Home
← Back to Blog

August 21, 2026 · Backgrounder Team

How to Tell If an Email Is a Phishing Scam

Most of us were taught one rule for spotting a scam email: check who sent it. Look at the address, and if it isn't right, delete it.

That rule was good advice for a while. It no longer covers what actually lands in inboxes, because the fastest way to deliver phishing now is from a real account that has already been taken over. So the useful question is not who sent this — it is what is this email trying to get me to do.

Phishing is about the ask, not the sender. Decide based on what the message wants you to do, then verify that on a separate channel.


The three things phishing tries to get you to do

Almost every phishing email, no matter how it's dressed up, pushes you toward one of three actions. Learn the three and you can triage a message in seconds.

Sign in to see something. An invitation, a shared document, a delivery notice, a security alert — and to view it, you're asked to sign in with your email, Google, or Microsoft account. The sign-in page is the attack. A file or an invitation has no reason to ask for your password.

Pay, or change where a payment goes. A new bank account for an invoice you were expecting. An urgent transfer. A gift-card errand. This is the shape that costs the most money, because the relationship and the conversation around it are often completely real — only the payment detail is fake.

Open something unexpected, right now. An attachment or link you weren't waiting for, wrapped in urgency: your account is locked, your package is held, your payment failed. The pressure is there to stop you from checking.

If an email is doing one of these three things, slow down. If it's doing one of them and rushing you, treat it as phishing until you've confirmed otherwise.

Why checking the sender stopped working

The old advice assumed phishing came from strangers with clumsy lookalike addresses. Increasingly it comes from real accounts belonging to people you actually know.

When an attacker takes over an email account and sends from it, the message passes every technical check, because it isn't spoofed — the mail genuinely came from that account. The display name is right. The address is right. It may even arrive inside a thread you've been part of for weeks. Every signal you were told to check says safe.

That's why the sender is no longer the thing to check. The request is.

The tells that still work

The sender may be genuine, but these don't go away:

  • The ask changed. Payment details, account numbers, or delivery instructions that differ from what was agreed. Treat any change to where money goes as unverified until you've confirmed it by voice.
  • Urgency arrives with secrecy. Do it now, don't loop anyone in, I'm about to board a flight. Real colleagues and real family are rarely both rushed and private about money.
  • A sign-in prompt with no reason to exist. An invitation, shared file, or delivery notice asking for your email password is the attack, whoever sent it.
  • It's slightly off. Odd timing, a greeting they never use, a request outside their normal role. You know this person's normal — trust the mismatch enough to check.

And when there's a link, the domain is the final word. The registered domain sits immediately to the left of the first single slash, and you read it right to left — google.com.secure-login.xyz is not Google, no matter how the page looks or who sent it.

Business email compromise: the phishing with no link

The most expensive version of this often contains no link and no attachment at all, which is exactly why it works.

Business email compromise, or BEC, targets a payment instead of a password. The email comes from a vendor, a colleague, or a boss — sometimes a genuinely compromised one — and the only fake element is the instruction: send this month's payment to a new account, or wire the deposit today. There's nothing for a spam filter to catch, because there's nothing technically malicious in the message. The attack is the sentence.

The defense is a single habit: any change to payment details gets confirmed by voice, on a number you already had, before money moves. Not by replying to the email. Not by calling the number in the signature. A ten-second call is faster than clawing back a wire you can't recall.

The one move that settles it

If you remember nothing else, remember this. When an email asks you to sign in, pay, or open something, confirm it on a different channel than the one it arrived on.

  • Arrived by email? Call or text on a number you already had.
  • Arrived by text? Call.
  • From a colleague? Message them somewhere else, or walk over.

Never use a phone number, link, or address supplied inside the message itself. If the message is fake, so is the contact detail in it — a helpful "call this number to confirm" is a standard feature of these kits.

The cost of this habit is about ten seconds. The cost of skipping it is a transfer you can't reverse or an account you spend a weekend getting back.

If you already clicked

Move quickly, and in this order.

  • Change the password now, on the real site, reached by typing the address yourself rather than clicking anything.
  • Sign out of every other session from your account's security page. A password change alone doesn't always evict someone already signed in.
  • Turn on two-factor authentication, using an authenticator app or hardware key rather than SMS.
  • Check your forwarding rules and filters and remove anything you didn't create — attackers add these to keep reading your mail after you lock them out.
  • If you entered card or bank details, contact your bank. If a file downloaded and you opened it, treat the device as compromised and get help checking it properly.

Summary

  • Judge the ask, not the sender. Phishing wants you to sign in, pay, or open something unexpected.
  • A genuine sender is not a safe message — compromised accounts are now a primary delivery method.
  • Business email compromise has no link to catch — the fake part is the payment instruction.
  • Any change to payment details is unverified until confirmed by voice.
  • Verify on a different channel, using contact details you already had.

Not sure about a message sitting in your inbox right now? Paste it into a free Quick Check with Carmen and you'll have a read on it in seconds.

Frequently asked questions

How can I tell if an email is a phishing scam?

Look at what the email is asking you to do, not just who it appears to be from. Phishing almost always pushes you toward one of three actions — sign in on a page you reached from the email, pay or move money in a new way, or open an unexpected attachment or link under time pressure. If a message does any of those, verify it on a separate channel before acting. Confirm by calling or texting the sender on a number you already had, never one supplied in the message.

Can a phishing email come from a real, correct email address?

Yes. Checking the sender address is no longer enough on its own. Attackers routinely take over real accounts and send from them, so the address, the display name, and the technical sender checks all pass. That is why the reliable habit is to verify the request itself on a different channel, rather than trusting that a genuine-looking sender means a safe message.

What is business email compromise?

Business email compromise, or BEC, is a phishing attack aimed at payments rather than passwords. Instead of a fake login page, the message quietly changes where money should go — new bank details on an invoice you were expecting, or an urgent transfer request that looks like it came from a colleague or vendor. It usually contains no link or attachment at all, which is why it slips past spam filters and ordinary caution. Any change to payment details should be confirmed by voice before you act.

What should I do if I already clicked a link or entered my password?

Move quickly. Change your password on the real site by typing the address yourself rather than clicking anything, sign out of all other active sessions from your account's security page, turn on two-factor authentication with an authenticator app or hardware key, and check your mail settings for forwarding rules you did not create. If you entered card or bank details, contact your bank. If a file downloaded and you opened it, treat the device as compromised and get help checking it.

Stay one step ahead of scams

Spot red flags early and protect yourself, your family, and your business

Try for free