How to Spot a Phishing Email Before You Click
Launch library · evergreen read

Phishing emails work by borrowing the shape of something familiar: a bank notice, a courier update, a workplace login page. The visual design can look convincing, right down to a genuine logo, but the underlying intent is always identical. The message wants you to click, type or transfer money before you have had time to properly think it through.
Look past the logo and focus on the details that are harder to fake. Check the actual sender address rather than the friendly display name, hover over any link to see where it truly leads, and notice generic greetings like "Dear Customer" from an organisation that would normally know your full name already. Odd spelling and mismatched fonts are smaller tells worth trusting too.
The strongest clue is usually urgency: a warning that your account will close within hours, a parcel that needs "immediate" action, a deadline measured in a very short window. Genuine organisations rarely rush a customer like this over email. If a message is pushing you to act fast without giving you room to check, treat that pressure itself as the real warning sign.
When something feels off, avoid replying to or clicking through the email altogether. Open a separate browser tab and go directly to the organisation's known website, or call the number printed on a past statement you already trust. Verifying through a channel you chose yourself, rather than one the email supplied, closes the door the message was trying to open.