
Look for four things before you trust any email. Does the sender's actual email address, not just the display name, match the company's real domain. Is the message pushing urgency or fear to get you to act fast. Does hovering over any link show a destination that matches the real company domain, not a lookalike or a shortener. And is it asking you to type a password, PIN, 2FA code, or payment details through the email itself, something legitimate companies almost never do by email. Any one of these is a warning sign. Two or more together means it's almost certainly phishing. If you already clicked, close the tab if you didn't enter anything, or change the password immediately (typed manually on the real site, not through the email link) if you did.
The display name on an email is just text the sender chooses. It costs nothing to type "PayPal Support" or "Microsoft Security Team" into that field, regardless of where the message actually came from. The part that matters is what comes after the @ symbol in the full email address, and most mail apps hide that by default, showing only the friendly name.
Tap or click on the sender's name to expand the full address. Then compare it carefully to the company's real domain. Scammers rely on you skimming, so the fakes are built to survive a glance: an extra letter (paypa1.com), a swapped character (rnicrosoft.com), an added word or hyphen (amazon-security.com), or a domain that puts the real brand name as a subdomain of something else entirely (paypal.com.account-verify.net, where the actual domain is account-verify.net, not paypal.com). The real domain is always the part immediately before the final dot-something, reading right to left from the @ symbol.
"Your account will be suspended in 24 hours." "Suspicious login detected, verify now." "Unpaid invoice, action required immediately." These messages are built to make you react before you think. Fear and time pressure are the single most consistent pattern across phishing attempts, because they short-circuit the careful checking that would otherwise catch the fake sender or the fake link.
Real companies do send security notifications and do have real deadlines, so urgency alone isn't proof of a scam. What's telling is the combination: urgency plus a demand to act right now through a link in the email, rather than by logging into the app or site you already know and trust. If a message makes your stomach drop and pushes you toward an immediate click, that's exactly the moment to slow down, not speed up.
A link's visible text and its actual destination are two completely separate things. A link that reads "Sign in to your account" can point anywhere the sender wants. Before clicking anything in an email you weren't expecting:
Companies you actually have an account with already know your name, and usually a detail like the last four digits of a card or account number, because you gave it to them. Their real emails tend to reflect that: "Hi Sarah," or "Your Visa ending in 4821 was charged $54.00," not "Dear Customer" or "Valued User." A generic greeting from a company that should know exactly who you are is worth a second look.
That said, treat this as one signal among several, not a guarantee. Scammers increasingly personalize phishing emails using names and details pulled from old data breaches or public profiles, so a message that gets your name right isn't automatically safe. Use the greeting as a tiebreaker alongside the sender domain and link checks, not as the deciding factor on its own.
Banks, payment processors, tax agencies, and major tech companies almost never ask you to type a full password, a PIN, a one-time 2FA code, or a credit card number by clicking a link and filling out a form. Their actual security practice is the opposite: they tell you to log in independently, through the app or by typing the known address yourself, precisely because email is such an easy channel to spoof.
Treat any of the following as a serious red flag, regardless of how convincing the rest of the email looks:
If you opened an attachment or entered credentials somewhere and you're not sure what, if anything, installed or changed on your device, we connect remotely, check for malware, review your account security, and confirm you're clean, or fix it if you're not. Flat $79.99 USD, any time zone, No Fix No Fee.
Get help now — $79.99If the account involved uses two-factor authentication tied to a phone number or authenticator app, and you're worried the attacker also has access to that, our guide on restoring authenticator codes after a phone change covers how to regain control without locking yourself out.
We help travelers with this from wherever you are:
Check four things before you trust any email: does the sender's actual email address, not just the display name, match the company's real domain, is the message creating urgency or fear to rush you into acting, does hovering over any link show a destination that matches the real company domain, and is it asking you to enter a password, PIN, 2FA code, or payment details through the email itself. Any one of these on its own is a warning sign. Two or more together means it's almost certainly phishing.
If a login page loaded and you didn't enter anything, just close the tab, no harm done. If you typed in a password, go to the real site directly by typing the address yourself, not through the email link, and change that password immediately, along with any other account using the same password. Turn on two-factor authentication if it isn't already active, run a malware scan if you opened an attachment, and keep an eye on your bank and account activity for the next few weeks.
Yes. Modern phishing kits copy logos, colors, and formatting almost pixel for pixel, so visual polish tells you nothing about legitimacy. The reliable signals are the sender's actual domain, where links really point when you hover over them, and whether the email is asking for something a real company wouldn't ask for by email, like a password or a gift card payment.
Urgency and fear are deliberate tactics. A message that says your account will be suspended in 24 hours, or that flags a suspicious login demanding immediate action, is designed to make you click before you stop to check the sender's domain or where the link actually goes. Legitimate security alerts exist, but real companies don't pressure you to act instantly through an emailed link with a countdown attached.