Phishing has become polished, personalized, and AI-assisted. The old advice about typos no longer works. These checks still do.
Why the old advice stopped working
For years, the standard tip was to look for bad grammar and spelling. Modern phishing kits and AI writing tools have erased that signal. Today’s fraudulent emails are fluent, correctly branded, and often personalized with details scraped from social media or past data breaches.
What attackers still cannot easily fake are the technical fundamentals: the true sending domain and the true link destination. That is where your ten seconds should go.
The 10-second check
First, expand the sender’s actual address, not just the display name. On a phone, tap the name; on a desktop, hover over it. An email claiming to be your bank that comes from a free mail provider or a lookalike domain, such as a brand name with an extra letter, fails the test immediately.

Second, hover over every link before clicking, or long-press on mobile, and read the real destination. The visible text can say anything; the underlying URL cannot lie. Look closely at the part of the address just before the first slash, because that is the domain that actually receives your click.
Third, ask what the email wants you to feel. Phishing runs on urgency and fear: your account will be closed, a payment failed, a package is stuck, you owe money today. Legitimate organizations rarely demand immediate action through an email link.
The scams doing the most damage right now
Payroll and invoice redirection messages target employees and small businesses, asking to update direct deposit details or a vendor’s bank account. Always verify payment changes by phone using a number you already have on file, never one supplied in the message.
Multi-factor fatigue attacks bombard you with sign-in approval prompts hoping you will tap approve to make them stop. If you receive prompts you did not initiate, deny them and change your password.
Package delivery texts and emails spike around holidays. Track packages only through the retailer’s own site or the carrier’s official app.
If you clicked or replied
Do not panic, and do not go quiet. Change the affected password immediately, and any other account that shared it. Turn on two-factor authentication if it was off. If you entered financial details, contact your bank right away.
Report the message. Forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, report to the FTC at ReportFraud.ftc.gov, and use your email provider’s report-phishing button, which improves filtering for everyone.
Frequently asked questions
Can opening an email infect my device?
Simply opening a modern email is rarely dangerous by itself. The risk lives in clicking links, opening attachments, and entering credentials on fake pages.
Why do phishing emails get past spam filters?
Attackers constantly rotate domains and hosting, and well-written messages from new domains can pass filters briefly. Filters catch most attempts; your judgment handles the rest.
Are text message scams handled the same way?
Yes. The same checks apply to smishing texts. You can also forward suspicious texts to 7726, which reports them to your carrier.




