← Back to blog
|6 min read

How to Spot a Phishing Email in 2026: 7 Red Flags Most People Miss

phishingemail securitytips

Phishing is still the number one way people get scammed online. According to the FBI's Internet Crime Report, phishing accounted for over 880,000 complaints in 2025 alone, with losses exceeding $4.5 billion. And the emails are getting harder to spot.

Gone are the days of obvious scams from foreign princes. Today's phishing emails use AI-generated text, pixel-perfect brand cloning, and sophisticated social engineering. Here are seven red flags that can still give them away.

1. The Sender Address Does Not Match the Brand

This is the easiest check and the one most people skip. The display name might say "PayPal Security Team," but the actual email address could be something like security@paypa1-alerts.com or noreply@paypal.billing-center.xyz.

What to look for:

  • Misspelled brand names in the domain (paypa1, arnazon, micros0ft)
  • Extra words appended to the domain (paypal-security-center.com)
  • Legitimate brand names used as subdomains of random domains (paypal.verify-account.com)
  • Free email providers like Gmail or Yahoo being used for "official" correspondence

2. Urgency That Forces You to Act Now

Scammers know that urgency shuts down critical thinking. If an email says your account will be "permanently deleted in 24 hours" or your "payment was declined and service will stop today," take a breath before clicking anything.

Common urgency phrases in phishing emails:

  • "Your account has been compromised"
  • "Immediate action required"
  • "Unusual sign-in activity detected"
  • "Your payment method failed"
  • "Verify your identity within 24 hours or your account will be suspended"

Legitimate companies rarely threaten to close your account via a single email with no prior warning. When in doubt, go directly to the company's website by typing the URL yourself instead of clicking any links in the email.

3. Links That Go Somewhere Unexpected

Hover over any link before you click it. The displayed text might say "Sign in to your account" but the actual URL could point to a completely different domain.

Red flags in links:

  • The display text shows one URL, but the actual link goes somewhere else
  • Shortened URLs (bit.ly, tinyurl.com) that hide the real destination
  • Domains that look similar to real ones but use different TLDs (.xyz, .top, .click)
  • IP addresses instead of domain names

This is one of the most reliable phishing indicators. If the link destination does not match what you would expect from the sender, do not click it.

4. Generic Greetings from Services That Know Your Name

If you have an account with a company, they know your name. An email from your bank that starts with "Dear Customer" or "Dear User" instead of your actual name is worth scrutinizing.

That said, this signal alone is not enough to condemn an email. Some legitimate mass emails use generic greetings. But combined with other red flags, it strengthens the case that something is off.

5. Attachments You Were Not Expecting

Unexpected attachments are one of the most dangerous phishing tactics, especially files with these extensions:

  • .exe, .scr, .bat - executable files that can install malware
  • .zip, .rar - compressed files that may contain executables
  • .docm, .xlsm - Office files with macros enabled
  • .html - web files that can redirect to phishing pages

If you were not expecting an attachment, do not open it. Even if the email appears to be from someone you know, their account may have been compromised.

6. Requests for Sensitive Information

No legitimate company will ask you to reply to an email with your password, Social Security number, credit card details, or other sensitive information. If an email asks for this, it is a scam. Full stop.

This includes emails that direct you to a webpage where you need to "verify" your credentials. Banks, payment processors, and tech companies have secure channels for identity verification. They will never ask you to email your password.

7. Something Just Feels Off

Trust your instincts. If the formatting looks slightly wrong, the tone is unusual for the sender, or the request seems out of character, pay attention to that feeling. Scammers can replicate logos and formatting, but they often miss subtle details like:

  • Inconsistent spacing or alignment
  • Slightly off-brand colors
  • Footer information that does not match the real company
  • Mixed languages or unusual phrasing

How AI Can Help

Even with these tips, sophisticated phishing emails can fool anyone. That is where AI-powered tools like PhishArmor come in. Instead of relying on a single signal, AI analyzes dozens of indicators simultaneously: link patterns, language analysis, sender verification, domain reputation, and more.

PhishArmor gives you a clear scam score from 0-100 for every email you scan, along with a breakdown of exactly which signals triggered and why. It catches the things humans miss, like subtle domain misspellings or hidden URL redirects that are invisible in normal email clients.

Stay Safe

Phishing will keep evolving, but the fundamentals of spotting it remain the same: slow down, verify the sender, hover before you click, and when in doubt, go directly to the source instead of using any links in the email.

And if you want an extra layer of protection, try PhishArmor. It is free to use with 10 scans per month, and it takes less than a minute to install.

Try PhishArmor Free

Scan emails and webpages for phishing with AI-powered detection. 10 free scans per month, no credit card required.

Install PhishArmor