IsThisAScam
StartseiteBlogPreiseÜber UnsHistoryAPIExtension
Upgrade
DE
Sign in
Sign in
IsThisAScam

Independent scam & phishing analysis. Free for individuals. APIs for developers.

Operated by Zeplik, Inc.
Produkt
  • Home
  • Blog
  • Pricing
  • Über Uns
  • History
  • Chrome Extension
Resources
  • Developers
  • API-Dokumentation
  • Phishing brief
  • Romance scams
  • Tech support
  • Crypto scams
  • Apple scams
  • PayPal scams
Rechtliches
  • Datenschutzrichtlinie
  • Nutzungsbedingungen
  • product@zeplik.com

© 2026 Zeplik, Inc. Alle Rechte vorbehalten.

Built for the calm, the cautious, and the careful.

Home/Guides/Phishing Email
Step-by-Step Guide

How to Spot a Phishing Email.

Phishing emails are the most common cyber threat, with over 3.4 billion sent daily. This guide teaches you exactly what to look for so you can identify a phishing email in seconds, even when it looks completely legitimate.

Not sure about an email?

Paste it here — our AI checks sender authentication, links, and manipulation patterns.

No signup · 6 detection layers · Results in seconds · Cmd+Enter

01Check the sender's full email address.

Don't just look at the display name — expand it to see the full email address. Scammers set display names like "PayPal Support" but send from random addresses like support@paypal-secure-verify.com. The domain after the @ sign must match the company's official domain exactly.

Tip

Hover over the sender name in your email client to reveal the real address. On mobile, tap the sender name.

02Look for urgency and pressure tactics.

Phishing emails almost always create urgency: "Your account will be suspended in 24 hours," "Unauthorized purchase detected — act now," or "Final warning before legal action." Legitimate companies rarely use this level of pressure in routine communications.

Tip

If an email makes you feel panicked or rushed, that's a red flag. Real emergencies are handled through official channels, not mass emails.

03Hover over links before clicking.

Before clicking any link, hover your mouse over it (or long-press on mobile) to see the actual URL. Phishing links often use lookalike domains (amaz0n.com), long URLs with the real domain buried deep in the path, or URL shorteners to hide the destination.

Tip

The domain name is the part right before the .com/.org/.net. Everything before it is a subdomain that anyone can create.

04Examine the greeting and personalization.

Legitimate companies that have your account use your real name. Phishing emails often use generic greetings: "Dear Customer," "Dear User," "Dear Account Holder." Some sophisticated phishing uses your name (from data breaches), but generic greetings are still a strong indicator.

Tip

Even if the email uses your name, apply all other checks. Scammers can obtain names from data breaches, social media, or company directories.

05Check for poor grammar and formatting.

While AI has improved phishing quality, many scam emails still contain telltale errors: unusual word choices, awkward phrasing, inconsistent formatting, mixed fonts, or logos that look slightly off. Compare the email's style with previous legitimate emails from the same company.

Tip

Note: AI-generated phishing emails are increasingly error-free. Don't rely on grammar alone — use all the checks in this guide.

06Verify requests for personal information.

No legitimate company will ask you to provide passwords, full credit card numbers, Social Security numbers, or PINs via email. If an email asks for this information, it's a scam — regardless of how official it looks.

Tip

When in doubt, contact the company directly using the phone number on their official website — not any number in the email.

07Check for suspicious attachments.

Be extremely cautious with email attachments you weren't expecting. Dangerous file types include .exe, .scr, .zip, .js, and macro-enabled documents (.docm, .xlsm). Even PDF and Word files can contain malware. If you weren't expecting an attachment, don't open it.

Tip

If you need to view an attachment from an unknown sender, open it in Google Docs or another online viewer rather than downloading it to your computer.

Quick checklist.

[ ]Sender's email domain matches the official company domain
[ ]No urgency language or threats of account suspension
[ ]Links point to the official company website
[ ]Greeting uses your real name (not "Dear Customer")
[ ]No spelling or grammar errors
[ ]No request for passwords, PINs, or financial information
[ ]No unexpected attachments
[ ]The email matches the company's usual communication style
Learn More
Read the full Phishing scam brief →
Related Guides
Fake WebsiteText Message ScamSocial Media Scam
Suspect Something?

Run a scan on the message you received.

Run a scan →