Skip to content
VaultPass

Fundamentals

How to spot a phishing email in under a minute

The VaultPass desk5 min read
A fishing lure with two treble hooks

Phishing emails with spelling mistakes and blurry logos have all but disappeared. Today's are well written, use your name, and arrive exactly when you were expecting that message. Spotting them is no longer about the prose — it is about knowing which three things to check.

Phishing is the attempt to get you to hand over what they want voluntarily: a password, a verification code, a card number. Nothing needs breaking if the victim opens the door.

It works because it does not attack the technology, it attacks attention. And attention fails when there is a hurry.

The three checks that settle 95% of cases

1. The sender’s real domain

The displayed name — “Barclays”, “Royal Mail”, “Netflix” — is written by whoever sent the message. It proves nothing.

What matters is what comes after the @, and specifically its ending. Learn to read it right to left:

  • notifications@royalmail.com → the domain is royalmail.com. Legitimate.
  • notifications@royalmail.com.parcel-tracking.net → the real domain is parcel-tracking.net. Fake.
  • support@royaImail.com → a capital i standing in for the l. Fake.

The usual trick is inserting the real brand name as a subdomain of another domain. Your eye reads “royalmail.com” and relaxes. The mechanical rule: the real domain is whatever sits immediately before the first slash, or at the end if there is no slash.

On a computer, hover over the link without clicking: the real destination appears at the bottom. On a phone, press and hold until the preview shows.

The link text can say www.mybank.com and lead anywhere. It is the oldest forgery there is and it still works.

Be wary too of link shorteners in supposedly official emails: no serious institution needs to hide its own address.

3. The emotion in the message

This is the most reliable signal of all, because it is the one the attacker cannot remove: they need you to act quickly.

Be suspicious the moment any of these appear:

  • Urgency. “Your account will be suspended in 24 hours.”
  • Fear. “Unauthorised access detected.”
  • Authority. A message from the managing director asking for something odd and urgent.
  • Prize. “Your parcel could not be delivered, pay £1.95 in customs.”
  • Secrecy. “Do not discuss this with anyone on the team yet.”

No bank, no government department and no serious company resolves a grave matter by giving you fifteen minutes over email.

What no longer works as a signal

Spelling mistakes. Today’s phishing is perfectly written. The “you can tell because the translation is bad” test is finished.

The browser padlock. Almost every phishing site has a certificate and a padlock. The padlock means the connection is encrypted, not that the site is who it claims to be. This is one of the most widespread and most exploited confusions.

That it uses your name and your details. If there has been a breach, the attacker knows your name, your phone number and even what you bought. A personalised message is not more legitimate; it is more dangerous.

That it comes from a known contact. If their account has been compromised, the email leaves from their real address.

The variants worth knowing

By text message (smishing). The classic held-parcel or unpaid-fine message. Texts have no verifiable sender, so anyone can appear as “HMRC” or “Royal Mail”. Worse, fake messages often land in the same conversation thread as genuine ones, which lends them enormous credibility.

By phone (vishing). Someone calls claiming to be your bank and asks you to confirm a code that has just arrived. That code is exactly the second factor they need. No bank asks for codes over the phone. Ever.

By QR code. A sticker placed over the legitimate QR on a parking meter or a restaurant menu. Nobody can read a QR by eye, and that is the point.

Notification fatigue. If they already have your password, they send dozens of approval prompts to your phone until you accept one out of exhaustion. If that happens, do not approve: change the password, because it means they already know it.

If you think you took the bait

Act in this order, without wasting time on regret:

  1. Change the password on the affected account, going to the official site typed by hand. And change it everywhere you reused it.
  2. End open sessions from the account’s security settings.
  3. Check forwarding rules on your email, which is where persistent access hides.
  4. If you gave banking details, call the bank and block the card. The sooner, the better the odds of recovering the money.
  5. If it is a work account, tell your IT team immediately. The cost of reporting and being wrong is zero; the cost of staying quiet can be enormous.

The defence that does not depend on your attention

Everything above requires you to be alert. Two measures work even when you are not:

A password manager. It will not fill credentials into a domain it does not recognise. If you land on a perfect imitation of your bank, the manager simply offers nothing. That hesitation — “why isn’t my password coming up?” — is an automatic, free alarm.

Passkeys or physical keys. They cryptographically verify the site’s address before responding. Against a fake site they do not work, and so phishing stops paying.

In short

  • Check the real domain, the link’s real destination, and the hurry in the message.
  • Perfect spelling and the browser padlock prove nothing.
  • No bank asks for passwords or codes by phone, email or messaging app.
  • A password manager detects fake domains better than your eye does.
  • If you took the bait: change the key, end sessions, check forwarding, call the bank.

Frequently asked

The questions that keep coming up

How do I know if an email is phishing?

Check three things: the sender's real domain, where the link actually points, and whether the message is rushing or frightening you. If any of the three fails, do not interact — go to the service by typing the address yourself.

I clicked a phishing link but entered nothing. Am I at risk?

The risk is low if you only opened the page and entered no data and downloaded nothing. Even so, keep your browser and system updated, because the click also confirms your address is active.

Can phishing come from a genuine address?

Yes. If an acquaintance's or supplier's account has been compromised, the email arrives from their real address and passes every filter. That is why the content matters, not just the sender.

What should I do with a phishing email?

Mark it as phishing in your email client, not merely as spam, and delete it. If it impersonates your bank, you can forward it to the reporting address most banks publish.

Keep reading