How to Spot a Phishing Email in 30 Seconds (7 Checks)

⏱ 1 min readUpdated 28 September 2026

Most account hacks start with one convincing email. These seven checks catch almost all of them.

  1. Check the real sender address, not just the name. “HDFC Bank <[email protected]>” is not your bank.
  2. Hover over links before clicking (long-press on a phone). Does the address actually go to the company’s own domain?
  3. Urgency and threats — “account blocked in 24 hours”, “legal action” — are designed to stop you thinking.
  4. Unexpected attachments, especially .zip, .html, .iso or Office files asking you to “Enable content”.
  5. Requests for OTP, PIN, password or remote access. No genuine bank or company asks for these.
  6. Payment detail changes — “our bank account has changed, pay the invoice here” — always confirm by phone using a number you already have.
  7. Too good to be true — refunds, prizes, jobs with huge pay.
💡 When in doubt, don’t use the link in the message. Open the app or type the website address yourself.

Set up two-factor authentication so a stolen password alone isn’t enough.

✨ Ask AI about this article

Stuck on a step? Ask a question and the AI answers using this article.

Free · AI can be wrong