JaguarVPN logo
JaguarVPN

Security

How to spot a phishing email: 8 signs that give it away

·2 min read·JaguarVPN Team

How to spot a phishing email: 8 signs that give it away

Phishing — a message pretending to be someone you trust, designed to trick you into handing over a password or clicking something nasty — is still the most common way ordinary people get hacked. It works because a good fake looks legitimate at a glance. The defence isn’t paranoia; it’s knowing the specific tells and slowing down for half a second. Here are eight, and a rule that beats all of them.

The eight tells

1. Urgency and threats. “Your account will be closed in 24 hours.” Manufactured panic is the phisher’s favourite tool, because rushed people don’t check details. Real companies rarely threaten you into acting immediately.

2. A sender address that’s slightly off. The display name says your bank, but the actual email address is a jumble, or a lookalike domain with an extra word or a swapped letter. Always expand and read the real address.

3. Links that don’t match. Hover over a link before clicking and check where it really goes — the visible text and the real destination often differ. On mobile, press and hold to preview.

4. Generic greetings. “Dear Customer” or “Dear User” from a company that knows your name is a small but real warning sign of a message blasted to thousands.

5. Requests for information no legitimate company asks for by email — your password, your full card number, a verification code. No real bank will ever email you asking for these.

6. Attachments you weren’t expecting, especially ones asking you to “enable content”. An unexpected invoice or delivery slip is a classic malware delivery.

7. Small errors. Odd phrasing, off-brand logos, slightly wrong colours. Professional companies proofread; hurried scammers often don’t.

8. It’s too good to be true. Refunds you didn’t expect, prizes you didn’t enter, parcels you didn’t order. Curiosity is bait.

The one rule that beats them all

If a message wants you to log in or act, don’t use its link. Go to the site yourself — type the address or use your own bookmark — and check from there. If your bank really needs you, it’ll be waiting in your account when you log in the normal way. This single habit defeats almost every phishing attempt, because the whole trick depends on you clicking their link instead of taking your own route.

When you slip up

Everyone clicks the wrong thing eventually — tired, distracted, caught at a bad moment. If you entered a password on a fake page, change it immediately on the real site, and anywhere else you reused it. If you’re worried about malware, update and scan your device. And lean on the safety nets that catch mistakes: two-factor authentication can stop a stolen password from being enough, and a VPN keeps your logins encrypted on networks you don’t trust. The goal isn’t to be perfect — it’s to make a single slip survivable.

Keep reading

Ready to browse privately?

Start free trial →