DEFINITIONS

Introduction

Have you ever opened an email that made your stomach drop? Maybe it claimed your bank account had been locked, or that a parcel couldn’t be delivered unless you clicked a link right away. Those heart-stopping moments are exactly what phishing scammers count on. Phishing is the digital version of a con artist showing up at your door in a fake uniform, hoping you’ll hand over your keys without a second thought. Understanding what a fake email looks like—and how to tell it apart from a real one—is one of the simplest and most powerful ways to protect your money, your identity, and your peace of mind. No technical background needed; just a bit of curiosity and a healthy dose of scepticism.

Phishing email concept – laptop displaying a suspicious message

What is Phishing, Really?

Phishing is when a criminal sends you an email that pretends to be from a trustworthy organisation—your bank, an online shop, a delivery firm, or even the tax office. Their goal isn’t to sell you something. It’s to trick you into giving away sensitive details: passwords, credit card numbers, your date of birth. Once they have that, they can steal from you or impersonate you online.

Think of it like this. A stranger knocks on your door wearing a courier’s jacket and holding a clipboard. They ask for your house keys “to check the meter.” You’d probably hesitate. You’d look closely at the uniform, the ID card, the logo. Phishing emails rely on you not taking that close look. They show you a familiar company logo and a scary message, hoping you’ll react without thinking.

A typical example: you receive an email that looks like it’s from PayPal. It says there’s been suspicious activity on your account and you must click a link to verify your identity immediately. The link, however, doesn’t take you to PayPal. It takes you to a clever copycat website that records anything you type in.

The Telltale Signs of a Phishing Email

Once you know what to look for, spotting a fake email becomes a quick routine. Here are the clues I’ve learned to check every single time—and they’ve saved me more than once.

  • The sender’s address is a little off. Real companies use domains like @paypal.com or @hmrc.gov.uk. Scammers often use addresses that look similar at a glance: @paypa1.com (that’s a number one instead of the letter ‘l’), @amaz0n.co.uk, or something long and messy like @secure-login-helpers.net. On a computer, you can hover your mouse over the sender’s name; on a phone, tap the name to expand it. If the address seems strange, trust your gut.
  • A generic greeting. A legitimate email from your bank or a shop where you have an account will almost always address you by name. A phishing email often starts with “Dear Customer” or “Dear User” because the scammer doesn’t know who you are.
  • A sense of urgent threat. “Your account will be suspended in 24 hours!” “Unusual login detected—verify now to avoid losing access.” Fear makes us act fast, and scammers know this. They want you to click before you have time to think.
  • Poor spelling and odd phrasing. Many phishing emails contain spelling mistakes, strange grammar, or sentences that don’t sound quite right. A real company invests in proofreading; a criminal in a hurry often does not.
  • Suspicious links and unexpected attachments. Never click a link in a suspicious email. Instead, hover your cursor over it (or long-press on mobile) to see where it really leads. If the web address looks nothing like the company’s real website, stop. Similarly, be extremely wary of attachments you weren’t expecting—especially invoices, receipts, or delivery notices. They can hide malicious software.
  • Requests for personal information. No genuine bank or government body will ever ask you to email your password, PIN, or full card number. If an email asks for these, it’s a red flag the size of a barn door.

A helpful comparison: verifying an email is like double-checking a text message that asks for money. You’d call your friend directly using the number you already have, not the one in the message. Do the same here—type the company’s web address into your browser yourself, or call them on a phone number you’ve found independently. Don’t use the details provided in the email.

Phishing in the Real World – Could This Happen to You?

Let’s put this into two everyday situations.

Margaret, a retired teacher, receives an email from “HMRC” telling her she’s owed a tax refund of £420. The email looks official, complete with a government logo. It asks her to click a link and fill in her bank details so the refund can be processed. She feels a flutter of excitement—£420 would help with the bills. But if Margaret pauses and checks the sender address, she’ll see it’s refunds@hmrc-gov.co.uk, not the real hmrc.gov.uk. The link leads to a website that was created just days ago. By simply deleting the email and logging into her official HMRC account (or calling HMRC using the number on their website), she avoids handing her bank details straight to a criminal.

Then there’s Tom, a university student. He gets an email offering him a well‑paid part‑time job he never applied for. All he needs to do, the email says, is click a link and complete a form with his bank account number so they can “set up payments.” It sounds too good to be true—and it is. The email is generic, the grammar is shaky, and the sender’s address is a jumble of letters. Tom’s excitement could cost him his savings. Recognising the classic signs gives him the power to delete that message and move on safely.

In both cases, the scam feels personal and real. That’s the trick. Your best tool is a brief pause—a moment to look again—before you act.

Key Takeaways

  • Phishing emails pretend to be from trusted companies to steal your personal or financial information.
  • Always check the sender’s full email address, not just the display name; scammers rely on you not looking closely.
  • Be suspicious of any message that pushes for immediate action, threatens account closure, or uses a generic greeting.
  • Hover over links to preview the real web address before you click; if in doubt, don’t click at all.
  • Legitimate organisations never ask for passwords, PINs, or full card numbers via email.
  • If an email makes you feel scared or excited, that’s your cue to slow down and double‑check through official channels.
  • Trust your instincts. If something feels off, delete the email or ask someone you trust for a second opinion.

Final Thoughts

You don’t need to be a tech wizard to spot a phishing email. You just need to know the simple checks that make a fake stand out like a crooked picture frame. Each time you pause, hover, and verify, you’re building a habit that keeps you safer than any piece of software alone. Your curiosity and caution are your best defence. Keep them sharp, and you’ll never be an easy catch.