Technology · Cybersecurity

How to Spot a Phishing Message Before You Click

Phishing no longer comes with spelling mistakes. These are the signals that still work, and exactly what to do in the first ten minutes if you fall for one.

A suspicious message on a phone screen with a security warning
Janitors · CC BY 2.0
Advertisement
Advertisement

"Watch for spelling mistakes" is obsolete advice. Phishing today is written in clean prose, carries real logos, and sometimes addresses you by name with a correct account number.

The signals that still work are different — and the strongest one is not in how the message looks, but in what it asks for and how it makes you feel.

The short answer

Do not judge a message by appearance. The three patterns that give it away are manufactured urgency ("your account closes in 24 hours"), a request no genuine organisation ever makes (your password or a verification code), and a domain that does not match. When in doubt, close the message and go to the site yourself.

Urgency is the first signal

Every successful phishing attempt needs you to act before you think. That is why almost all of them manufacture time pressure:

  • "Your account will be suspended within 24 hours"
  • "Suspicious login detected — confirm your identity now"
  • "Your parcel is held, pay the clearance fee today"
  • "You have won a prize, claim it before it expires"

Banks and government offices do not work this way. Real processes arrive dated, with reasonable deadlines, through more than one channel.

The working rule: the more urgent it feels, the more you should slow down. That inversion is your best defence, because it works even when the message is technically flawless.

What nobody legitimate asks for

No genuine organisation will ever ask — by any channel — for:

  • Your full password
  • The verification code that just arrived
  • Your full card number with expiry and security code
  • You to install a "support" app from a link in a message

The verification code is the dangerous one. The common scam: someone calls posing as your bank, says they are verifying your identity, and asks for the code that just arrived. That code is what they need to get into your account. You are the one opening the door.

This is where most of the deception happens. A web address is read from the left up to the first single slash — the last part before it is the real domain. Everything after is decoration.

LinkReal domainVerdict
bank.com/loginbank.comGenuine
bank.com.verify-id.net/loginverify-id.netPhishing
secure-bank.com/loginsecure-bank.comA different domain entirely
bank-secure.co/loginbank-secure.coDifferent suffix

The second row is the most effective trick: the real domain appears first, but it has become a subdomain of the attacker's site.

On a computer: hover without clicking; the destination appears at the bottom of the window. On a phone: press and hold until a preview appears.

The independent channel

This is the one rule that works against even the most sophisticated attack, and it needs no technical skill:

Never use the contact method that came in the message.

Got a message from your bank? Do not click the link or call the number in it. Open your banking app yourself, or call the number printed on your card.

If the message was real, you will find the same notification in your account. If you find nothing, you have your answer.

That is the difference: you are not trying to judge the message — you are bypassing it entirely. Which is why it holds even when the message is perfect.

Common variants

Parcel fees. A message asking for a small sum to release a delivery. The amount is small on purpose so you do not hesitate — the target is your card details, not the fee.

Contact impersonation. A message from an unknown number: "this is my new number, I need an urgent transfer." Call the old number first.

Fake job offers. High pay for few qualifications, then a request for a registration fee or bank details.

Stolen-account follow-up. After an account is taken over, messages go to its contacts appearing to come from a real friend — which is what makes them work.

If you clicked and entered your details

Act in this order; speed genuinely matters:

  1. Change the password immediately for that account, and for any other account using the same one.
  2. Turn on two-factor authentication if it is not already on.
  3. Call your bank if card details were involved, and have the card stopped.
  4. Review active sessions in the account's security settings and end anything you do not recognise.
  5. Watch your accounts for two weeks — small test charges usually precede large ones.

Do not delay reporting out of embarrassment. Well-made phishing fools security professionals too; what makes the difference is how fast you move afterwards.

Advertisement
Advertisement

Frequently asked questions

How do I check a link before clicking?

On a computer, hover over the link without clicking and the real destination appears at the bottom of the window. On a phone, press and hold until a preview shows. What matters is the domain immediately before the first single slash.

The message has the bank's logo and my real name — surely it is genuine?

No. Logos are copied in seconds, and names and account numbers leak from other sites' breaches. How a message looks tells you nothing about where it came from.

I clicked but did not enter anything. Am I at risk?

Far less. Simply opening a page is rarely enough on its own. Watch your accounts, run a scan, and do not enter anything if the page asks again.

How do I verify a call is really from my bank?

Hang up and call the number on the back of your card or on the official website. Never use a number the caller gives you. A genuine caller will not object.

What is the most dangerous kind?

Targeted phishing, where the sender knows your name, your employer and possibly a real transaction you made. It cannot be spotted by appearance — only by one rule: verify through an independent channel before any transfer or credential.

Sources

  1. CISA — Avoiding social engineering and phishing attacks
Corrections

Found an error? Email us and we will fix it and note the change at the bottom of this article. Hello@daily-atlas.com

Related reading