You were probably taught to look for bad spelling and awkward grammar as the giveaway sign of a scam email. Sadly in 2026 That advice is now out of date, and relying on it will get you caught out. Due to the rise of AI phishing emails are now polished, professional, and personalized, often better written than the legitimate business emails they’re impersonating.
According to Huntress’s 2026 Cyber Threat Report, the median time it takes someone to click a phishing link and submit their information is under 60 seconds. That leaves almost no room for hesitation once a convincing message lands in your inbox, so knowing what to check matters more than ever now.
Why the Old Advice Doesn’t Work Anymore
Attackers now use AI to write their messages, and with AI they mirror the target company branding with pixel-perfect accuracy, and time their scams around real-time current events to create urgency. The grammar-check mental model that used to catch most phishing attempts catches almost nothing today. That doesn’t mean phishing has become undetectable so to speak, it just means that the signals intitially worth checking have shifted from writing quality to process and context.
The Red Flags to Check
The sender’s email address, not just their display name. Did you know a message can show “Amazon Support” as the sender name while the real address is something completely unrelated? Look for subtle domain tricks specifically: letter swaps for example arnazon.com instead of amazon.com, extra words or hyphens (microsoft-security.net), or a free email provider (Gmail, Yahoo) being used for what claims to be official business correspondence.
Whether the request matches how that process normally works. Ask yourself: would this person or company usually ask for this, in this way? Finance, payroll, or account changes rarely happen through a single unexpected email with no supporting process behind it.
Artificial urgency or pressure to skip a normal step. A polished, well-written message can still be a scam if it’s pushing you to act faster than you normally would, skip your usual verification process, or avoid asking someone else to double-check.
Whether you actually initiated the interaction. Password reset emails, MFA prompts, invoice notices, and delivery updates you didn’t trigger yourself deserve extra scrutiny by default, regardless of how legitimate they look.
Links that don’t match their visible text. Before clicking anything, hover over a link (or press and hold on mobile) to see the true destination URL. If it doesn’t match the text or the organization it claims to be from, don’t click it.
QR codes inside emails asking you to scan and authenticate. This is a newer, fast-growing tactic specifically designed to bypass corporate email security by moving the scam onto your personal phone, where those protections don’t apply. Treat any QR code requesting login or MFA setup inside an email as a red flag.
Unexpected attachments, especially ones framed as invoices, contracts, or voicemail transcripts you weren’t expecting.
Common Scam Templates Worth Knowing
A few specific setups show up constantly because they consistently work:
- The account-risk alert: “Unusual sign-in detected” or “Your account will be suspended”, designed to trigger fear of losing access to something you depend on. Microsoft-branded impersonation alone accounts for a large share of all phishing brand impersonation.
- The fake delivery notification: “Your parcel could not be delivered”, this is to catch people expecting a genuine delivery.
- The fake signed document: an email appearing to come from DocuSign or a similar service, with a “Review Document” button leading to a fake login page designed to steal your credentials.
How to Verify Before You Click On a Potential Scam
If something feels slightly off but you’re not sure, a few quick checks go a long way:
- Don’t click the link. Open a new browser tab and navigate directly to the organisation’s official website or app instead. If there’s an issue with your account, it’ll show up there.
- Search the exact subject line alongside the word “phishing” or “scam.” Active campaigns are typically reported and discussed online within hours of going out.
- Verify the sender’s domain, not just the display name, by checking the full email address or headers if your email client allows it.
- When in doubt, verify through a second channel. For anything involving money, credentials, or account access, confirm the request by phone, in person, or through a messaging platform you already use with that person or organization, never by replying to the email itself.
If You’ve Already Clicked On a Phishing link
Act in this order, quickly:
- Disconnect the device from the internet to stop any ongoing data transmission.
- Change your passwords from a different, trusted device, starting with your email account.
- Check for unexpected inbox rules, attackers sometimes quietly set up email forwarding rules to keep receiving your messages even after you change your password.
- Revoke active sessions on any account you suspect was compromised, most major platforms let you sign out of all other devices from your account security settings.
- Run a full security scan on the device you clicked from.
- Contact your bank immediately if any financial information may have been entered or exposed.