Phishing emails are designed to make you act fast, before you think too hard. Slowing down for even 30 seconds catches most of them. Here's what to check.

1. Look at the actual sender address, not just the name

"Amazon Support" can say whatever it wants in the display name, but the real address next to it might be something like support@amaz0n-verify.ru. Tap or hover on the sender's name to see the real address underneath.

2. Urgency and threats are a red flag by design

"Your account will be closed in 24 hours." "Unusual activity detected. Verify now." Real companies rarely create this kind of panic in an email. Scammers do it deliberately, because panicked people don't stop to check.

3. A generic greeting on something that should be personal

"Dear Customer" or "Dear User" from a company that actually has your name on file is a small but real tell. Not proof on its own, but worth noticing.

4. Hover Over Links Before Clicking (Don't Tap on Your Phone)

On a computer, hover your mouse over a link (without clicking) and look at where it actually points, usually shown at the bottom of the window. If the visible text says "yourbank.com" but the real link goes somewhere else entirely, that's the scam. On a phone, press and hold the link instead of tapping it to preview the address.

5. Unexpected attachments, especially .zip or .exe files

An invoice or document you weren't expecting, from someone you weren't expecting it from, is one of the most common ways malware actually gets onto a computer. When in doubt, don't open it. Ask the sender directly, through a different channel, whether they actually sent it.

One habit that helps more than any checklist

Use a password manager, and turn on two-factor authentication wherever it's offered. Even if a phishing email does trick you into typing a password somewhere it shouldn't go, a password manager means that password is unique to one site. It can't be reused to break into your other accounts. I've got a couple of free, trusted options on my software page.

See the password managers I recommend →

Or print the one-page phishing checklist to keep by the desk →