How to Spot Phishing: 15 Warning Signs That Work Across Every Type of Attack

The single most effective defense against phishing is not technology — it’s awareness. Spam filters miss things. Antivirus software has blind spots. But a person who knows what to look for and takes one extra moment to evaluate a message before acting will catch phishing attempts that bypass every technical control.

This guide gives you 15 specific, actionable warning signs to look for across every delivery channel phishing uses — email, text message, and phone calls. Bookmark it. Share it with your family. These signs apply to every brand impersonation, every urgency play, and every social engineering tactic that phishing attackers use.

The Universal Warning Signs — These Apply to All Phishing

These five warning signs apply regardless of whether the phishing arrives by email, text, or phone.

Warning Sign 1: Urgency or threats with a deadline.

“Your account will be suspended in 24 hours.” “Act now or face arrest.” “Pay today to avoid service interruption.” Urgency is the most universal hallmark of phishing. It is designed to override careful thinking by creating a sense of panic or time pressure. Legitimate institutions always give you time to verify.

Warning Sign 2: Requests for sensitive information.

No legitimate entity — not your bank, not the IRS, not a government agency, not tech support — will ask you for your password, your full Social Security number, your credit card number, or your one-time verification code via email, text, or an unsolicited phone call. This is an absolute rule. There are no exceptions.

Warning Sign 3: Payment via unusual methods.

Gift cards, wire transfers, cryptocurrency, Zelle, Venmo, CashApp, or money orders are not payment methods used by the IRS, legitimate banks, government agencies, or real utilities. Any request for payment via these methods is a scam.

Warning Sign 4: Something you weren’t expecting.

A package notification when you haven’t ordered anything. A refund from a company you don’t use. A security alert from an account you don’t have. A prize from a contest you didn’t enter. Unexpected contact is a reason for heightened suspicion, not action.

Warning Sign 5: Requests for secrecy.

“Don’t tell anyone about this.” “This is a confidential business matter.” “Don’t call the bank — come directly to us.” Legitimate institutions never ask you to keep their contact secret. This is a manipulation technique designed to prevent you from getting a second opinion.

Email-Specific Warning Signs

Warning Sign 6: The sender’s email address doesn’t match the domain it claims.

The display name says “PayPal Security” but the actual address is paypal.security@notification-verify.net. In your email client, click on the sender’s name to see the actual email address. Any domain that isn’t paypal.com (or the exact official domain of the company) is fraudulent. Be alert to lookalike domains: paypa1.com, paypal-secure.com, paypal.support-center.net.

Warning Sign 7: Hover over links before clicking.

On a desktop, hover your mouse over any link to see its actual destination URL in the bottom of your browser window. The link text might say “Click here to verify your account at amazon.com” while the actual URL is something completely different. Mobile users: press and hold a link to see a preview of where it goes before tapping.

Warning Sign 8: Generic greetings.

“Dear Customer,” “Dear User,” “Dear Account Holder.” Legitimate companies that have your email address almost always also have your name. Generic greetings indicate a mass-blast campaign that wasn’t personalized.

Warning Sign 9: Unexpected attachments.

An attachment you weren’t expecting — particularly a PDF, Word document, Excel file, or ZIP archive — is a high-risk element. Malicious macros and embedded malware are often delivered this way. Even if the email appears to come from someone you know, verify before opening.

Warning Sign 10: Poor grammar, odd phrasing, or unusual formatting.

Many phishing campaigns are produced quickly or originated by non-native English speakers. Grammatical errors, unusual word choices, inconsistent fonts, and oddly formatted text are tells. That said, AI-generated phishing is increasingly grammatically perfect — don’t rely on this sign alone.

Text Message (Smishing) Warning Signs

Warning Sign 11: A link in a text from a number you don’t recognize.

A text containing a link from a random 10-digit number — or even a short code you don’t recognize — asking you to take action is suspicious. Legitimate delivery notifications, bank alerts, and government texts can usually be verified through the company’s official app or website without using the link.

Warning Sign 12: A shortened URL.

Links in scam texts are often shortened using services like bit.ly, tinyurl, or custom shorteners — because the real destination URL would be obviously suspicious. Legitimate companies send full, recognizable URLs in official text communications. Never click a shortened URL in an unsolicited text.

Warning Sign 13: The text references a service you didn’t recently use.

If you haven’t ordered a package recently, a delivery alert is suspicious. If you’re not an EZPass customer, a toll payment notice is a scam. Context mismatch is a reliable red flag.

Phone Call (Vishing) Warning Signs

Warning Sign 14: An unsolicited call from a government agency, bank, or tech company.

The IRS does not call you without first sending multiple written notices. The SSA does not call to tell you your number has been “suspended.” Microsoft does not call you about viruses on your computer. Your bank may call you to verify a transaction — but they will never ask for your full password or a one-time code during that call. Any unsolicited call from one of these types of entities should be treated as suspicious.

Warning Sign 15: Caller ID that shows a familiar or official number.

Caller ID is trivially easy to spoof. A call that displays your bank’s real phone number, the IRS’s actual 800 number, or your local police department’s number proves nothing about who is actually calling. The number you see on screen is not a verification of the caller’s identity.

Real Examples of Phishing Messages — What They Look Like

Example 1 — Classic PayPal Email Phishing:

Subject: “Your PayPal account has been limited”

From: “PayPal Service <service-paypal@mail-notifications.net>”

Body: “We’ve noticed some unusual activity in your account. To protect you, we’ve temporarily limited your account. Please click the link below to restore your access within 48 hours or your account will be permanently closed. [Verify My Account]”

Red flags: Sending domain is not @paypal.com, urgency deadline, threat of “permanent closure,” link leads to paypal-secure-accounts.net.

Example 2 — McAfee Renewal Invoice Smishing:

Text from: +1 (743) 229-4811

“McAfee: Your annual protection plan has been renewed for $399.99. To cancel, call 1-833-XXX-XXXX within 24 hours.”

Red flags: Random phone number, no link verification, amount designed to trigger panic, number connects to scammers.

Example 3 — IRS Vishing:

“This is a call from the Internal Revenue Service. There is a warrant out for your arrest for federal tax fraud. You must call 1-800-XXX-XXXX within one hour to speak with an IRS agent and resolve this matter before authorities are dispatched to your location.”

Red flags: IRS never calls about arrest warrants without prior written notice, urgency, threat of arrest, call-back number connects to scammers.

Example 4 — Geek Squad Phishing Email:

Subject: “Your Geek Squad Total Tech Support Plan has been renewed”

From: “Geek Squad Billing <billing@geeksquad-renewal.com>”

Body: “Your Geek Squad annual plan has been renewed. You will be charged $299.99 on your card on file. If you did not authorize this charge, call us immediately at 1-866-XXX-XXXX.”

Red flags: Domain is not @bestbuy.com, amount designed to shock, phone number connects to tech support scammers.

A Quick Reference Checklist

Before clicking any link, downloading any attachment, calling any number, or entering any information in response to an unexpected message, ask yourself:

□ Was I expecting this contact?

□ Does the sender’s address/number match the company it claims to be?

□ Is there unusual urgency or a threat?

□ Does it ask me to provide sensitive information?

□ Does it ask for payment by gift card, wire transfer, or crypto?

□ Does it ask me to keep something secret?

□ Does it promise something I didn’t initiate (prize, refund, package)?

If you answered “yes” to any of these questions — pause. Verify through the company’s official channel (their real website or app) before taking any action.

→ Back to Pillar: https://www.scammed.org/phishing/

→ See also: https://www.scammed.org/phishing/how-to-report-phishing/