Back to all articles

Recognizing Phishing Emails: A Field Guide

Phishing emails have gotten harder to spot at a glance, but the underlying tactics haven't changed much. Here's what to actually look for, beyond the outdated 'watch for spelling mistakes' advice.

Phishing emails have gotten harder to spot at a glance — the crude, typo-riddled scam email of a decade ago has largely given way to polished copies of real bank and retailer templates. The underlying tactics haven't changed much, though, which means the useful advice has shifted from "look for spelling mistakes" to a handful of more reliable signals.

The sender address, not the sender name

Email clients display a sender's name prominently and the actual address in smaller text or not at all by default. A message can say "First National Bank" in bold while the actual address is something like security-alert@fnb-verify-account.com. Always check the full email address, not just the display name — this single habit catches a large share of phishing attempts on its own.

Urgency as the core mechanism

Almost every phishing email creates artificial time pressure: "your account will be suspended in 24 hours," "unusual activity detected — verify immediately," "final notice." This isn't incidental — urgency is the entire mechanism the scam depends on, because it discourages the slow, careful checking that would otherwise expose it. A genuine notification from a real company rarely demands action within hours.

Where the link actually goes

Hovering over a link (without clicking) shows the actual destination URL, usually in a small preview at the bottom of the screen. A link displayed as "Click here to verify your account" might actually point somewhere entirely unrelated to the company it claims to be from. On mobile, a long-press achieves the same preview.

Generic greetings on an email that claims urgency

"Dear Customer" or "Dear User" on a message claiming your specific account has a specific problem is a mismatch worth noticing — a real account-specific alert usually addresses you by name, since the company already has that on file.

Requests that legitimate companies don't make by email

No legitimate bank, retailer, or government department will ask you to email back your password, ID number, or full card details. Any message requesting this, regardless of how official it looks, is not legitimate.

Attachments you weren't expecting

An unexpected invoice, delivery notice, or "important document" attachment, especially from a sender you don't recognise, is one of the more common ways malware gets installed. If in doubt, don't open it — contact the supposed sender through a channel you already trust to confirm it's genuine.

What to do when you spot one

Don't click anything, don't reply, and don't unsubscribe (which sometimes just confirms your address is active to the sender). Report it if your email provider offers a "report phishing" option, then delete it. If it impersonates a company you actually deal with, consider forwarding it to that company's official fraud-reporting address — most South African banks and major retailers have one.

The habit worth building

None of these signals require technical skill — they require a brief pause before acting on any unexpected message, and a willingness to verify independently rather than through the message itself. That pause is the entire defense.