In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — more than any other cybercrime category. That number has only climbed since. I've investigated breaches at organizations of every size, and the entry point is almost always the same: one employee who couldn't spot a phishing email fast enough.
Knowing how to spot phishing emails isn't a nice-to-have skill anymore. It's the single most effective thing you and your team can do to prevent a data breach, ransomware infection, or credential theft event. This post breaks down the exact red flags I teach security teams to look for — with real examples, not theory.
Why Phishing Still Works in 2026
Phishing isn't a new attack. It's been around for decades. So why does it still work? Because threat actors have gotten significantly better at it. Modern phishing emails don't come from Nigerian princes. They come from spoofed Microsoft 365 login pages, fake HR portals, and AI-generated messages that mimic your CEO's writing style.
According to Verizon's 2024 Data Breach Investigations Report, the human element was involved in 68% of breaches. Phishing and social engineering remain the top initial access vectors. The attackers aren't breaking through your firewall — they're walking through your front door because someone held it open.
The problem isn't stupidity. It's speed. People check email on phones between meetings, first thing in the morning before coffee, and late at night. That's exactly when threat actors want you reading their messages.
The 8 Red Flags That Give Away a Phishing Email
Here's what I train organizations to look for. These are the real indicators — the ones that actually matter in a production inbox, not a textbook.
1. Sender Address Doesn't Match the Brand
This is the first thing to check and the most commonly missed. A phishing email might display "Microsoft Support" as the sender name, but the actual address reads something like [email protected]. Always expand the sender field. On mobile, tap the name to reveal the full address.
2. Urgency and Threats
"Your account will be suspended in 24 hours." "Unauthorized login detected — act now." Threat actors manufacture panic because panicked people skip verification steps. If an email demands immediate action, that's your signal to slow down.
3. Generic Greetings
"Dear Customer" or "Dear User" from a service that definitely knows your name? That's a mass-blast phishing campaign. Legitimate services personalize communication. Not every phishing email uses generic greetings — sophisticated ones won't — but it's still a reliable early indicator.
4. Suspicious Links
Hover before you click. Every time. On desktop, your browser or email client will show the actual URL in the bottom-left corner. If the link text says "login.microsoft.com" but the hover reveals "login-microsoft.security-verify.ru," you've just caught a phishing attempt. On mobile, long-press the link to preview it.
5. Unexpected Attachments
If you weren't expecting a file — especially a .zip, .exe, .docm, or .html attachment — don't open it. These are common ransomware and malware delivery mechanisms. Even PDFs can contain malicious links. Verify with the sender through a separate channel before opening.
6. Mismatched or Slightly Off Branding
Blurry logos, wrong colors, inconsistent fonts, or outdated branding. Threat actors clone corporate templates, but they rarely get every detail right. Compare suspicious emails to legitimate ones from the same sender. Small visual discrepancies often reveal the deception.
7. Requests for Credentials or Sensitive Data
No legitimate organization will ask you to reply to an email with your password, Social Security number, or banking details. If an email asks you to "verify" or "confirm" sensitive information, it's almost certainly a phishing attempt or a social engineering play.
8. Poor Grammar and Odd Phrasing
This red flag is less reliable than it used to be — AI tools have dramatically improved phishing copy. But awkward phrasing, unusual word choices, and grammatical errors still show up in high-volume campaigns. Don't rely on this alone, but don't ignore it either.
What Does a Phishing Email Actually Look Like?
Here's a common scenario I use in phishing awareness training for organizations: an employee receives an email that appears to come from IT, requesting they reset their password via an embedded link. The email uses the company's logo, references the correct email domain, and even includes a ticket number.
The only giveaway? The sender address is off by one character, the link points to an external domain, and the email was sent at 2:47 AM from a time zone where nobody in IT works. Three red flags, all subtle, all catchable — if you know what to look for.
That's the gap training closes. People don't fail phishing simulations because they're careless. They fail because nobody showed them specifically what to examine.
The $4.88M Lesson Most Organizations Learn Too Late
IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million. Phishing was the most common initial attack vector. For small and midsize businesses, a single successful phishing email can mean regulatory fines, legal costs, lost customers, and operational downtime that takes months to recover from.
Multi-factor authentication helps. Zero trust architecture helps. But neither eliminates the risk entirely if your people can't recognize a phishing email before they interact with it. Technology is a safety net. Human awareness is the first line of defense.
How to Spot Phishing Emails: A Quick-Reference Checklist
If you're building a security awareness program or just want a personal reference, here's the condensed version:
- Check the sender's full email address — not just the display name.
- Hover over every link before clicking. Verify the domain matches the claimed sender.
- Watch for urgency or threats designed to bypass your judgment.
- Don't open unexpected attachments without verifying through a separate channel.
- Look for personalization — or the lack of it.
- Compare branding against known legitimate emails.
- Never submit credentials via an email link. Go directly to the service's website instead.
- Report suspicious emails to your IT or security team immediately.
Print this. Post it in break rooms. Include it in onboarding packets. The simpler the reference, the more likely people will actually use it.
Phishing Simulations Are Non-Negotiable
Reading about red flags is one thing. Recognizing them under pressure is another. That's why phishing simulation programs exist — they give your employees realistic practice in a controlled environment.
I've seen organizations cut their phishing click rates by over 60% within six months of implementing regular simulations combined with targeted training. The key is consistency. One annual training session doesn't change behavior. Monthly simulations with immediate feedback do.
CISA's phishing guidance for organizations recommends ongoing training as a core component of any cybersecurity program. If your organization hasn't started yet, our cybersecurity awareness training program is designed to get your team up to speed quickly with practical, scenario-based learning.
What to Do When You Catch One
Spotting a phishing email is only half the battle. What you do next matters just as much.
Don't Click, Don't Reply, Don't Forward
Interacting with a phishing email in any way can trigger tracking pixels, confirm your address is active, or worse. Leave it alone.
Report It Immediately
Use your organization's phishing report button if one exists. If not, forward the email to your security team with full headers. Speed matters — if one person received it, others likely did too.
Change Credentials If You Clicked
If you already clicked a link or entered credentials, change your password immediately. Enable multi-factor authentication if it isn't already active. Notify your IT team so they can check for unauthorized access.
Phishing Evolves — Your Defenses Must Too
The phishing emails of 2026 look nothing like those from even three years ago. AI-generated content, deepfake voice messages attached to emails, QR code phishing (quishing), and multi-stage attacks that start with a harmless first email before delivering the payload in a follow-up — these are all active techniques in the wild right now.
Knowing how to spot phishing emails today means staying current with how attacks are evolving. Static training decks from 2022 won't protect your team against 2026 threats. Invest in training that updates regularly and reflects real attack patterns.
The NIST Small Business Cybersecurity Corner offers additional resources for organizations building out their defenses. Pair that guidance with hands-on training and regular phishing simulations, and you'll have a program that actually moves the needle.
Your inbox is the most attacked surface in your organization. Treat it that way.