advanced version: the page relays what you type to the real site in real time, so it can also capture the one-time code from your authenticator app and step straight into your account.
The page can be flawless. The branding, the layout, the padlock — all perfect. The one thing the attacker usually cannot perfectly fake is the web address in your browser's bar. That is why the URL is the single most reliable thing to check, and why the safest move is to never log in from an email link at all.
Why MFA helps — and why it is not a force field
Multi-factor authentication — the code or prompt on top of your password — is one of the best things you can turn on. It stops the large majority of attacks that rely on a stolen password alone. If you do one thing after reading this, turn it on everywhere.
But know its limits. Attackers adapt. Some spam you with approval prompts until you tap "yes" just to make the buzzing stop — a trick called MFA fatigue. Others use the real-time relay described above to grab the code as you enter it. The strongest answer is phishing-resistant MFA — passkeys or physical security keys — which are tied to the real website and simply will not work on a fake one. They take the human judgment out of the loop, which is exactly the point.
The habit that beats phishing
Because the emails are getting too good to reliably spot, the durable defense is not sharper eyes. It is a few simple habits that work even when the email is perfect.
Never log in or pay from a link in an email. If "your bank" emails you, open a new tab and type the address yourself, or use your saved bookmark. Treat urgency as a reason to slow down, not speed up — real institutions do not destroy your account in ten minutes. Verify any unexpected request for money or credentials through a separate, trusted channel before acting. And when something looks off, report it to your IT or security team rather than just deleting it — reporting one phish can get it blocked for everyone else in your organization.
What to actually do
For individuals: turn on multi-factor authentication everywhere, and use passkeys where they are offered. Get into the habit of typing addresses or using bookmarks instead of clicking email links. Hover over links to check where they really go. Verify money and password requests out of band. When in doubt, do not click — ask.
For organizations: make reporting a suspicious email a single click, and thank the people who use it. Run realistic phishing simulations so staff meet a fake in training before they meet one for real. Filter inbound mail and flag messages from outside the company. Move toward phishing-resistant MFA for anything that matters. And build payment and access processes that do not collapse the moment one person is fooled — because eventually, someone will be.