Phishing Emails Explained: How to Spot Them and What to Do
How to spot a phishing email by its real red flags, the scams impersonating Amazon and Geek Squad right now, and what to do if you clicked or handed over a password.

A phishing email is a message designed to look like it comes from a real company or person — your bank, Amazon, "Geek Squad," even a coworker — in order to trick you into clicking a malicious link, opening an infected attachment, or typing your password or payment details into a fake page. The red flags are consistent even as the scams evolve: a sender address that doesn't quite match the real company, a link whose destination doesn't match its text, a lookalike domain (like amaz0n-billing.com), and a message built around urgency or fear. If you clicked a link or entered credentials, the fix is also consistent: change the password immediately (on a device you trust, not through the email), enable multi-factor authentication, watch your accounts and statements, and report the message to the FTC, the FBI's IC3, and the company being impersonated.
- What it is: a fake message impersonating a trusted sender to steal credentials, money, or install malware.
- Top red flags: mismatched sender domain, urgent/threatening tone, a link that goes somewhere other than it claims, requests for passwords or payment.
- If you clicked but didn't enter anything: close the tab, run a security scan, don't enter any info if a page opened.
- If you entered a password or card number: change that password now (typed manually, not via the email's link), turn on two-factor authentication, and check your accounts.
- Where to report it: ReportFraud.ftc.gov, forward it to [email protected], file with the FBI's IC3 at ic3.gov, and forward it to the impersonated company's abuse address (e.g., [email protected]).
What is a phishing email, exactly?
Phishing is a social-engineering attack: instead of breaking into a system, an attacker tries to talk a person into handing over access. The Cybersecurity and Infrastructure Security Agency (CISA) describes it as a message that "appears to be from a legitimate company" and pressures the recipient to click a link, open an attachment, or reply with sensitive information. The FBI's Internet Crime Complaint Center (IC3) tracks it as "Phishing/Spoofing" and it is, by a wide margin, the most reported form of internet crime in the United States. In its 2024 Internet Crime Report, IC3 logged 193,407 phishing/spoofing complaints out of 859,532 total complaints that year — more than any other crime category — alongside $70 million in directly attributed losses. Tech-support scams, the category that covers fake "Geek Squad" and antivirus-renewal emails, added another 36,002 complaints and $1.46 billion in losses on their own.
Phishing isn't limited to email anymore — the same tactics show up as text messages ("smishing"), phone calls ("vishing"), and social media DMs — but email remains the most common delivery method because it's free to send at scale and easy to make look legitimate with a copied logo and a spoofed display name.
How to spot a phishing email: the real red flags
Search interest in "phishing email meaning" and "phishing email examples" spikes because the scams keep changing shape, but the underlying tells have stayed remarkably stable. CISA's guidance, along with parallel advice from the FTC, Google, and Microsoft, converges on the same handful of signals:
1. The sender address doesn't match
The display name might read "Amazon" or "Bank of America," but the actual email address behind it often belongs to a free webmail account, a random domain, or a near-miss spelling of the real one. Always check the full address, not just the name shown in your inbox.
2. Urgency, fear, or a deadline
CISA flags "urgent or emotionally appealing language, especially messages that claim dire consequences" as one of the clearest signs of phishing. Real companies rarely threaten to suspend your account, cancel your order, or report you within hours. Scammers use that pressure specifically to short-circuit careful reading.
3. Links that go somewhere other than they claim
Hover over a link (or long-press it on mobile) before clicking, and look at where it actually leads versus what the text says. Google's phishing guidance specifically calls out "links with URLs that don't match their displayed text" as a core tactic, and Microsoft's guidance notes the same for Outlook, where hovering reveals "the actual URL differs from the displayed text."
4. Lookalike and shortened domains
CISA's own example is a domain like amazan.com — swapped or added letters, extra words ("amazon-secure-update.com"), or a shortened URL that hides the real destination. These are built specifically to survive a quick glance.
5. Requests for information a real company wouldn't need by email
Passwords, one-time codes, full card numbers, or your Social Security number are the FTC's flagged red flag: "Legitimate companies won't email or text with a link to update your payment information." Any message asking you to "confirm" or "verify" account details through an embedded link should be treated as suspect by default.
6. Poor grammar — but don't rely on it anymore
Misspellings and awkward phrasing used to be a reliable tell. CISA now explicitly warns that AI tools let scammers produce "grammatically correct" messages, so treat clean writing as no longer proof of legitimacy — judge the sender, links, and request instead.
| Red flag | What it looks like | Why it works |
|---|---|---|
| Sender mismatch | Display name says "Amazon," address is random@gmail or a strange domain | Most inboxes show the display name by default, hiding the real address |
| Urgency/threats | "Your account will be suspended in 24 hours" | Pressure discourages careful checking |
| Mismatched link | Text says "amazon.com," hovering reveals a different domain | Most people don't check before clicking |
| Lookalike domain | amaz0n-support.com, geeksquad-billing.net | Close enough to pass a fast read |
| Unexpected attachment/invoice | A "renewal invoice" for a subscription you never bought | Curiosity or alarm prompts an open/click |
| Request for credentials or codes | "Verify your password" or "enter your 2FA code to cancel" | Gives the attacker direct account access |
The most common phishing scams right now
Most phishing email traffic clusters around a handful of impersonated categories. Recognizing the pattern of the specific scam is often faster than parsing every red flag from scratch.
Delivery and Amazon order scams
These messages claim a package couldn't be delivered, a payment method failed, or an order needs "confirmation," with a link to a fake tracking or account page. Amazon's own guidance on spoofed emails warns that these messages are "sent from an outside party attempting to access your personal information" by mimicking Amazon's branding closely enough to pass a glance. The same pattern shows up as fake USPS, UPS, and FedEx delivery-failure texts asking you to "reschedule" through a link and pay a small redelivery fee — a request no shipping carrier makes by unsolicited text. If an order or delivery message worries you, open the retailer's app or site directly (not through the email) and check your order history there instead.
"Geek Squad" and tech-support renewal scams
This is one of the most-reported impersonation scams in the country: a fake invoice or "renewal notice" for a Geek Squad, antivirus, or computer-support subscription you never bought, usually priced in the hundreds of dollars, with a phone number to call to "dispute" the charge. Calling that number connects you to a scammer who asks for remote access to your computer or your card details to process a "refund." The FTC has specifically warned about a wave of fake Geek Squad renewal emails, and IC3's tech-support category — which covers this exact scam — logged over 36,000 complaints and $1.46 billion in reported losses in 2024 alone. The tell is the same every time: you never ordered the service, and the "customer support" number is in the email itself rather than on the real company's own site.
Bank and financial-account phishing
These impersonate your bank, card network, or payment app with alerts about "suspicious login attempts," frozen accounts, or a payment that needs confirming. The FTC's guidance notes scammers routinely "say they've noticed suspicious activity or log-in attempts" that never actually happened, specifically to get you to click a "secure your account" link. No bank needs your full password, PIN, or a one-time code sent to you by email or text — if a message asks for any of those, it's not from your bank.
Government and refund impersonation
Fake messages from the IRS, Social Security Administration, or state agencies about refunds, benefits, or unpaid fines are common enough that IC3 tracks "Government Impersonation" as its own crime category — over 17,000 complaints in 2024. Real government agencies don't demand payment by gift card, wire transfer, or cryptocurrency, and don't threaten arrest by email.
What to do if you get a phishing email
CISA frames the response as three steps: Recognize, Resist, Delete.
- Recognize the warning signs above rather than reacting to the message's urgency.
- Resist the urge to click any link or open any attachment. If you think the underlying claim might be real — an actual order, an actual bill — go directly to the company's official site or app, typed in yourself, rather than through anything in the email.
- Delete the message without replying, and don't click "unsubscribe" either — on a phishing email that link can itself be malicious or simply confirm your address is active.
Most email clients let you flag the message on the way out the door. In Gmail, open the message, click the three-dot "More" menu next to Reply, and choose Report phishing — Google says it uses these reports, plus a copy of the message, to improve its spam filtering for everyone. In Outlook or Microsoft 365, select the message and choose Report > Report phishing from the ribbon.
How to report a phishing email
Reporting does two things: it can get a fraudulent site taken down, and it feeds the data that agencies use to track scam trends. There isn't one single place to send every report — where you report depends on what you want to happen.
| Channel | Best for | How |
|---|---|---|
| FTC — ReportFraud.ftc.gov | Any scam attempt, whether or not you lost money | File a report at reportfraud.ftc.gov |
| Anti-Phishing Working Group | The raw phishing email itself, for takedown/analysis | Forward the email as-is to [email protected] |
| FBI's IC3 | Internet crime, especially if money was sent or an account was compromised | File a complaint at ic3.gov |
| CISA | Reporting to the U.S. government's cyber defense agency | Use the reporting link on CISA's phishing page, or your email client's built-in "report spam/phishing" button |
| The impersonated company | Getting a spoofed brand/site taken down fast | e.g., forward Amazon-spoofed email to [email protected] |
| Text message ("smishing") | Phishing sent by SMS instead of email | Forward the text to 7726 (SPAM) |
You can — and often should — do more than one of these at once: report the message to your email provider so its filters learn from it, forward it to the APWG and/or ReportFraud.ftc.gov so the scam gets logged, and forward it to the real company's abuse address (most large companies, from Amazon to major banks, publish one) so they can move to take the fake site down.
What to do if you already clicked the link
Clicking a phishing link isn't automatically catastrophic — the damage usually happens at the next step, when you type something into the page that opens or a malicious file runs. Work through this in order:
- Don't enter anything. If a login or payment page opened after you clicked, close it without typing a password, code, or card number.
- Disconnect if a file downloaded or ran. If an attachment opened or a download started, disconnect the device from Wi-Fi/network and run a full scan with updated security software before reconnecting.
- Change any password you did enter — immediately, and not via the email. Go to the real site directly and change that password, plus the password on any other account that reuses it.
- Turn on multi-factor authentication on the affected account if it isn't already on, so a stolen password alone isn't enough to get back in. Our guide to setting up an authenticator app for two-factor authentication walks through it, and where a service supports them, passkeys go a step further because, as covered in our guide to setting up passkeys, they can't be phished the way a typed password can.
- Watch your accounts and statements for unfamiliar logins, password-reset emails you didn't request, or charges you didn't make.
What to do if you already gave up a password, card number, or your SSN
This is where the FTC's guidance shifts from prevention to recovery, and the steps differ depending on exactly what you handed over:
- Passwords or login details: Change that password right away, and change it everywhere else you reused it — password reuse is exactly what lets one phished login turn into several compromised accounts. If you're not sure which of your accounts and passwords may already be circulating from past breaches, our explainer on checking whether you've been part of a data breach covers how to check.
- Credit card or bank details: Contact your card issuer or bank immediately to flag the card, dispute any charges, and request a replacement number.
- Social Security number, driver's license, or other ID details: Go to IdentityTheft.gov, the FTC's dedicated recovery site. It walks you through a personalized recovery plan based on exactly what was exposed, including placing a fraud alert or credit freeze.
- Any of the above: Report the incident at ReportFraud.ftc.gov and, if you lost money or believe an account was compromised as a result, file a complaint with the FBI's IC3. These reports don't usually get you your money back directly, but they feed the data law enforcement uses to track and act on scam networks.
How to avoid getting phished next time
None of this requires becoming paranoid about every email — a few habits handle most of it:
- Type company URLs directly into your browser instead of clicking email links, especially for anything account- or payment-related.
- Treat urgency as a red flag on its own — real deadlines from real companies rarely arrive by surprise email demanding action within hours.
- Turn on multi-factor authentication everywhere it's offered, so a phished password alone doesn't hand over your account.
- Keep your browser and security software up to date so known phishing sites get blocked automatically.
- If you want to test your own eye for these red flags in a low-stakes way, Google's sister company Jigsaw runs a free phishing quiz built from real-world examples — a reasonable answer to "phishing email test" searches, since it's built and hosted by Google/Jigsaw rather than a random third-party checker.
Common questions about phishing emails
A few questions come up often enough to answer directly:
Is there a single "phishing email checker" tool that scans any message for you? Not a universal one you should trust blindly — the safest check is manual (sender address, link destination, and whether the request makes sense) plus your email provider's built-in filtering and "report phishing" button, which uses the reports it collects to get better over time.
Can just opening a phishing email infect my device? Usually not from opening plain text alone, but clicking a link or downloading/opening an attachment can. Treat both as the actual risk point, not the act of opening the message.
Why do lookalike domains still work if people are told to check links? Because most people read a URL quickly rather than character-by-character, and mobile screens make long or shortened links even harder to inspect — which is exactly why CISA and others flag domain lookalikes as a standing top red flag rather than an outdated one.
What's next
Phishing tactics will keep shifting with whatever's topical — tax season, holiday shipping, a new subscription price hike — but the underlying mechanics (a spoofed sender, an urgent ask, a link that doesn't go where it claims) have stayed the same for years, and official guidance from CISA, the FTC, and the FBI's IC3 is updated as new lures emerge. The most durable protection isn't spotting every fake email on sight; it's making a phished password harder to use, by turning on multi-factor authentication or, where it's supported, switching to passkeys, and by getting into the habit of reporting suspicious messages instead of just deleting them — that reporting is part of how the takedown and tracking systems keep working.
Frequently asked questions
What does a phishing email actually mean?
It means a message is impersonating a real company or person to trick you into clicking a malicious link, opening an infected attachment, or entering your password, card number, or other personal information into a fake page.
What are some real examples of phishing emails?
The most common current examples impersonate a delivery or order problem from Amazon or a shipping carrier, a fake 'Geek Squad' or antivirus renewal invoice for a subscription you never bought, and bank alerts claiming suspicious login activity that never happened.
Is there a reliable phishing email checker I can run a message through?
There's no single trustworthy checker for every message. The safest approach is manually checking the sender's full address, hovering over links before clicking, and using your email provider's built-in 'report phishing' feature, which improves its own filtering from those reports.
What should I do if I got a phishing email pretending to be from Amazon?
Don't click any link in it. Open Amazon directly and check your order history there, then forward the suspicious email to Amazon's abuse address, [email protected], and report it at ReportFraud.ftc.gov.
What should I do if I got a fake Geek Squad renewal invoice?
Don't call the phone number in the email. If you're not sure whether you have a real subscription, contact the company directly through its official site, and report the email to ReportFraud.ftc.gov; the FBI's IC3 also tracks this as a tech-support scam.
I already clicked a phishing link and typed my password. What now?
Change that password immediately by going to the real site directly (not through the email), change it anywhere else you reused it, turn on multi-factor authentication, and watch the account for unfamiliar activity. If you also gave up a Social Security number or ID details, go to IdentityTheft.gov for a personalized recovery plan.
Sources
- CISA: Recognize and Report Phishingcisa.gov
- FTC Consumer Advice: How To Recognize and Avoid Phishing Scamsconsumer.ftc.gov
- FTC: Report Fraud (ReportFraud.ftc.gov)reportfraud.ftc.gov
- FTC: IdentityTheft.gov recovery stepsidentitytheft.gov
- FBI IC3: 2024 Internet Crime Report (PDF)ic3.gov
- Google: Report phishing emails in Gmailsupport.google.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

.webp)