Article
How to Spot a Phishing Email – with Real Examples and Red Flags
grcsolutions.io
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Sender clues “Is it from a public domain (e.g. @gmail.com) but pretending to be from a company?” Is the domain slightly misspelled (e.g. amaz0n.com)?
Is it from a public domain (e.g. @gmail.com) but pretending to be from a company? “Is the domain slightly misspelled (e.g. amaz0n.com)?” Does it differ from how that organisation normally emails you?
Quick phishing checklist: is this email a scam? “Answering ‘yes’ to any of the questions below is a sign the email may be fraudulent.” Sender clues
Is the domain slightly misspelled (e.g. amaz0n.com)? “Does it differ from how that organisation normally emails you?” Content and tone
Are there spelling or grammatical errors? “Does it urge immediate action (e.g. “Act now”, “Your account will be closed”)?” Is the tone inconsistent with the sender’s usual communication style?
Links and attachments “Does the link URL differ from the anchor text?” Is there an unexpected attachment?
Does the link URL differ from the anchor text? “Is there an unexpected attachment?” Are the call-to-action buttons vague (e.g. “Click here”, “Log in now”)?
Phishing is also the most prevalent form of attack: the UK government’s Cyber Security Breaches Survey 2025 found that phishing accounted for 93% of all cyber crime in the UK. “Phishing attacks are designed to manipulate people into giving up sensitive information, clicking malicious links or downloading dangerous attachments.” But while phishing tactics are evolving, so are the ways we can identify and mitigate them. This guide walks you through the most common red flags, updated for 2025 with real examples to help you stay vigilant.