How to Spot a Phishing Email in 10 Seconds (The 5 Checks That Catch Them All)

Tutomod • Premium content made for you.

How to Spot a Phishing Email in 10 Seconds (The 5 Checks That Catch Them All)

Phishing is the front door of nearly every major hack, and it works because it looks completely ordinary on a busy morning.

Updated August 09, 2026, after a fresh review, with updated visuals and links.

You don't need to be paranoid, you need a 10 second routine. These five checks, in order, catch essentially every attempt.

Inspecting a suspicious email
Photo by Solen Feyissa on Pexels

The fast version

  1. Check the sender's actual address, not the display name. 'Amazon Support' means nothing, anyone can type it. Tap the name to reveal the address: amaz0n-security@mail-server247.ru is the whole scam visible. Real companies mail from their own domain, not lookalikes or free providers.
  2. Hover every link before clicking. On a computer, hover and read the true destination bottom left. On phone, long press the link for a preview. If the text says 'your bank' but the link goes somewhere unpronounceable, you just dodged a bullet.

The thorough version

  1. Interrogate the urgency. 'Your account will be closed in 24 hours', 'final notice', 'immediate action required'. Manufactured panic is the fuel of phishing: real companies send polite, boring notices. Urgency plus a link equals red flag, always.
  2. Ask: were you expecting this?. An invoice from a company you never used, a package you didn't order, a password reset you didn't request. Unexpected attachments and links quarantine in your head first: don't open to 'check what it is'.
  3. When in doubt, go around the link. Worried it might be real? Don't click anything. Open your browser, type the company's address yourself, log in, and check for alerts in the official account. Real problems exist there too; fake ones evaporate.

Where people go wrong

  • Attachments named invoice.pdf.zip or .html pages asking to 'verify your account' are poison even from known addresses (friends get hacked too).
  • Don't assume mobile makes you safer: small screens hide the address bar, making taps riskier than clicks. Hover habits matter more on phones.
Checking a link before clicking
Photo by Brett Sayles on Pexels

Small tweaks, big difference

  • Enable your email's report button: Gmail and Outlook both have 'Report phishing' that trains their filters for everyone.
  • Check the greeting: 'Dear customer' from your own bank is theater, they know your name.
  • Two factor authentication turns a stolen password into a dead end even in the worst case: make sure email and banking have it.

Before you ask

I clicked a phishing link. What now?
If you only opened a page: close it, you're fine. If you typed a password: change it immediately everywhere it was used, enable 2FA, and watch the account for a few weeks.

Can spam filters just handle all of this?
They catch the bulk, but targeted attacks slip through daily. Your 10 second routine is the final layer, and it's the one attackers budget around.

Keep reading

Wrapping up

Address, hover, urgency, expectation, go around. Ten seconds of skepticism is the cheapest insurance on the internet.