Phishing Emails Explained: How to Spot Them and What to Do

How to spot a phishing email by its real red flags, the scams impersonating Amazon and Geek Squad right now, and what to do if you clicked or handed over a password.

CISA Secure Our World campaign banner promoting phishing and cybersecurity awareness
CISA's Secure Our World public awareness campaign. Image: CISA.

A phishing email is a message designed to look like it comes from a real company or person — your bank, Amazon, "Geek Squad," even a coworker — in order to trick you into clicking a malicious link, opening an infected attachment, or typing your password or payment details into a fake page. The red flags are consistent even as the scams evolve: a sender address that doesn't quite match the real company, a link whose destination doesn't match its text, a lookalike domain (like amaz0n-billing.com), and a message built around urgency or fear. If you clicked a link or entered credentials, the fix is also consistent: change the password immediately (on a device you trust, not through the email), enable multi-factor authentication, watch your accounts and statements, and report the message to the FTC, the FBI's IC3, and the company being impersonated.

Fast answer
  • What it is: a fake message impersonating a trusted sender to steal credentials, money, or install malware.
  • Top red flags: mismatched sender domain, urgent/threatening tone, a link that goes somewhere other than it claims, requests for passwords or payment.
  • If you clicked but didn't enter anything: close the tab, run a security scan, don't enter any info if a page opened.
  • If you entered a password or card number: change that password now (typed manually, not via the email's link), turn on two-factor authentication, and check your accounts.
  • Where to report it: ReportFraud.ftc.gov, forward it to [email protected], file with the FBI's IC3 at ic3.gov, and forward it to the impersonated company's abuse address (e.g., [email protected]).

What is a phishing email, exactly?

Phishing is a social-engineering attack: instead of breaking into a system, an attacker tries to talk a person into handing over access. The Cybersecurity and Infrastructure Security Agency (CISA) describes it as a message that "appears to be from a legitimate company" and pressures the recipient to click a link, open an attachment, or reply with sensitive information. The FBI's Internet Crime Complaint Center (IC3) tracks it as "Phishing/Spoofing" and it is, by a wide margin, the most reported form of internet crime in the United States. In its 2024 Internet Crime Report, IC3 logged 193,407 phishing/spoofing complaints out of 859,532 total complaints that year — more than any other crime category — alongside $70 million in directly attributed losses. Tech-support scams, the category that covers fake "Geek Squad" and antivirus-renewal emails, added another 36,002 complaints and $1.46 billion in losses on their own.

Phishing isn't limited to email anymore — the same tactics show up as text messages ("smishing"), phone calls ("vishing"), and social media DMs — but email remains the most common delivery method because it's free to send at scale and easy to make look legitimate with a copied logo and a spoofed display name.

How to spot a phishing email: the real red flags

Search interest in "phishing email meaning" and "phishing email examples" spikes because the scams keep changing shape, but the underlying tells have stayed remarkably stable. CISA's guidance, along with parallel advice from the FTC, Google, and Microsoft, converges on the same handful of signals:

1. The sender address doesn't match

The display name might read "Amazon" or "Bank of America," but the actual email address behind it often belongs to a free webmail account, a random domain, or a near-miss spelling of the real one. Always check the full address, not just the name shown in your inbox.

2. Urgency, fear, or a deadline

CISA flags "urgent or emotionally appealing language, especially messages that claim dire consequences" as one of the clearest signs of phishing. Real companies rarely threaten to suspend your account, cancel your order, or report you within hours. Scammers use that pressure specifically to short-circuit careful reading.

Hover over a link (or long-press it on mobile) before clicking, and look at where it actually leads versus what the text says. Google's phishing guidance specifically calls out "links with URLs that don't match their displayed text" as a core tactic, and Microsoft's guidance notes the same for Outlook, where hovering reveals "the actual URL differs from the displayed text."

4. Lookalike and shortened domains

CISA's own example is a domain like amazan.com — swapped or added letters, extra words ("amazon-secure-update.com"), or a shortened URL that hides the real destination. These are built specifically to survive a quick glance.

5. Requests for information a real company wouldn't need by email

Passwords, one-time codes, full card numbers, or your Social Security number are the FTC's flagged red flag: "Legitimate companies won't email or text with a link to update your payment information." Any message asking you to "confirm" or "verify" account details through an embedded link should be treated as suspect by default.

6. Poor grammar — but don't rely on it anymore

Misspellings and awkward phrasing used to be a reliable tell. CISA now explicitly warns that AI tools let scammers produce "grammatically correct" messages, so treat clean writing as no longer proof of legitimacy — judge the sender, links, and request instead.

Common phishing red flags, at a glance
Red flagWhat it looks likeWhy it works
Sender mismatchDisplay name says "Amazon," address is random@gmail or a strange domainMost inboxes show the display name by default, hiding the real address
Urgency/threats"Your account will be suspended in 24 hours"Pressure discourages careful checking
Mismatched linkText says "amazon.com," hovering reveals a different domainMost people don't check before clicking
Lookalike domainamaz0n-support.com, geeksquad-billing.netClose enough to pass a fast read
Unexpected attachment/invoiceA "renewal invoice" for a subscription you never boughtCuriosity or alarm prompts an open/click
Request for credentials or codes"Verify your password" or "enter your 2FA code to cancel"Gives the attacker direct account access

The most common phishing scams right now

Most phishing email traffic clusters around a handful of impersonated categories. Recognizing the pattern of the specific scam is often faster than parsing every red flag from scratch.

Delivery and Amazon order scams

These messages claim a package couldn't be delivered, a payment method failed, or an order needs "confirmation," with a link to a fake tracking or account page. Amazon's own guidance on spoofed emails warns that these messages are "sent from an outside party attempting to access your personal information" by mimicking Amazon's branding closely enough to pass a glance. The same pattern shows up as fake USPS, UPS, and FedEx delivery-failure texts asking you to "reschedule" through a link and pay a small redelivery fee — a request no shipping carrier makes by unsolicited text. If an order or delivery message worries you, open the retailer's app or site directly (not through the email) and check your order history there instead.

"Geek Squad" and tech-support renewal scams

This is one of the most-reported impersonation scams in the country: a fake invoice or "renewal notice" for a Geek Squad, antivirus, or computer-support subscription you never bought, usually priced in the hundreds of dollars, with a phone number to call to "dispute" the charge. Calling that number connects you to a scammer who asks for remote access to your computer or your card details to process a "refund." The FTC has specifically warned about a wave of fake Geek Squad renewal emails, and IC3's tech-support category — which covers this exact scam — logged over 36,000 complaints and $1.46 billion in reported losses in 2024 alone. The tell is the same every time: you never ordered the service, and the "customer support" number is in the email itself rather than on the real company's own site.

Bank and financial-account phishing

These impersonate your bank, card network, or payment app with alerts about "suspicious login attempts," frozen accounts, or a payment that needs confirming. The FTC's guidance notes scammers routinely "say they've noticed suspicious activity or log-in attempts" that never actually happened, specifically to get you to click a "secure your account" link. No bank needs your full password, PIN, or a one-time code sent to you by email or text — if a message asks for any of those, it's not from your bank.

Government and refund impersonation

Fake messages from the IRS, Social Security Administration, or state agencies about refunds, benefits, or unpaid fines are common enough that IC3 tracks "Government Impersonation" as its own crime category — over 17,000 complaints in 2024. Real government agencies don't demand payment by gift card, wire transfer, or cryptocurrency, and don't threaten arrest by email.

What to do if you get a phishing email

CISA frames the response as three steps: Recognize, Resist, Delete.

  1. Recognize the warning signs above rather than reacting to the message's urgency.
  2. Resist the urge to click any link or open any attachment. If you think the underlying claim might be real — an actual order, an actual bill — go directly to the company's official site or app, typed in yourself, rather than through anything in the email.
  3. Delete the message without replying, and don't click "unsubscribe" either — on a phishing email that link can itself be malicious or simply confirm your address is active.

Most email clients let you flag the message on the way out the door. In Gmail, open the message, click the three-dot "More" menu next to Reply, and choose Report phishing — Google says it uses these reports, plus a copy of the message, to improve its spam filtering for everyone. In Outlook or Microsoft 365, select the message and choose Report > Report phishing from the ribbon.

How to report a phishing email

Reporting does two things: it can get a fraudulent site taken down, and it feeds the data that agencies use to track scam trends. There isn't one single place to send every report — where you report depends on what you want to happen.

Where to report a phishing email
ChannelBest forHow
FTC — ReportFraud.ftc.govAny scam attempt, whether or not you lost moneyFile a report at reportfraud.ftc.gov
Anti-Phishing Working GroupThe raw phishing email itself, for takedown/analysisForward the email as-is to [email protected]
FBI's IC3Internet crime, especially if money was sent or an account was compromisedFile a complaint at ic3.gov
CISAReporting to the U.S. government's cyber defense agencyUse the reporting link on CISA's phishing page, or your email client's built-in "report spam/phishing" button
The impersonated companyGetting a spoofed brand/site taken down faste.g., forward Amazon-spoofed email to [email protected]
Text message ("smishing")Phishing sent by SMS instead of emailForward the text to 7726 (SPAM)

You can — and often should — do more than one of these at once: report the message to your email provider so its filters learn from it, forward it to the APWG and/or ReportFraud.ftc.gov so the scam gets logged, and forward it to the real company's abuse address (most large companies, from Amazon to major banks, publish one) so they can move to take the fake site down.

What to do if you already clicked the link

Clicking a phishing link isn't automatically catastrophic — the damage usually happens at the next step, when you type something into the page that opens or a malicious file runs. Work through this in order:

  1. Don't enter anything. If a login or payment page opened after you clicked, close it without typing a password, code, or card number.
  2. Disconnect if a file downloaded or ran. If an attachment opened or a download started, disconnect the device from Wi-Fi/network and run a full scan with updated security software before reconnecting.
  3. Change any password you did enter — immediately, and not via the email. Go to the real site directly and change that password, plus the password on any other account that reuses it.
  4. Turn on multi-factor authentication on the affected account if it isn't already on, so a stolen password alone isn't enough to get back in. Our guide to setting up an authenticator app for two-factor authentication walks through it, and where a service supports them, passkeys go a step further because, as covered in our guide to setting up passkeys, they can't be phished the way a typed password can.
  5. Watch your accounts and statements for unfamiliar logins, password-reset emails you didn't request, or charges you didn't make.

What to do if you already gave up a password, card number, or your SSN

This is where the FTC's guidance shifts from prevention to recovery, and the steps differ depending on exactly what you handed over:

  • Passwords or login details: Change that password right away, and change it everywhere else you reused it — password reuse is exactly what lets one phished login turn into several compromised accounts. If you're not sure which of your accounts and passwords may already be circulating from past breaches, our explainer on checking whether you've been part of a data breach covers how to check.
  • Credit card or bank details: Contact your card issuer or bank immediately to flag the card, dispute any charges, and request a replacement number.
  • Social Security number, driver's license, or other ID details: Go to IdentityTheft.gov, the FTC's dedicated recovery site. It walks you through a personalized recovery plan based on exactly what was exposed, including placing a fraud alert or credit freeze.
  • Any of the above: Report the incident at ReportFraud.ftc.gov and, if you lost money or believe an account was compromised as a result, file a complaint with the FBI's IC3. These reports don't usually get you your money back directly, but they feed the data law enforcement uses to track and act on scam networks.

How to avoid getting phished next time

None of this requires becoming paranoid about every email — a few habits handle most of it:

  • Type company URLs directly into your browser instead of clicking email links, especially for anything account- or payment-related.
  • Treat urgency as a red flag on its own — real deadlines from real companies rarely arrive by surprise email demanding action within hours.
  • Turn on multi-factor authentication everywhere it's offered, so a phished password alone doesn't hand over your account.
  • Keep your browser and security software up to date so known phishing sites get blocked automatically.
  • If you want to test your own eye for these red flags in a low-stakes way, Google's sister company Jigsaw runs a free phishing quiz built from real-world examples — a reasonable answer to "phishing email test" searches, since it's built and hosted by Google/Jigsaw rather than a random third-party checker.

Common questions about phishing emails

A few questions come up often enough to answer directly:

Is there a single "phishing email checker" tool that scans any message for you? Not a universal one you should trust blindly — the safest check is manual (sender address, link destination, and whether the request makes sense) plus your email provider's built-in filtering and "report phishing" button, which uses the reports it collects to get better over time.

Can just opening a phishing email infect my device? Usually not from opening plain text alone, but clicking a link or downloading/opening an attachment can. Treat both as the actual risk point, not the act of opening the message.

Why do lookalike domains still work if people are told to check links? Because most people read a URL quickly rather than character-by-character, and mobile screens make long or shortened links even harder to inspect — which is exactly why CISA and others flag domain lookalikes as a standing top red flag rather than an outdated one.

What's next

Phishing tactics will keep shifting with whatever's topical — tax season, holiday shipping, a new subscription price hike — but the underlying mechanics (a spoofed sender, an urgent ask, a link that doesn't go where it claims) have stayed the same for years, and official guidance from CISA, the FTC, and the FBI's IC3 is updated as new lures emerge. The most durable protection isn't spotting every fake email on sight; it's making a phished password harder to use, by turning on multi-factor authentication or, where it's supported, switching to passkeys, and by getting into the habit of reporting suspicious messages instead of just deleting them — that reporting is part of how the takedown and tracking systems keep working.

Frequently asked questions

What does a phishing email actually mean?

It means a message is impersonating a real company or person to trick you into clicking a malicious link, opening an infected attachment, or entering your password, card number, or other personal information into a fake page.

What are some real examples of phishing emails?

The most common current examples impersonate a delivery or order problem from Amazon or a shipping carrier, a fake 'Geek Squad' or antivirus renewal invoice for a subscription you never bought, and bank alerts claiming suspicious login activity that never happened.

Is there a reliable phishing email checker I can run a message through?

There's no single trustworthy checker for every message. The safest approach is manually checking the sender's full address, hovering over links before clicking, and using your email provider's built-in 'report phishing' feature, which improves its own filtering from those reports.

What should I do if I got a phishing email pretending to be from Amazon?

Don't click any link in it. Open Amazon directly and check your order history there, then forward the suspicious email to Amazon's abuse address, [email protected], and report it at ReportFraud.ftc.gov.

What should I do if I got a fake Geek Squad renewal invoice?

Don't call the phone number in the email. If you're not sure whether you have a real subscription, contact the company directly through its official site, and report the email to ReportFraud.ftc.gov; the FBI's IC3 also tracks this as a tech-support scam.

I already clicked a phishing link and typed my password. What now?

Change that password immediately by going to the real site directly (not through the email), change it anywhere else you reused it, turn on multi-factor authentication, and watch the account for unfamiliar activity. If you also gave up a Social Security number or ID details, go to IdentityTheft.gov for a personalized recovery plan.

Sources

More on Phishing →PhishingEmail securityScamsAmazonGeek SquadFTC
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all