How to spot phishing
Phishing is an attempt to trick you into giving away passwords, payment details or access to your device, usually by pretending to be someone you trust.
This guide contains no partner links.
Warning signs
- Urgency or threats — “act within 24 hours”, “your account has been suspended”.
- A mismatched sender or link — the display name says your bank, but the address or the link destination belongs to another domain. On a computer, hover over a link to see where it really goes.
- Requests for credentials or codes — legitimate companies do not ask you to send your password or a two-factor code by email, message or phone.
- Unexpected attachments — especially archives, documents asking you to “enable content”, or files with double extensions.
- Too good to be true — prizes, refunds or parcels you were not expecting.
- Generic greetings and odd wording — increasingly less reliable, as scammers now write fluent text, so do not rely on spelling mistakes alone.
What to do
- Do not click links or open attachments in a suspicious message.
- Contact the organisation through a channel you already trust: its official app, or a website you type in yourself.
- If you entered a password, change it immediately, and anywhere else you used it, then check your two-factor settings.
- If you shared payment details, contact your bank at once.
- Report the message using your email provider’s “report phishing” option, and delete it.
How software helps
Browsers, email providers and security products maintain lists of known phishing sites and can warn you before a page loads. These filters catch many attacks but not all, especially new ones, so your own judgement remains the most important defence. Read more in our guide to how antivirus software works.