Most people picture a phishing email as something obviously fake. Bad spelling, a fake lottery win, a stranger asking for bank details. That version still exists, but it is no longer the one that works. The messages that succeed today look like a routine part of your day. A package that needs a two dollar redelivery fee. A shared document from a coworker. A text from your bank about a charge you never made. Avoiding phishing is less about spotting bad grammar and more about building a habit that runs before you click.
The reason the old advice stopped working is that the people sending these messages got better tools. Free AI writing assistants produce clean, fluent text in any language and any tone. Attackers also pull real details from data breaches, so a message may mention your employer, your manager’s name, or a recent order. Our breakdown of how to identify AI phishing emails covers the writing tells that still survive, but the short version is this. Tone and polish prove nothing. Behavior proves everything.
The stakes are not small. The Federal Trade Commission reported that consumers lost $12.5 billion to fraud in 2024, up roughly 25 percent from the year before, and imposter scams were the most reported category. The FBI’s Internet Crime Complaint Center recorded $16.6 billion in reported losses the same year. Those figures only count what people noticed and bothered to report, so the true total is higher. A single clicked link can lead to drained accounts, a hijacked email inbox, or months of identity cleanup.
This guide walks through seven steps you can start today. Each one is concrete and takes minutes. You do not need technical skills, and you do not need to become suspicious of everything. You need a short checklist that runs automatically when a message asks you to do something. If you are ever unsure whether a message came from a machine or a person, our guide on how to verify AI versus human contact gives you simple questions that produce clear answers.
What You’ll Need
- A password manager for unique logins
- An authenticator app or passkey for two factor authentication
- A family code word agreed in advance
- Your bank’s official phone number saved in your contacts
- A credit freeze or fraud alert on your three credit reports
How Do You Avoid Phishing?
- Learn the five patterns that cover nearly every phishing attempt.
Phishing messages are built from a small set of patterns. Learn the patterns and you stop needing to judge each message on its own. The five that matter most are urgency, authority, an unexpected link or attachment, a request that touches money or credentials, and a push to move to a different channel. Here is a real example. An email says your account will be closed in 24 hours. It appears to come from your bank. It contains a button. It asks you to confirm your details. That is four patterns in one message.
Attackers also copy context. If your email address appeared in a past data breach, they may already know where you work, who your manager is, and which software your team uses. Free AI writing tools then produce a message in clean, fluent English that matches your company’s usual tone. The old advice to hunt for typos and broken sentences no longer protects you. Treat polished writing as neutral. It proves nothing either way.
Run one question before you touch anything. Does this message ask me to do something I would not normally do right now, on my own, with no prompt? If the answer is yes, stop. Do not reply to ask whether it is real. A reply confirms your address is live and gives the sender a chance to reassure you with a better story.
Set a personal rule and keep it. No link or attachment that arrives in a message may be used for anything involving money, passwords, or personal information. Instead, open the company’s app, or type the web address yourself. Two extra seconds of typing removes most of the risk in this entire article.
- Check the real sender address and the actual destination of every link.
The display name in your inbox is free text. Anyone can set it to your bank’s name or your boss’s name. The address behind it is what matters. On a phone, tap the sender name to expand it and read the full address. On a desktop, hover over it. If the domain is not exactly the one you know, delete the message without opening anything inside it.
Look for lookalike domains. Common tricks include swapping the letter m for the letters rn, using a zero in place of the letter o, adding a hyphen such as micro-soft, and placing the real brand name in a subdomain. A link that reads paypal.com.account-review.xyz does not go to PayPal. The real domain is always the part just before the first single slash after the protocol. Read the address from right to left until you pass the first dot, and judge that word alone.
Do not judge a link by its visible text. The words on screen can say anything while the underlying address goes somewhere else. On a desktop, hover for two seconds and read the status bar at the bottom of the window. On a phone, press and hold the link until a preview appears, then read the domain. If no preview appears at all, do not tap it.
Watch for QR codes in emails, letters, and parking meters. A QR code hides its destination, and phones often preview nothing. Scammers mail fake parking tickets, payroll notices, and delivery slips with codes that lead to a credential harvesting page. If a message contains a QR code you did not expect, verify through an app or a phone number you already have.
Attachments carry risk as well. Be wary of HTML files, password protected ZIP files, and Office documents that ask you to enable macros. Real invoices rarely arrive that way. When in doubt, call the sender using a number already saved in your contacts, never a number printed inside the message.
- Verify money and password requests through a channel you chose yourself.
Any request to move money, change bank details, or reset a password must be verified through a second channel. The key word is second. A separate email thread is not a second channel. A reply is not a second channel. Use a phone number or app you already had before the message arrived.
For a vendor or contractor asking to update payment details, call the person you normally deal with. Confirm the new account on a recorded line or in a signed document. Wire transfer fraud works so well because the request looks like an ordinary update and it usually lands at a busy moment. Slow down and call.
For a bank, utility, or government agency, hang up and call the number printed on your statement, your card, or the agency’s official website. Never use the number in the message. Scammers often keep a caller on the line and pass them to a fake agent who confirms the whole story. The person you are talking to may be part of the same operation.
Voice cloning makes this harder than it used to be. A convincing clone can be built from a short clip of someone’s voice, often pulled from a social media video or a voicemail greeting. If a call sounds like your boss or a relative in trouble, do not decide based on the voice. Ask a question only that person could answer, or hang up and call them back on a number you already have. Our guide to AI voice cloning scams walks through the specific audio tells and the questions that expose a clone quickly.
Agree on a family code word now, before you need it. Pick something unrelated to your daily life and easy to remember. If a caller claims to be a relative in an emergency, ask for the word. A real family member will know it. A clone will not, and neither will the person reading a script.
- Make a stolen password useless with passkeys, codes, and a credit freeze.
Passwords are the weakest link, and phishing exists mainly to steal them. Fix that by making a stolen password far less useful. Start with your email account, because your inbox controls password resets for nearly everything else. If email falls, everything falls.
Turn on a passkey or an authenticator app for email, banking, and any account that stores payment details. A passkey ties the login to your device plus your face or fingerprint. It cannot be typed into a fake login page, so a phishing site collects nothing at all. Authenticator apps that generate a new six digit code every 30 seconds are the next best option. Text message codes are the weakest form of two factor authentication and can be intercepted or moved to another phone through a SIM swap.
Where a service supports security keys, consider a hardware key for your most important accounts. It is a small USB or tap to connect device. A phishing page cannot complete the handshake, so the login simply fails.
Use a password manager to create and store unique passwords. One reused password is enough to unlock several accounts at once. A manager also helps in a quieter way. It refuses to autofill your credentials on a lookalike domain, and that silence is a useful warning sign that something is off.
Check whether your email appeared in a known breach and change that password if it did. Turn on login alerts so you receive a message whenever a new device signs in. Then reduce the damage a stolen identity can cause. A credit freeze is free and blocks new accounts from being opened in your name. Our walkthrough on how to freeze your credit against AI identity theft covers the steps for all three bureaus and how to lift a freeze temporarily when you need new credit. Do the email account first, then the freeze. Together they close the two biggest doors.
- Slow down the three situations attackers engineer for speed.
Most successful phishing depends on speed. Attackers create moments where a slow decision feels expensive. Learn the three setups and you will recognize them in seconds.
The first is a deadline. Your account will be closed, a payment will fail, a delivery will be returned to sender. Give yourself 24 hours before acting on any unsolicited message with a deadline attached. Real institutions do not shut down accounts within an hour by email, and they do not need your password to fix a billing issue.
The second is fear of loss or embarrassment. A message claims a charge you do not recognize, a compromised password, or a legal notice. The emotion is the payload. Log into the service directly by typing the address, and confirm the problem exists before you respond to anyone. Most of the time there is no problem at all.
The third is authority plus secrecy. A message or call claims to be from your boss, the tax office, or IT support, and asks you to keep it confidential. Secrecy is a warning sign. Real processes allow you to check with a colleague, a supervisor, or a family member. Anyone who tells you not to verify is telling you exactly what they are.
Add one more delay that costs nothing. Close the message, do something else for ten minutes, then come back to it. Phishing scripts are written for a person who is reacting. They work poorly on someone who is thinking. This single pause defeats more attacks than most software you could install.
- Run a two-minute family drill so the people around you can spot it too.
Phishing spreads through households and small teams. One person who clicks can expose everyone in their contact list, and the follow up messages arrive with a familiar name attached. A short, calm conversation prevents more losses than any filter.
Sit down with the people you are responsible for. Explain that requests for gift cards, wire transfers, crypto, or login codes are never legitimate when they arrive out of the blue. Set a family rule that nobody sends money based on a message alone, no exceptions and no embarrassment.
Agree on the code word from step three. Make sure everyone knows it and knows how to ask for it without feeling foolish. Shame is the main reason people hide a click until it is far too late. Say out loud that a mistake reported in five minutes is a nuisance, and a mistake hidden for three days is a disaster.
Help older relatives with the technical basics. Turn on two factor authentication, add login alerts, and set up a password manager for them. Review who can see their social media posts, because public birthday posts, pet names, and street photos feed the security questions and personal details that make a phishing message convincing. Our guide on how to protect elderly parents from AI scams covers the settings to change first, including call blocking and voicemail screening.
For a work team, ask IT to run a short training and to publish a one click way to report suspicious messages. People who can report a mistake in seconds will report it. People who fear a reprimand stay quiet for days, which is exactly the window an attacker needs.
- Report the attempt, and clean up fast if you already clicked.
If you spot a phishing message, report it. Reporting helps the next person and it takes about a minute. In the United States, file a complaint with the FBI Internet Crime Complaint Center. Include the sender address, the full headers if you can retrieve them, and any money lost. The IC3 uses these reports to trace campaigns and issue public warnings.
Forward the message to your IT or security team at work, then delete it. Do not forward it to friends as a warning with the link still live, because someone will click it. Take a screenshot instead if you want to show somebody. For text messages, forward the text to 7726, which spells SPAM on a keypad, so your carrier can investigate.
If you already clicked, act in this order. Disconnect from the network if you downloaded a file or gave someone remote access. From a different device, change the password on the affected account and on any account that shares it. Then sign out of all active sessions, which cuts off the attacker’s access immediately. Check your email settings for new forwarding rules, filters, and recovery addresses, because those often survive a password change.
If you entered payment details, call your bank and ask for a card replacement. If you entered a Social Security number or other identity data, place a credit freeze and file a report at identitytheft.gov. Keep a written timeline of what happened and when. Banks, insurers, and police ask for it, and it helps you remember details weeks later.
If money left your account by wire or crypto transfer, contact your bank or exchange the same day. Some transfers can be recalled within hours, and speed decides the outcome. Report the loss to the IC3 and save your report number. Our step by step guide on how to report an AI scam lists the exact places to file and what information each one requires. Finally, tell one other person what happened. One honest story protects more people than any warning banner.
Red Flags & Warnings
- 🚨 Never trust a phone number that appears inside a message. Look it up on the company’s official website or use the number printed on your card, statement, or policy document. Scammers answer their own lines and confirm the story.
- 🚨 Never approve a login prompt or push notification you did not trigger. That prompt means someone already has your password and is trying to finish the login. Deny it, then change the password immediately.
- 🚨 Never install remote access software like AnyDesk or TeamViewer because a caller asked you to. That is not support, it is a burglar asking for the front door key. Hang up and call the company back on a number you looked up yourself.
- 🚨 Do not assume a padlock icon means a site is safe. Padlocks only prove the connection is encrypted, and most phishing pages use encryption too. Judge the domain name instead.
- 🚨 Do not reuse one password across your email, banking, and shopping accounts. One leaked password unlocks the rest through password reset emails, which is why a password manager matters more than a strong memory.
- 🚨 Do not post travel dates, pet names, or a full workplace chart on social media. Those details feed the security questions and the personal touches that make a fake message convincing.
Frequently Asked Questions
What is the single best way to avoid phishing?
Never act on a link, attachment, or phone number that arrives inside a message. Open the company’s app or type the web address yourself, then verify any request through a channel you already trusted. That one habit defeats the large majority of phishing attempts.
Are phishing emails still full of spelling mistakes?
Some are, but the ones that work are usually clean and well written. Cheap AI writing tools now produce fluent text in your language and tone, so grammar is no longer a reliable clue. Judge the request instead of the prose.
A text says it is my bank. How do I check without clicking?
Do nothing with the message. Open your bank’s official app or call the number printed on the back of your card. If the alert is real, the agent or the app will show it. If it is fake, you have just confirmed it without exposing anything.
I clicked a link but did not type anything. Am I safe?
Usually yes, as long as you did not enter credentials, approve a login prompt, or download a file. Close the page, then check your account for new sign ins and change the password if you are unsure. If you downloaded anything, run a full security scan before doing anything else.
Does antivirus software stop phishing?
It helps a little but it is not a solution. Many phishing pages are hosted on legitimate domains and are only live for a few days, so blocklists miss them. Your own habit of typing addresses manually is far more reliable than any filter.
How do I report a phishing text message?
Forward the text to 7726, which spells SPAM on a keypad. That routes it to your mobile carrier for investigation. You can also file a complaint with the FBI Internet Crime Complaint Center at ic3.gov, and forward email phishing to your employer’s security team.
What Should You Remember?
- Verify out of band: confirm every money or password request by calling a number you already had, never one printed in the message.
- Read the real domain: the true destination is the text just before the first single slash, so paypal.com.secure-login.xyz is not PayPal.
- Adopt passkeys: a passkey cannot be typed into a fake login page, which makes it the strongest defense against credential theft.
- Use the 24-hour rule: any unsolicited message with a deadline gets a full day of delay before you act on it.
- Secure email first: your inbox controls password resets for everything else, so protect it before any other account.
- Report within minutes: file at ic3.gov and tell your IT team, because early reports help freeze stolen money and warn others.
This article is for general educational information only and is not legal, financial, or professional security advice. Scam tactics evolve quickly, so verify current guidance with official sources like the FTC, FBI IC3, or CISA before acting. Some links may be affiliate links that support this site at no cost to you.