How to Spot a Phishing Email: Red Flags and Verification

The Quick Read

Phishing emails impersonate a sender you trust, usually to steal a password or to install malware. CISA and the FTC publish overlapping checklists of red flags, and they all point at the same few signals: urgency, requests for personal data, look-alike domains, and untrusted shortened links. [1] [2]

AI-written phishing has mostly killed the "bad grammar" tell. CISA's own guide now warns that "in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling." [1] What still gives the email away is the sender address, the link destination, and the request. This guide walks through both.

Why the Stakes Are High

A phishing email is not just spam. It is a credential-theft attempt. CISA documents a "login credential phishing attempt" in which a victim named Omar clicked a fake "payment didn't go through" link and handed over his password and credit card details to a fraudulent website that mimicked the real login. [1]

Once an attacker has a password to one account, the damage spreads. The FTC's consumer guide notes that phishing is paired with "multi-factor authentication bypass attempts" and that attachments and links in phishing messages "might install harmful malware" on the device. [2] The single email is rarely the end of the attack.

What CISA and the FTC Agree On

Both agencies publish red-flag checklists. Read them next to each other and they describe the same email.

CISA's official guide lists these common signs: [1]

  • "Urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately"
  • "Requests to send personal and financial information"
  • "Untrusted shortened URLs"
  • "Incorrect email addresses or links, like amazan.com"

The FTC's phishing page lists the same family of tells: [2]

  • A generic greeting
  • False claims of "suspicious activity or log-in attempts"
  • False claims of "a problem with your account or your payment information"
  • Requests to "confirm some personal or financial information"
  • An invoice you do not recognize attached
  • A link to "make a payment" that contains malware
  • False claims you are "eligible to register for a government refund"
  • False offers of "a coupon for free stuff"

None of these is unique on its own. The combination is what gives the email away.

The Tells That Have Gotten Weaker

The classic phishing tells used to be typos, broken English, and bad formatting. CISA's guide is explicit that this signal is dying: "Note that this used to be a common sign of phishing, but in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling." [1]

What replaced it is content. A perfectly written email asking you to update a billing method on a "billing problem" is just as phishable as one written with typos. The FTC's example phishing screenshot, the agency's own guide warns, "invites you to click on a link to update your payment details" and "legitimate companies won't email or text with a link to update your payment information." [2] That last sentence is the new test.

How to Verify Before You Click

If an email looks even slightly off, the right move is to verify the sender without opening anything in the message. CISA's specific advice for a message that "might be real" is to "go to the company's website and capture their contact information from the verified website" and then contact the company through a channel you trust. [1] That second part is non-optional: the verification channel must be one you reached on your own, not a number or address inside the suspicious email.

The sender address

Read the full address, not the display name. The display name is just a label and can be set to anything; the address after the @ is what routing actually uses. A display name of "Netflix Support" paired with a sender address at a domain that is not netflix.com is the textbook phish. The FTC's example phishing screenshot of a fake "your account is on hold because of a billing problem" email falls into this category. [2]

CISA's specific example for this tell is "amazan.com": a domain that looks like Amazon until you look at the letter between the z and the n. [1] The same trick works with rn for m, l for 1, and zero for O. Read the domain letter by letter when anything important rides on the click.

The link destination

Hover over any link on a desktop mail client. The actual URL appears in a tooltip or in the bottom status bar. On mobile, long-press the link to see the URL without opening it. If the link says it's going to yourbank.com but the underlying URL points to a completely different domain, that is a phish.

Shortened URLs (bit.ly, t.co, tinyurl) hide this tell from you. CISA's guide lists "untrusted shortened URLs" as a red flag in its own right. [1] If a message from your bank contains a short link with no context, treat it as suspect and reach the bank another way.

The header

If you want a deeper check, view the raw message header. The header is the technical metadata that travels with the email, and it is where the email authentication checks live. Three standards do that work: SPF, DKIM, and DMARC.

SPF (Sender Policy Framework) lets a domain owner publish a list of mail servers authorized to send for that domain. RFC 7208 defines the protocol and notes that without SPF, "existing protocols place no restriction on what a sending host can use as the 'MAIL FROM'", meaning anyone can claim to send from your bank. [3] SPF is enforced by DNS, and it is one of the three checks receivers use to flag spoofed mail.

DKIM (DomainKeys Identified Mail) is a cryptographic signature that binds a message to the signing domain. RFC 6376 lets "a person, role, or organization claim some responsibility for a message by associating a domain" with it through a signature stored in the message header and verified against a public key in DNS. [4] A failed DKIM check tells the receiver the message was tampered with in transit or was never signed by the claimed domain.

DMARC ties SPF and DKIM together. RFC 7489's stated purpose is to prevent "bad actors from sending mail that claims to come from legitimate senders, particularly transactional senders," and it works by requiring the SPF-authenticated domain or the DKIM-signed domain to align with the visible From: address. [5] If your bank publishes a DMARC record and the message you received fails the alignment check, the receiving server can reject or quarantine the message before you see it.

RFC 7208 includes a caution that applies even when SPF passes: "SPF-Authorized Email May Contain Other False Identities." [3] Passing SPF proves the sending server is authorized for the envelope sender, not that the visible display name or reply-to is honest. That is exactly why the three standards are deployed together.

What "Verify the Sender" Actually Looks Like

CISA's advice for a message that "might be real" is to use "another way to reach the person to confirm whether they contacted you." [1] A few practical translations:

  • If the email claims to be from your bank, call the number on the back of your card or on a statement you already have. Do not call a number from the email.
  • If the email claims to be from a coworker, message them on Slack, Teams, or text, on a channel that is already established. Do not reply to the email and do not use a contact from inside the message.
  • If the email claims to be from a delivery company, log into your account on the company's real website by typing the address yourself. Do not follow the link in the email.

If the contact cannot be reached through any pre-existing channel, that itself is a red flag.

What to Do Once You Know It's a Phish

Do not click, do not reply

CISA's specific instruction is: "Delete the message. Don't reply or click on any attachment or link, including any 'unsubscribe' link. Just delete." [1] Replying tells the attacker the address is live. Clicking unsubscribe on a phish confirms the same thing. The "unsubscribe" link in a phishing email is bait.

Report it through your mail client

Every modern mail client ships with a built-in report button. Microsoft is in the middle of transitioning Outlook customers from the Report Message and Report Phishing add-ins to a built-in Report button. Microsoft's own documentation describes the Report button as "consistent across consumer and enterprise accounts," "front and center across Outlook clients," and supported in "virtually all consumer and enterprise Outlook clients." [6]

Gmail ships a similar Report phishing option inside the message menu. Both feed the report into the provider's anti-phishing systems, which is what improves filtering for everyone on the same platform.

Forward to the right places

The FTC's consumer advice page lists the two forwarding addresses: phishing emails should be forwarded to the Anti-Phishing Working Group at [email protected] and to the FTC at [email protected], and text phishing should be forwarded to SPAM (7726). [2] After forwarding, the FTC's instruction is to delete the original.

The FTC also runs ReportFraud.ftc.gov for any fraud that has already happened. [2]

If You Already Clicked

You typed your password into a site you now believe was fake, or you opened an attachment that you now believe was malicious. The damage depends on what you handed over.

  • If you reused the password: change it everywhere it is used. Start with the email account itself, since email is the password-reset back door for most other accounts.
  • If you entered a one-time code from your authenticator: the attacker is signed in as you. Revoke active sessions and rotate credentials.
  • If you entered a credit card number: call the bank, dispute any pending charges, and request a new card.
  • If you opened an attachment: disconnect the device from the network, run a full antivirus scan, and consider a clean reinstall if the attachment was an installer.

Then file a report at ReportFraud.ftc.gov and at ic3.gov (the FBI's Internet Crime Complaint Center). The FTC and IC3 use these reports to build cases against the operators behind the campaigns.

What Email Authentication Means for You as a Receiver

DMARC, DKIM, and SPF are deployed by the sending organization, but the checks happen on your receiving mail server. If the bank you do business with publishes a DMARC policy of "reject," a spoofed email claiming to be from that bank will be rejected before it ever lands in your inbox. [5]

That does not mean a missed DMARC check is a problem on your end. It means the sender has not finished deploying it. As a user, the practical effect is: when a spoofed message lands in your inbox at all, the sender has not (yet) configured DMARC to reject, and you have to do the recognition work yourself.

The Hard Cases

Some phishing emails will pass every check above because the attacker controls a real domain. Business email compromise, where an attacker actually compromises a real mailbox and sends from it, defeats every sender-side tell. The only way to catch it is to verify the request out of band, exactly as CISA recommends. [1]

Some phishing emails will target you personally with your name, your employer, and a project you actually worked on. That is the AI-personalized variant, and the only defense is the same: do not act on the email's instructions. Open a new channel, reach the person you think sent it, and confirm.

The Bottom Line

Phishing is a recognition problem with a verification solution. The recognition side is the red flags: urgency, requests for personal data, look-alike domains, shortened links, and a "verify your account" pitch. CISA and the FTC publish the same list because they describe the same attack. [1] [2]

The verification side is what kills the attack: never trust the contact info inside a suspicious email, never click to find out, and always reach the supposed sender through a channel that was already established before the email arrived.

If you only remember three things, make them these:

  1. Read the full sender address, not the display name. The display name is free; the domain is what routing uses.
  2. Hover (desktop) or long-press (mobile) on every link before you click. If the visible text and the underlying URL do not match, that is a phish.
  3. If anything about a money, password, or account request feels off, reach the sender through a channel you already had. CISA's own guide is explicit: "go to the company's website and capture their contact information from the verified website." [1]

References

  1. CISA: Recognize and Report Phishing (red flags, resist, delete guidance)
  2. FTC Consumer Advice: Phishing (red flags, protection steps, report channels)
  3. IETF RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email
  4. IETF RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
  5. IETF RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  6. Microsoft Learn: Transition from Report Message or the Report Phishing add-ins to the built-in Report button in Outlook