Phishing is the attempt to trick you into revealing passwords, payment details, or personal information — usually by pretending to be someone you trust. It's the most common way accounts get taken over and malware gets installed, and it targets individuals and businesses alike. The good news: phishing messages share recognizable patterns, and with practice, they become easy to spot.

What Phishing Looks Like Today

Phishing arrives as emails, text messages, phone calls, or fake websites. Attackers impersonate banks, delivery companies, social platforms, IT teams, or people you know. Modern phishing is often spear-phishing: personally tailored with your name, your company, or details scraped from public profiles.

Spotting a Phishing Email

Work through these checks — any one of them should raise a flag:

  • Urgency. "Account suspended!", "Action required within 24 hours", "Verify immediately." Urgency is a pressure tactic.
  • The sender's actual address. The display name may say "Your Bank", but hover or inspect the raw address — typos and odd domains (e.g., bank-update.ru) are red flags.
  • Generic or odd greetings. "Dear customer" when you have a name on file.
  • Mismatched URLs. The visible text says one thing, the destination is another. Hover over links to preview the real address.
  • Requests for credentials. Legitimate companies never ask you to enter your password by email.
  • Poor formatting. Grammatical errors, odd logos, or inconsistent branding — though recent AI-assisted phishing makes these subtler.

Never trust a link enough to click it directly. Instead:

  1. Hover over the link to preview where it actually goes.
  2. Hunt for lookalike domains — extra letters, swapped letters, or unusual top-level domains.
  3. If in doubt, navigate to the site yourself by typing the known, official address.
  4. Enable web protection tools — like McAfee's WebAdvisor — that flag malicious URLs before you land on them. See our McAfee guide for setup.

Smishing: Phishing via Text

Text-message phishing ("smishing") uses short, urgent messages about deliveries, unpaid bills, or suspicious logins, often with a shortened link. Treat unexpected SMS the same as email: verify through an official channel, not the message itself, and never call back numbers sent from an unknown source.

Fake Websites: The Lookalike Threat

A convincing phishing site can clone a login page perfectly. Defenses:

  • Check for a valid HTTPS connection — though a padlock alone is not proof of legitimacy.
  • Compare the URL character by character before entering credentials.
  • Use a password manager that auto-fills only on the exact matching site — it will refuse to fill on lookalikes, which is a built-in tripwire.
  • Enable 2FA. Even if you slip, the attacker still needs the second factor. Our passwords & 2FA guide shows how.

Practical tip

When a message panics you, don't click. Contact the real organization through its official website or app, or call the number on the back of your card. Panic is the attacker's main tool.

Already Clicked? Act Quickly

  1. Change your password from a trusted device for any account that may have been involved.
  2. Enable 2FA if you haven't already.
  3. Run an antivirus scan if you downloaded or opened anything.
  4. Report it — forward suspicious emails to your IT team or provider and consider reporting to anti-phishing authorities.
  5. Watch the account activity on your email and banking for anything unusual.

Spotting phishing is a skill you build. Businesses should make it an ongoing habit — it's one of the most effective practices in our business cybersecurity checklist. And pairing awareness with strong malware defenses covers you even when a message slips through.

Slowness is a security feature. The pause before clicking is where most attacks die.