Email Phishing: How It Works, What It Looks Like, and How to Stop It
Email phishing is the world’s most common cybercrime delivery mechanism. Every day, an estimated 3.4 billion phishing emails are sent globally — that’s roughly 1.2 trillion per year. Despite decades of awareness campaigns and increasingly sophisticated spam filters, phishing email campaigns remain extraordinarily effective because attackers continuously adapt their techniques to bypass both technical defenses and human skepticism.
This guide explains exactly how email phishing works, what modern phishing emails look like, the most reliable warning signs, and the specific steps to take if you receive — or click — a phishing email.
—
How Email Phishing Works
An email phishing attack begins with the attacker selecting a template — typically an impersonation of a high-trust brand — and acquiring a list of target email addresses (purchased from data brokers, stolen in breaches, or harvested from the web). The email is constructed to maximize believability: copied branding, realistic sender names, and a compelling call to action.
The email is deployed in bulk — often millions of copies simultaneously — using compromised email servers or purpose-built mass mailing infrastructure that evades basic spam filters. The attacker needs only a small fraction of recipients to take action for the campaign to be profitable.
When a recipient clicks the link in the email, they are directed to a fraudulent website — a near-perfect clone of the legitimate company’s site — and prompted to enter their credentials, payment information, or personal details. Those details are captured instantly. In some variants, the link doesn’t go to a fake site at all but directly triggers a malware download.
—
What Real Phishing Emails Look Like — Examples
The PayPal Invoice Scam
You receive an email with the subject line “Your PayPal invoice is ready” or “You’ve sent a payment of $299.00.” The email has the PayPal logo, color scheme, and footer. The body says an invoice has been generated and you’ll be charged in 24 hours unless you call the cancellation number provided. The number connects to a scammer — not PayPal.
The Account Suspension Warning
“We’ve detected unusual activity on your account. Your account has been temporarily limited. Please verify your identity within 24 hours to avoid permanent suspension.” A link labeled “Verify Now” leads to a fake login page that captures your credentials.
The Security Alert
“A sign-in to your account was detected from a new location (Moscow, Russia). If this was not you, click here to secure your account.” Designed to trigger fear and immediate action, bypassing rational evaluation.
The Refund Notification
“We were unable to process your refund of $487.32. Please update your payment method to receive your refund.” Greed and curiosity make this format highly effective.
The Package Delivery Notice
“Your package could not be delivered. Please reschedule your delivery by clicking here.” Particularly effective during high-shipping periods and for frequent online shoppers.
—
10 Ways to Spot a Phishing Email
- The sending address doesn’t match the claimed sender’s domain.
Check the actual email address, not just the display name. “PayPal Security <paypal-security@notification-center-mail.net>” is not from PayPal. Legitimate PayPal emails come from @paypal.com.
- Hover over links before clicking.
Right-click or hover any link and look at the destination URL. Discrepancies between the displayed link text and the actual destination — or destinations at unfamiliar domains — are a reliable tell.
- Generic greetings.
“Dear Customer” instead of your actual name. Companies with your email address generally also have your name.
- Urgency and threats.
“Act within 24 hours or your account will be closed.” Urgency is the #1 psychological lever in phishing.
- Unexpected attachments.
Any unexpected attachment — even from someone you know — should be verified before opening. A .zip, .exe, .pdf, or Office document from an unknown sender is high risk.
- Requests for sensitive information.
No legitimate company asks for your password, SSN, or full credit card number via email.
- Offers that are too good to be true.
Unexpected refunds, prizes, or packages from companies you don’t recognize.
- Poor grammar or unusual phrasing.
Even well-crafted phishing emails often contain subtle oddities in sentence structure or word choice.
- Mismatched branding.
Logos that look slightly off, colors that aren’t quite right, or fonts that differ from the real company’s emails.
- The email is from a company you don’t use.
A Chase bank alert when you bank with Wells Fargo. A Netflix notice when you don’t have an account. These mass campaigns hit millions of addresses indiscriminately.
—
Phishing Email Examples by Category
Financial institution impersonation: Fake alerts from PayPal, Venmo, Cash App, Zelle, your bank, Coinbase. Common lures include fraud alerts, account limitations, unusual transaction notifications, and payment requests.
Antivirus/tech software impersonation: Fake renewal invoices from McAfee, Norton, Geek Squad, and Microsoft. Designed to trigger a call to a fraudulent tech support number.
Delivery and shipping: Fake USPS, UPS, FedEx, and Amazon delivery notifications, failed delivery alerts, and customs clearance fees.
Government impersonation: IRS tax notices, Social Security Administration alerts, Medicare notifications, DMV updates, and stimulus payment offers.
Streaming and subscription services: Netflix, Disney+, Spotify, Apple TV+ account suspension warnings and payment failure notices.
Workplace and productivity tools: Microsoft 365, Google Workspace, Slack, DocuSign. These target corporate credentials and are particularly common in business email compromise attacks.
—
What to Do If You Receive a Phishing Email
If you receive a phishing email and haven’t clicked anything:
– Do not click any links or download any attachments
– Do not call any phone numbers listed in the email
– Mark it as phishing or spam in your email client
– Report it to the FTC (spam@uce.gov) and to the company being impersonated
– Delete it
If you clicked a link but didn’t enter information:
– Close the browser tab immediately
– Run an antivirus scan
– Change passwords on any accounts the email referenced
If you entered information on the fake site:
– Change your password immediately on the real site
– Change any other accounts that use the same password
– Contact your bank if financial information was entered
– Enable 2FA on all affected accounts
– Monitor credit reports for new accounts
—
How to Protect Yourself From Phishing Emails
Use a spam filter. Every major email provider (Gmail, Outlook, Apple Mail) has built-in spam and phishing detection. Make sure it’s enabled and periodically check your spam folder for false positives.
Never click links in unexpected emails. Instead of clicking a link in an email, go directly to the company’s website by typing the address in your browser. If there’s really an issue with your account, it will be visible when you log in directly.
Enable multi-factor authentication. Even if a phishing attack captures your password, MFA prevents the attacker from accessing your account without the second factor.
Use a password manager. Password managers autofill credentials only on the correct domain. If you’re on a fake PayPal site, your password manager won’t fill in your credentials — because the domain doesn’t match. This is one of the most underrated anti-phishing features of password managers.
Install an anti-phishing browser extension. Tools like Google Safe Browsing (built into Chrome), Microsoft Defender SmartScreen (built into Edge), and third-party extensions like Bitdefender TrafficLight provide real-time warnings when you navigate to known phishing sites.
→ Back to Pillar: https://www.scammed.org/phishing/
→ See also: https://www.scammed.org/phishing/how-to-report-phishing/