For years the standard advice was "watch for typos and clumsy grammar." It was decent advice while it lasted. It doesn't anymore. By 2026, phishing emails are routinely written by AI — clean, well-formatted, on-brand, often more polished than a real message from the same company. The FTC has been blunt about it: professional wording and correct spelling are now standard in scams, not a sign of legitimacy. So if you're still screening your inbox for broken English, you're checking for a flaw the attackers stopped making.
The good news is that the mechanics haven't changed. A phishing email still has to do two things: convince you it's from someone you trust, and get you to click, open, or send. Every check below targets one of those two moves — and none of them depend on spotting a typo.
The red flags that still hold up
You rarely need all six. Any one of these is usually enough to stop and verify before you touch anything in the message.
The sender domain doesn't match the name
The display name is free text — anyone can type "PayPal Support" or your CEO's name into it. What matters is the actual address after the @. Read it right to left: support@amaz0n-security.com is not amazon.com, and billing@paypal.account-verify.com is not paypal.com. Attackers register look-alike domains precisely so a glance doesn't catch it. If the domain isn't exactly the company's real one, nothing else in the email matters.
The link text and the real URL disagree
Hover over any link (on a phone, press and hold) and read where it actually goes before you tap. "Log in to your account" pointing at a random string of subdomains, a URL shortener, or a domain you don't recognize is the whole scam in one line. The visible text is bait; the destination is the truth.
Urgency stacked with a threat
"Your account will be suspended in 24 hours," "unusual sign-in — verify now," "payment failed, update immediately." Real companies rarely manufacture a countdown, because they don't need you panicked. The pressure exists to stop you from doing the one safe thing: pausing to check. When an email's main product is urgency, treat that as the finding, not the deadline.
An attachment or QR code you didn't ask for
A .zip, .html, .svg, or Office file with macros arriving out of nowhere is a classic delivery method — .svg and .html files can carry hidden scripts, and .docm files carry macros. The newer twist is quishing: a QR code image instead of a link, which slips past filters that only scan text. Don't open the file, and don't point your camera at the code, until you've confirmed the sender through another channel.
It asks for something legitimate senders never ask for
Passwords, full card numbers, one-time codes, or payment in gift cards, wire, or crypto. No bank, tax office, or platform collects a login or an MFA code over email, and none takes payment in Apple gift cards. The request itself — regardless of how polished the email looks — is often enough to end it.
It's oddly perfect, or subtly off from the real person
Typos used to be the giveaway. In 2026 that advice is backwards: AI writes phishing that's grammatically flawless and neatly formatted — security researchers report AI-written lures clicked far more often than the old clumsy ones. So the new tell is a behavioral mismatch. A famously two-line manager suddenly sending three tidy paragraphs, or a vendor whose tone is a little too generic, is worth a second look precisely because it reads so clean.
The one move that beats a convincing fake
If you take a single habit from this guide, take this one: never verify an email using the email itself. Don't click its link, don't call its phone number, don't reply to ask "is this really you?" — a scammer controls all three. Instead, reach the sender through a channel you already trust. Type the company's address into your browser yourself, or open its app. Call the number printed on the back of your card or on a past statement. Message the colleague on Slack or a number you already have saved.
This works even when the email is flawless, because it sidesteps the fake entirely. CISA's core guidance is the same in plain terms: if a message pressures you to act, slow down and confirm it independently before you do anything. The pressure is the point; refusing to be rushed is the defense.
When you want proof: read the headers
Your inbox shows you a friendly name and hides the plumbing. If you want to check who really sent something, the headers don't lie the way the display name does. It takes about thirty seconds.
Open the real headers
In Gmail, open the message, click the three-dot menu, and choose "Show original." In Outlook desktop, open the message, then File → Properties, and read the Internet headers box. This shows what your inbox hides.
Look for SPF, DKIM, or DMARC failing
Legitimate mail from a real organization passes these three sender-verification checks. A line reading dmarc=fail or spf=fail on an email that claims to be your bank is a strong signal it's forged.
Compare From with Return-Path and Reply-To
On a genuine message these belong to the same organization. When the From says your bank but the Return-Path or Reply-To points at some unrelated throwaway domain, someone is redirecting your replies — a textbook spoofing pattern.
You don't have to do this for every email — most of the time the domain and link checks settle it. Save the headers for the ones that look legitimate but feel wrong, which, increasingly, is exactly where the danger lives.
A note on the "urgent news" angle
A growing tactic is to hang the lure on a real, current event — a data breach in the headlines, a service outage, a tax deadline — because a plausible backdrop lowers your guard. If an email leans on some breaking claim to justify why you must act now, treat the claim as unverified until you check it somewhere other than that email. You can run the underlying story through FAXTR's fact-check search to see whether it's real reporting or a manufactured hook — separating the event from the email is often what breaks the spell.
If you already clicked or replied
Clicked a link but entered nothing? Close the tab and you're likely fine — but don't open any download it started. If you typed a password or a code, move quickly: change that password now, starting with your email and any account that reuses it, and turn on multi-factor authentication if it isn't already on. CISA recommends a hardware security key (like a FIDO2 key) as the strongest option, but even app-based codes beat none. If it was a work account, tell your IT or security team immediately so they can reset sessions and watch for follow-on activity.
Then report it — reports are what get the sending domains taken down before the next person opens the same email. In Gmail, use the report-phishing option in the message menu. In the US, forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org and file with the FTC at ReportFraud.ftc.gov; elsewhere, use your national cybercrime or consumer-protection authority. If the message reached you as a text or a call instead, the same instincts apply — our guides on scam text messages and AI voice-cloning scams cover those, and spotting a fake URL pairs closely with the link check above.
Not sure if a claim in your inbox is real?
FAXTR searches 100+ fact-checking organizations in one query — and lets you report the scams and fakes you run into.