What Is a Phishing Attack and How to Spot One
Short answer
Phishing is a message that impersonates an organisation you trust in order to get you to type a password, a card number or a login code into a page the sender controls. The reliable tell is not spelling — it is urgency plus a link. Any message that gives you a deadline and a button is worth verifying through a channel you chose yourself.
On this page
Phishing is a confidence trick delivered by message. Someone pretends to be your bank, your employer’s IT desk, a courier or a streaming service, and the entire purpose is to get you to type something secret into a page they control.
The popular description of phishing is badly out of date. Most people were taught to look for bad grammar, odd fonts and strange sender names. Attackers read the same advice, and fixing those things costs nothing. A phishing email in 2026 is frequently a byte-for-byte copy of the real one with the links swapped.
What has not changed is the structure underneath, which is much harder to disguise.
The shape every phishing message shares
Strip away the branding and almost every phishing attempt contains three things in the same order.
- A pretext — a reason this message exists. A payment failed, a parcel is held, someone signed into your account from Lagos, your mailbox is full.
- Urgency or fear — a deadline, a threatened consequence, or alarm. Twenty-four hours. Account suspension. Unauthorised charge.
- A single action — one button, one link, one attachment. Never a list of options, because options give you time to think.
That combination is the signal. A real organisation that needs something from you will usually let you find it yourself by logging in normally. A phishing message cannot afford that, because the moment you navigate to the real site on your own, the trick fails completely.
| What you see | Benign explanation | Phishing explanation |
|---|---|---|
| “Verify your account within 24 hours” | Rare; real deadlines are longer | Standard |
| Link text and destination differ | Tracking redirects, sometimes | Standard |
| Asks for a code you were just sent | Never legitimate | Standard |
| Attachment you did not expect | Occasional from colleagues | Common |
| Arrives at a plausible moment | Coincidence | Often targeted |
That last row deserves attention. A fake parcel notice is far more convincing during the week you are actually waiting for a parcel, and attackers send these in enormous volume precisely because somebody, somewhere, is always waiting for a parcel.
The checks that actually work
Most advice gives you ten things to look at. Three of them do nearly all the work.
Check the domain, reading right to left. In a web address, the meaningful
part is the bit immediately before the first single slash. In
apple.secure-login.example.com, the real domain is example.com — everything
to the left is decoration the attacker chose. People read left to right and stop
at the brand name, which is the entire reason this works.
On a computer, hover over the link and read the address in the status bar at the bottom. On a phone, press and hold the link until a preview appears, then dismiss it without tapping.
Ask what is being requested. Credentials, card numbers, one-time codes and “confirm your identity” forms are the payload. Narrow your suspicion to messages that want one of those, and the volume of things to worry about drops sharply. A newsletter you did not subscribe to is spam, not phishing.
Verify through a channel you chose. This is the only check that cannot be defeated. Do not use the number in the email or the link in the text. Open the app you already have, or type the address you already know, or ring the number printed on your bank card. If the alert was real, it will be waiting for you there.
The ones that are genuinely hard
Some attempts are good enough that the checks above take real effort.
Thread hijacking. Someone’s mailbox has been compromised and the attacker replies inside a genuine, existing conversation — correct subject line, correct history, correct person. There is no spoofing to detect because the account is real. The only defence is to notice that the request is unusual and confirm it by phone.
Lookalike domains. rnicrosoft.com reads as “microsoft” at a glance because
rn resembles m. Mixed-script addresses can push this further. Reading the
domain slowly, character by character, is the defence, and it is one of the few
situations where slowing down genuinely helps.
Invoice and payment-change requests. An email claiming a supplier’s bank details have changed, aimed at whoever pays invoices. These frequently involve no link at all, which defeats every link-based check. Any change of payment details, ever, is confirmed by telephone on a number you already had.
The code request. You receive a genuine verification code from a real service because the attacker has triggered a login, and then a separate message asks you to read it out “to confirm your identity”. No organisation on earth needs you to tell them a code they just sent you. This is the single clearest rule in security, and it is worth remembering as an absolute.
What phishing cannot do
Useful to know, because misplaced fear leads people to ignore the real risks.
- Reading an email does not compromise a device. Mail clients have not executed content automatically for a very long time.
- Hovering over a link is safe. So is looking at a page without typing anything, in the overwhelming majority of cases.
- Phishing is not hacking. Nothing is broken into. You are persuaded to open the door, which is why no amount of antivirus fully solves it.
That last point matters. Security software catches known bad sites and known bad attachments, which helps, but a brand-new phishing page hosted on a legitimate service looks like any other page to a scanner. The decision stays with you.
The two defences worth setting up
If you do nothing else, do these.
Use a password manager and let it fill your passwords. A password manager matches the saved entry to the domain. Land on a lookalike site and it will simply not offer the password, which is a silent, automatic domain check running every time you sign in. Browser-built-in managers do this too.
Turn on two-factor authentication, ideally with an app or a passkey. A stolen password alone then achieves nothing. Passkeys are the stronger option because they are bound to the real site’s domain and cannot be handed to a fake one at all, which removes the human decision from the loop.
SMS codes are weaker than an app, but they are considerably better than nothing, and for an account that offers no other option they are worth enabling.
If you already clicked
Opening the page is usually the end of it. Typing something is not.
The ordered response depends on what you entered, and the first step is almost always changing the password from a different device before anything else — a detailed walkthrough is in what happens if you click a phishing link, and the fuller checklist is in what to do after clicking a suspicious link.
If the message claimed to be from your bank specifically, the header and link checks in telling a real bank email from a fake one go a level deeper than the quick checks here.
Realistic expectations
You will not catch every phishing attempt by inspection, and treating that as the goal is how people end up exhausted and careless. Professional attempts are designed by people who do this full time, against defenders who are doing something else.
The sustainable approach is structural rather than vigilant. Let a password manager refuse to fill credentials on the wrong domain. Let two-factor authentication make a stolen password useless. Then reserve your actual attention for the narrow category that matters: any message asking for a code, a payment detail or a credential, where the rule is simply that you verify it yourself, through a route you chose.