Learn how to tell if an email is a scam. Check these 10 phishing email warning signs before you click a link, open an attachment, or share any personal information.
Email is still the single most common way people first encounter a scam. The US Federal Trade Commission reports that impersonation and phishing messages remain among the most reported fraud categories year after year, and the attackers behind them have gotten better at making messages look genuine. The good news is that almost every scam email leaves clues. You do not need technical knowledge to spot them; you need a checklist.
This guide walks through ten warning signs you can check in under a minute, plus what to do if a message fails the test. For a broader overview of how these attacks work, see our guide on what phishing is and how phishing scams work. If you want a faster answer on a specific message, you can paste it into Scamlify's Email Scam Checker, which runs these same checks automatically.
The display name ("Apple Support") is decorative. The part that matters is the address after the @. A real message from Apple comes from an @apple.com address, not @apple-security-update.com, @apple-id-verify.net, or @mail.apple-support.org.
Scammers register lookalike domains because the display name is all most people glance at. On a phone, the address is often hidden behind a "Details" tap. Make the tap. If the domain after the @ is not the company's real domain, treat the message as suspect. For a deeper walk-through of verifying the true sender, see our guide on how to check if a suspicious email is really from a company.
"Your account will be suspended in 24 hours." "Final notice." "Immediate action required." Urgency is the single most effective tool a scammer has, because it pushes you past the moment where you would normally stop and think.
Legitimate organisations rarely threaten you into acting within minutes. If a message insists you must act right now or lose access to something, that pressure is itself the warning sign. Slow down and verify through a channel you already trust.
No reputable bank, government agency, or tech company will email you to ask for your password, full card number, Social Security number, or a one-time login code. These details are never needed to "verify" your identity by email, and a request for them is almost always a phishing attempt.
Treat any email that asks you to enter credentials, payment details, or identity documents as hostile until proven otherwise. If you are unsure, log in to the service directly through its app or website, not a link in the message.
A link's visible text and its real destination are two different things. On a computer, hover over the link and read the URL that appears in the bottom corner of your browser. On a phone, press and hold the link to preview it without opening it.
Watch for:
When in doubt, do not click. Go to the website directly by typing the address yourself.
"Dear Customer." "Dear account holder." "Hi user." Real companies you have a relationship with know your name and usually use it. Mass-produced phishing emails are sent to millions of recipients at once, so they default to a generic salutation.
A generic greeting on its own is not proof of a scam; some legitimate bulk mail uses it too. But combined with any other sign on this list, it strengthens the case.
Modern scam emails are often well-written; many are generated or polished with AI. But plenty still contain obvious errors: misspelled brand names, broken sentences, odd phrasing, or inconsistent capitalisation.
Pay special attention to the brand name itself. "PayPaI", "Microsft", "Netfl ix". A company will almost never misspell its own name in an official message. One typo in a brand name is a strong signal the message did not come from that brand.
Attachments are a common delivery method for malware and credential-theft tools. Be wary of any attachment you were not specifically expecting, especially:
If someone genuinely needs to send you a file, you usually know it is coming. When in doubt, contact the sender through a separate, trusted channel before opening anything.
"You've won a prize." "Refund of £480 waiting for you." "Exclusive investment returning 12% per week." If an email offers money, a prize, or a return that you cannot explain, the explanation is usually that someone is trying to take money from you rather than give it to you.
The FTC publishes regular guidance on recognising prize and refund scams, and the pattern is consistent: the message creates excitement, then asks for a fee, a payment detail, or account access to "release" the reward. Real winnings do not require you to pay first.
Look at the footer and signature block. Legitimate companies include real contact information: a postal address, a registered phone number, links to genuine help pages. Scam emails often include a phone number that does not match the company's published number, or a "support" link that points to a lookalike domain.
A useful check: search the phone number or address independently. If it does not appear on the company's official website, do not trust it.
"Keep this confidential." "Don't tell anyone in the office." "Reply to this private address instead of the company system." Any message that tries to move you away from your normal, monitored channels (your work email, your bank's in-app messaging, your IT helpdesk) is trying to isolate you from the people who would tell you it is a scam.
This pattern is especially common in business email compromise, where a fake "CEO" or "supplier" asks for an urgent payment to be made quietly. The secrecy is not a coincidence; it is the mechanism that makes the fraud work.
If a message shows one or more of these signs, do not click any links, do not open attachments, and do not reply. Then:
Yes. Modern phishing kits clone the exact branding, layout, and even the real website's logos and fonts. That is why the visual appearance of an email is the least reliable signal. The sender's domain, the link destinations, and the behaviour the email asks for are far harder for an attacker to fake convincingly.
No. Clicking a link can trigger tracking pixels, install malware through drive-by downloads, or load a credential-harvesting page that looks identical to the real one. Preview the destination by hovering or long-pressing instead, and only visit a site by typing the address yourself if you are unsure.
Act quickly. If you entered a password, change it immediately on the real site and enable two-factor authentication. If you entered payment details, contact your bank's fraud department. If you opened an attachment, disconnect from the internet and run a malware scan. The faster you respond, the more you limit the damage.
Most of them do. Smishing (SMS phishing) uses the same urgency, impersonation, and suspicious-link tactics. The sender ID is even easier to spoof than an email address, so treat any text containing a link and a sense of urgency with the same caution. For the SMS-specific checklist, see our guide on how to tell if a text message is a scam.