What is phishing? Learn how phishing scams work, common phishing techniques, warning signs, and practical ways to avoid phishing emails, texts, and fake websites.
Phishing is one of the most common ways scammers try to steal information online.
You may receive an email that appears to come from your bank. You might get a text claiming that a package could not be delivered. Or you could receive a message saying your account has been locked and you need to sign in immediately.
The message may look convincing.
But the person behind it may not be who they claim to be.
That is phishing.
Phishing scams are designed to trick people into clicking links, opening attachments, sharing sensitive information, sending money, or handing over account credentials.
The good news is that once you know what phishing looks like, it becomes much easier to recognize.
This guide explains what phishing is, how phishing scams work, the warning signs to watch for, and what you can do to protect yourself.
Phishing is a type of online scam in which someone pretends to be a trusted person, company, or organization to trick you into taking an action.
That action could include:
The scammer's goal is usually to obtain something valuable, such as login credentials, personal information, payment details, or access to an account.
Phishing can happen through email, text messages, social media, websites, phone calls, and other communication channels.
Most phishing scams follow a fairly simple pattern.
First, the scammer creates a message that appears to come from someone you trust.
It could appear to be from:
Next, the message gives you a reason to act.
You might be told that there is a problem with your account, a payment needs to be confirmed, a package needs attention, or suspicious activity has been detected.
The message then pushes you toward an action, often through a link or attachment.
If you follow the instructions without checking the message, you could end up on a fake website or provide information directly to the scammer.
That is the basic idea behind many phishing attacks:
Create trust, create pressure, and encourage a quick reaction.
Phishing is not necessarily about creating a technically sophisticated attack.
Often, the scammer is trying to take advantage of normal human reactions.
People naturally pay attention when they believe:
A phishing message uses that reaction to push you toward a decision before you have time to verify what is happening.
That is why slowing down is one of the simplest ways to protect yourself.
Phishing is not limited to email.
Scammers use different channels and techniques depending on who they are targeting.
Email phishing is one of the most familiar forms.
A scammer sends an email that appears to come from a legitimate company or person.
The email may ask you to click a link, open an attachment, confirm information, or log into an account.
Some emails are sent to thousands of people at once, while others are written to look like they are specifically targeting you.
If you receive an unexpected email, inspect the sender and links before taking action.
You can also use the Scamlify Email Scam Checker to help analyze a suspicious email.
Phishing through text messages is often called SMS phishing or smishing.
A scam text might claim that:
The message may contain a link leading to a fake website.
Never assume a text message is genuine simply because it appears on your phone.
If the message is unexpected, verify it independently before clicking anything.
You can learn more in our guide on how to tell if a text message is a scam.
Spear phishing is a more targeted form of phishing.
Instead of sending the same message to a huge number of people, the scammer may research the target and create a message that appears more personal.
For example, a message might use your name, workplace, job role, or information that is publicly available online.
Because the message appears more specific, it may feel more trustworthy.
That is exactly what the scammer wants.
Business email compromise involves criminals impersonating or compromising business email accounts to trick people into sending money or sensitive information.
For example, someone may receive a message that appears to come from a manager asking for an urgent payment.
The message can seem legitimate because it uses familiar names or business information.
Unexpected payment requests should always be verified through a separate trusted communication channel.
Voice phishing, sometimes called vishing, uses phone calls or voice messages to trick people.
A scammer may claim to be from a bank, government organization, technology company, or another trusted service.
The caller may ask for personal information, passwords, verification codes, or payment.
Do not assume that a phone call is legitimate simply because the caller knows some information about you.
If you receive an unexpected message from a company you do business with, stop and think before responding.
Did you actually request a password reset?
Did you recently place the order mentioned?
Did you expect the invoice?
Did you ask the company to contact you?
If the answer is no, take extra care.
Phishing messages often try to make you feel that you have to act immediately.
Examples include:
The purpose is to stop you from taking time to investigate.
Do not let a threatening or urgent message force you into clicking a link.
Look carefully at the actual email address rather than only the name shown in your inbox.
A scammer may use an address that contains extra words, unusual characters, or a domain that does not match the organization.
A familiar display name is not proof that the email is genuine.
A phishing message may contain a link that appears legitimate while sending you somewhere completely different.
Before clicking an unexpected link, inspect its destination.
Check the main domain carefully.
If it does not match what you expected, stop.
For more information, see our guide on how to check if an email link is safe before clicking.
Be suspicious when an unexpected message asks for:
Do not provide sensitive information simply because a message asks for it.
Verify the request through an official website, app, or trusted contact method.
Attachments can create additional risks.
Be especially careful with unexpected documents, compressed files, applications, or other downloads.
If you were not expecting the attachment, verify the sender before opening it.
Phishing emails sometimes copy the appearance of legitimate companies.
You may see familiar logos, colors, or layouts.
But there could be spelling mistakes, unusual formatting, strange wording, or other inconsistencies.
Professional-looking design does not prove that a message is genuine.
Unexpected prizes, refunds, discounts, jobs, investment opportunities, or rewards can all be used as bait.
If an email promises something valuable but asks you to click a link or provide information first, stop and verify the claim.
Be cautious when someone asks you to do something unusual.
For example, a message may ask you to:
Unexpected changes should be independently verified.
You do not need to identify a specific technical problem before deciding not to click.
If the message seems unusual, unexpected, or out of place, stop.
You can always verify the situation later.
You cannot always undo information you have already shared.
When you receive a suspicious email, examine the whole message rather than focusing on one detail.
Check:
The sender: Is the actual email address consistent with the organization?
The message: Was the email expected? Does the request make sense?
The link: Where does it really go?
The request: Is it asking for money, passwords, security codes, or personal information?
The pressure: Is it trying to make you act immediately?
If several warning signs appear together, treat the message as suspicious.
For a more detailed guide, read How to Tell If an Email Is a Scam: 10 Phishing Warning Signs to Check.
You do not need to become a cybersecurity expert to reduce your risk.
A few simple habits can make a big difference.
If a message makes you feel worried or rushed, stop.
Take a moment to think before clicking.
If a message claims there is a problem with your account, open the official website or app yourself.
Do not rely on the link or phone number provided in the suspicious message.
Inspect the destination of unexpected links.
If you cannot determine where the link goes or the destination looks suspicious, do not open it.
Avoid using the same password across multiple accounts.
If one account is compromised, reused passwords can put other accounts at risk.
Multi-factor authentication adds another layer of protection to many accounts.
Even if a password is exposed, an additional authentication step can make unauthorized access more difficult.
Install security and operating system updates when they become available.
Updates can include important security fixes.
Do not open attachments simply because an email looks professional.
If the attachment was unexpected, verify it first.
No.
HTTPS helps protect the connection between your device and a website, but it does not prove that the website is legitimate.
A phishing website can also use HTTPS.
This is why you should look at the actual domain and consider how you reached the website.
A padlock or HTTPS should never be your only reason for trusting a site.
Clicking a phishing link does not automatically mean that your account has been compromised.
The risk depends on what happens after the link is opened.
You may encounter a fake login page, a request for personal information, a fraudulent payment page, or a potentially harmful download.
The most important thing is to stop before entering sensitive information or continuing with the instructions.
If you have already clicked a suspicious link, assess what happened and take appropriate steps rather than assuming the worst.
If you believe a message is phishing:
If you entered a password on a suspicious website, change the password through the legitimate website or app.
If you entered financial information, contact your bank or financial institution through an official channel.
Yes.
If you have received a suspicious email, you can use the Scamlify Email Scam Checker to analyze it for common scam and phishing indicators.
If you need to investigate technical email information, the Scamlify Email Header Analyzer can help you examine email headers.
For suspicious text messages, the Scamlify SMS Scam Checker can help you analyze the message.
These tools are designed to assist with investigation. They should not be treated as an absolute guarantee that a message is safe or malicious.
When something remains suspicious, the safest choice is to avoid clicking links or sharing sensitive information until you can verify it.
Phishing is a scam where someone pretends to be a trusted person or organization to trick you into clicking a link, sharing information, sending money, or taking another action that benefits the scammer.
Phishing scams usually create a believable story, establish a sense of trust or urgency, and then encourage the target to take an action such as clicking a link, opening an attachment, logging in, or providing personal information.
A phishing email may look like a normal message from a bank, store, employer, delivery company, or another organization. Warning signs can include an unexpected request, urgency, unusual sender address, suspicious link, attachment, or request for sensitive information.
Check the actual sender address, inspect links before clicking, consider whether you expected the message, and look for urgency or requests for sensitive information. Several warning signs together should make you cautious.
Yes. Phishing can happen through SMS and other messaging services. Scam texts often use fake delivery notices, account alerts, payment problems, rewards, or urgent requests to encourage people to click a link.
Not necessarily. An unusual email can have many explanations. However, if you cannot verify the sender or request, treat it cautiously and avoid clicking links or sharing sensitive information.
The result depends on the website and what you do after clicking. You may be taken to a fake login page, asked for sensitive information, or directed toward a harmful download. If you clicked one, stop interacting with the page and assess what information, if any, you provided.
Slow down when receiving unexpected messages, inspect links before clicking, verify important requests through official websites or apps, use strong unique passwords, enable multi-factor authentication, and keep your devices and software updated.
It is generally safer not to reply. Do not provide information or confirm that your email address is active. Use the appropriate reporting method and delete the message when appropriate.
Scamlify can help analyze suspicious emails and SMS messages for scam and phishing indicators. However, no automated checker should be treated as a perfect guarantee. Important decisions should also consider the sender, link destination, context, and other warning signs.
Phishing works because scammers try to make fake messages feel real.
They use familiar companies, urgent warnings, convincing links, fake login pages, and believable stories to get people to react quickly.
You can reduce your risk by doing the opposite.
Slow down.
Check the sender.
Inspect the link.
Question unexpected requests.
Verify important information through an official website or app.
And never let an urgent message pressure you into sharing sensitive information before you have had a chance to check whether it is genuine.
A few seconds of caution can make a big difference.