Quick Answer
Check three things before you act on any email: the full sender address (not the display name), where the link actually points when you hover over it, and whether the message creates urgency. Real companies do not demand immediate action to prevent account closure. When unsure, open the company’s app or website directly instead of clicking.
What Phishing Actually Is
Phishing is an attempt to trick you into handing over something valuable: a password, an OTP, card details, or access to your machine. The attacker impersonates a source you trust, such as your bank, your employer, a courier service, a tax department, or a colleague.
It works because it targets attention, not technology. A well-built phishing page looks identical to the real login screen. Your antivirus cannot save you from typing your own password into a convincing form.
There are several varieties worth naming:
- Bulk phishing: the same message blasted to millions of addresses.
- Spear phishing: a personalised message aimed at you specifically, using your name, role, and real colleagues.
- Whaling: spear phishing aimed at executives who can approve payments.
- Business email compromise (BEC): an attacker takes over or imitates a real internal mailbox and requests a bank transfer or invoice change.
- Smishing and vishing: the same tactics delivered over SMS and phone calls.
The 12 Warning Signs
1. The sender address does not match the brand
Display names are free to set. Anyone can call themselves “HDFC Bank Support”. Expand the header and read the actual address. Watch for extra words, hyphens, and public domains: support@hdfcbank-verify.com or hdfcsupport@gmail.com are not the bank.
2. Lookalike domain characters
Attackers register domains that read correctly at a glance: rnicrosoft.com (r plus n reading as m), paypa1.com, arnazon.in. Read the domain character by character when money is involved.
3. Manufactured urgency
“Your account will be suspended in 24 hours.” “Immediate action required.” “Final notice.” Urgency exists to stop you from thinking. Legitimate organisations give you time and multiple channels.
4. A generic greeting
“Dear Customer”, “Dear User”, “Dear Account Holder”. Your bank knows your name. That said, personalised greetings do not prove legitimacy, since breached data often includes real names.
5. A link whose destination differs from its text
Hover over the link on desktop and read the status bar. On mobile, press and hold to preview. If the text says icicibank.com and the preview shows something else entirely, stop.
6. Unexpected attachments
Especially .zip, .iso, .html, .js, and Office files asking you to enable macros. An invoice you were not expecting is an attack until proven otherwise.
7. Requests for credentials, OTPs, or card details
No bank, tax authority, or genuine company asks for your password or one-time passcode by email, chat, or phone. This rule has no exceptions and is worth teaching to every family member.
8. Slightly wrong language
Odd phrasing, inconsistent capitalisation, strange spacing before punctuation, or a tone that does not match the brand. AI-written phishing is cleaner than it used to be, so treat this as a supporting signal rather than a primary test.
9. Mismatched reply-to address
The message appears to come from one address but replies route somewhere else. Check the reply-to field in the message details.
10. A payment detail change
Any email asking you to update bank account details for a supplier, or to pay a new account “because of an audit”, should be verified by phone using a number you already have.
11. Images instead of text
Some phishing messages are a single image so spam filters cannot read the words. If a supposed invoice or notice is one big picture, be suspicious.
12. It arrives at the wrong address
An email to your personal address about your work payroll, or to an address you never gave that company, is a strong signal.
How to Check a Suspicious Email Safely
| Check | On desktop | On mobile |
| Real sender address | Click the sender name to expand full headers | Tap the sender name to expand details |
| Link destination | Hover and read the status bar | Press and hold to preview the URL |
| Domain age or legitimacy | Search the domain separately in a browser | Same, in a new tab |
| Attachment safety | Do not open. Scan or view in a sandbox | Do not open at all |
| Brand verification | Open the official app or type the URL manually | Open the official app |
The single most reliable habit: never act from the email. Open a new tab, type the company’s address yourself, and log in there. If the alert is real, it will be waiting inside your account.
What to Do If You Already Clicked
Speed matters more than embarrassment.
If you only opened the email: usually harmless. Delete it and report it.
If you clicked the link but entered nothing: close the tab, run a malware scan, and change nothing yet. Watch for unusual account activity.
If you entered your password:
- Change that password immediately from a device you trust.
- Change it anywhere else you reused it.
- Turn on two-factor authentication on the affected account.
- Sign out all active sessions from the account’s security settings.
- Check for new forwarding rules, filters, or recovery addresses added to your mailbox. Attackers add these to keep reading your mail after you regain access.
If you shared an OTP or card details:
- Call your bank’s official number and block the card.
- Report the transaction as fraudulent.
- In India, report it on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline. The first few hours matter most for recovery.
If it happened on a work machine: tell your IT or security team straight away. Delay causes more damage than the click did.
Mistakes to Avoid
- Replying to ask if it is genuine. You are confirming your address is live.
- Clicking “unsubscribe” in a phishing message. That link is part of the attack.
- Trusting a padlock icon. HTTPS means the connection is encrypted, not that the site is honest. Phishing pages have certificates too.
- Assuming a message is safe because it came from a colleague. Their account may be compromised.
- Forwarding the suspicious message to friends as a warning. Report it instead so the links do not spread.
Pro Tips
- Report phishing using your mail client’s built-in Report Phishing button. It trains the filter for everyone.
- Turn on two-factor authentication on email first. Email is the reset route into every other account.
- For any payment change request, verify by voice on a known number. Treat this as an unbreakable rule in any business.
- Keep a bookmark folder for banking and government logins so you never navigate by search or email link.
- Run a five-minute phishing awareness session with your team or family. It stops more incidents than any tool.
Frequently Asked Questions
What is the most common sign of a phishing email?
A mismatch between the display name and the actual sender address, combined with pressure to act immediately. Display names are easy to fake, so the real address is where the impersonation shows. Urgency is the second constant, since the attack relies on you reacting before you verify.
Can I get hacked just by opening an email?
Opening a plain email is almost always safe on modern mail clients. Risk begins when you click a link, open an attachment, enable macros, or enter details into a page the email sent you to. Keeping your mail app and browser updated closes the rare cases where viewing alone is risky.
How do I check if a link is safe without clicking it?
Hover over the link on desktop and read the destination in the status bar, or press and hold it on mobile to preview the URL. Read the domain immediately before the first single slash, since that is the real destination. If in doubt, type the company’s address into your browser yourself.
What should I do if I entered my password on a phishing site?
Change that password immediately from a device you trust, change it anywhere you reused it, enable two-factor authentication, sign out all sessions, and check your mailbox for forwarding rules or recovery addresses added by the attacker. If banking details were involved, call your bank and block the card.
Are phishing emails getting harder to spot?
Yes. Generative AI has removed the spelling and grammar errors that once gave phishing away, and attackers now copy real brand templates precisely. This shifts the defence from spotting bad writing to verifying sender addresses, link destinations, and requests through a separate channel.
How do I report a phishing email?
Use the Report Phishing option in Gmail, Outlook, or your mail client so the provider can block similar messages. Forward it to the impersonated company’s abuse address if they publish one. In India, financial fraud can be reported at cybercrime.gov.in or by calling 1930.

