Anatomy of a Phishing Email: 5 Red Flags to Look For

By Amit Singla·July 4, 2025·Updated June 26, 2026·4 min read

You Are the Human Firewall

Quick answer

The five red flags of a phishing email are an "off" From address, urgent or threatening language, links that don't match their displayed text, bad grammar and awkward phrasing, and unexpected attachments. When an email feels off, don't click or reply — delete it, or forward it to your helpdesk.

We can install the best firewalls, email filters, and antivirus in the world, but it all comes down to one critical moment: the 3 seconds after an email lands in your inbox. In those 3 seconds, you are the company's last line of defense.

Phishing attacks are getting sophisticated. They look real. They use real logos. But they almost always have "tells." You just need to train your brain to look for them.

Here is the anatomy of a phishing email, and the 5 red flags you should always check before you click.

Red flag How to check
The "From" address is off Hover or tap the sender name to reveal the real address; watch for misspellings or public domains
Urgent or threatening language Be suspicious of any email demanding immediate action or creating panic
The link is wrong Hover over the link to see the actual destination URL before clicking
Bad grammar & awkward phrasing Look for spelling and grammar mistakes a major corporation wouldn't make
Unexpected attachment Never open attachments you weren't expecting; call the sender to verify

Red Flag 1: The "From" Address is "Off"

This is the #1 giveaway. The display name might look perfect (e.g., "Microsoft Security"), but the actual email address behind it is a mess.

How to check: On your computer, hover your mouse over the "From" name. On your phone, tap the name. This will reveal the real email address.

What you'll see:

  • Legit: security@microsoft.com
  • Fake: microsoft.security@1aB-service-92.xyz or microsft.security@gmail.com

Look for misspellings (microsft), or a "public" domain (like @gmail.com or @outlook.net). No legitimate corporation will ever email you from a public domain.

Red Flag 2: The "Urgent" or "Threatening" Language

Phishing attacks rely on social engineering. They want to make you panic. By making you panic, they make you stop thinking and start reacting.

What you'll see:

  • "Your account has been suspended!"
  • "Unusual login activity detected. Your password will expire in 2 hours."
  • "You have an unpaid invoice that is overdue. Click to avoid late fees."
  • "Can you buy 10 Amazon gift cards for a client? I'm in a meeting." (This is a common "CEO Fraud" attack).

The rule: Any email that demands an immediate, urgent action should be treated as suspicious. A real company will not suspend your account via a single, frantic email.

Red Flag 3: The "Hover-to-Discover" Link is Wrong

Just like the "From" address, the link they want you to click is almost never what it appears to be. The text of the link might say Click here to log in, but the destination is malicious.

How to check: On your computer, hover your mouse over the link. Don't click it! Just hover. In the bottom corner of your browser, it will show you the actual destination URL.

What you'll see:

  • Link Text: www.microsoft.com/account
  • Actual URL: http://login-portal.micosoft.net/a9fkeo2

Look for misspellings (micosoft) or a different domain (.net instead of .com). If the link doesn't go where it says it's going, it's a trap.

Red Flag 4: Bad Grammar & Awkward Phrasing

Many (though not all) phishing attacks originate from non-English-speaking countries. The text is often run through a translation program, and it comes out sounding... weird.

What you'll see: "Your account is be suspended for security reason. You must kindly click the link below for update your information."

Major corporations have professional copywriters. Their emails don't have glaring spelling or grammar mistakes. This "awkward" phrasing is a massive red flag.

Red Flag 5: The "Unexpected" Attachment

This is a classic malware vector. You get an email from "UPS" or "FedEx" with an "Invoice" or "Tracking Information" attached. The attachment isn't a PDF; it's a .zip, .html, or .exe file.

The rule: Never, ever open an attachment you were not 100% expecting. If you're not sure, pick up the phone and call the sender (using a number from their official website, not from the email) to verify they sent it.

Your Action Plan: "When in Doubt, Throw it Out!"

It's that simple. If an email feels "off," it probably is. Don't click, don't reply, and don't open the attachment. Just delete it. If you're in a business with an MSP, forward it to the helpdesk (as an attachment) and let them analyze it safely.

It is always better to delete a legitimate email than to click on one malicious link. One click can compromise an entire company.

Ready to Put This Into Practice?

Book a free 30-minute AI Workflow Audit. We'll identify your highest-ROI automation opportunity and show you the exact build plan.

Book Free AI Audit →