Modern phishing emails don’t look like the obviously fake “Nigerian prince” messages anymore. The good ones are clean, well-written, and copy real company branding closely. Spotting them takes checking the right details, not just a gut feeling.
1. Check the actual sender address, not the display name
Email clients show a friendly display name like “Microsoft Support” or “Bank of America,” but that name means nothing — anyone can set it to anything. Click or tap on the sender’s name to reveal the real email address underneath. A legitimate email from Microsoft will come from a microsoft.com address, not “microsoft-support@mail-secure123.com” or a similar look-alike domain.
2. Hover before you click any link
On desktop, hover your mouse over a link (without clicking) and look at the URL preview that appears, usually in the bottom-left of your email client or browser. On mobile, press and hold the link to preview it. The displayed link text can say anything — “Click here to verify your account” — while the actual destination is a completely different, unrelated domain. That mismatch is one of the most reliable phishing signals.
3. Be suspicious of urgency and consequences
“Your account will be suspended in 24 hours,” “Unusual sign-in detected — verify now,” “Your payment failed, update your card immediately” — manufactured urgency is a deliberate tactic to get you to click before thinking. Real companies rarely threaten immediate account loss over email, and if they do, you can always verify by going directly to the company’s website yourself rather than clicking the email’s link.
4. Watch for requests that don’t match normal process
No legitimate bank, the IRS, or Microsoft will ask for your password, full Social Security number, or a gift card payment over email. Be especially wary of “invoice” or “payment” emails referencing a transaction you don’t remember making, and of any email asking you to “confirm” login credentials by typing them into a linked page.
5. Check for subtle domain look-alikes
Attackers register domains that look right at a glance: rnicrosoft.com (rn instead of m), paypa1.com (the number 1 instead of a lowercase L), or amazon-security.com (a real brand name plus extra words, but not the actual amazon.com domain). Read the domain character by character if something feels off.
6. If you’re not sure, verify independently
Don’t click anything in the email. Open a new browser tab and go directly to the company’s website by typing the address yourself, or call the phone number on the back of your card / on a past legitimate statement — never a number provided in the suspicious email itself.
If you already clicked
Change the password for that account immediately, from a different device if possible, and enable two-factor authentication if it isn’t already on. If you entered a password on a fake page, change that same password anywhere else you reused it — this is exactly why reusing passwords across sites is risky. If financial information was involved, contact your bank or card issuer right away.
The step almost everyone forgets: check for mail rules
A common move after an account is compromised is to set a quiet forwarding rule, so the attacker keeps reading your mail even after you change the password. In Gmail, open Settings → Forwarding and POP/IMAP, and Settings → Filters and Blocked Addresses. In Outlook, check Rules and Forwarding. Delete anything you did not create yourself.
While you are there, look at recent sign-in activity and sign out all other sessions. And if it was a work account, tell someone immediately rather than tomorrow — speed is what limits the damage.
The scam most likely to reach you by phone
Related and more aggressive: an unsolicited call or a full-screen pop-up claiming to be Microsoft, Apple, or your bank, warning of a virus and asking to connect to your computer. This is the single most common tech scam there is, and granting remote access hands over everything.
The rule that covers almost every version: if they contacted you, don’t grant access, don’t pay, and don’t call the number they gave you. No legitimate company calls you unprompted asking for remote access. Hang up, close the browser, and look up the real number independently.
If something got through and you want a second set of eyes on the machine, we can check it over. It is also worth reading our guide to backing up properly — a good backup is what turns a ransomware incident into an afternoon of inconvenience.
On-site and remote tech support for homes and small businesses across the Upper West Side and Manhattan.
Book a consultation (844) 915-4004
We value your opinion. If we have helped you, a quick review means a lot — leave one on Google. Thank you.
