How to Spot a Phishing Email in the Age of AI

Phishing is the email that pretends to be someone you trust, your bank, your employer, a delivery service, a login provider, so you click, sign in, or reply. This guide is for anyone with an inbox. It covers what phishing tries to achieve, the modern red flags that still work now that AI writes flawless copy, and a safe way to verify a suspicious email without taking the bait.

How we check this: Reflects how CISA, the FTC, and email-security researchers describe phishing tactics, including AI-generated content. · Last reviewed: 2026-08

What a phishing email is trying to do

Phishing is a numbers game played over email. A message impersonates a trusted sender and tries to get you to take one specific action: click a link to a fake login page, open an attachment, or reply with sensitive information. The endgame is almost always your credentials, a verification code, or a payment.

Most phishing is sent broadly to thousands of addresses. A more dangerous version, spear-phishing, is tailored to you specifically, using your name, your employer, or a project you are working on to seem legitimate. And business email compromise targets companies, impersonating an executive or vendor to trigger a wire transfer. Different scale, same core trick: borrow a trusted identity to make you act.

Why "bad grammar" is no longer a reliable tell

For years the standard advice was to watch for typos and clumsy phrasing. That advice is now out of date. AI writing tools let anyone produce clean, professional, perfectly-spelled emails in any language and any tone, matching a bank's formal style or a colleague's casual one. The awkward, error-filled phishing email still exists, but its absence proves nothing.

So stop grading a message on its writing quality and start reading its intent and its technical details. A flawless email can still be a scam. Judge it by what it is asking you to do, who it claims to be from at the technical level, and where its links actually lead, none of which AI can fake as easily as prose.

The red flags that still work

Look at the sender's actual address, not just the display name. Display names are trivial to fake; the real address behind them is harder to disguise and often reveals a wrong or lookalike domain. A message "from your bank" that actually comes from a random or misspelled domain is spoofing in plain sight.

Inspect links before clicking. Hover over a link (or long-press on mobile) to reveal the true destination and compare it to the company it claims to be from. Watch for typosquatting, a domain that swaps, adds, or drops a character so it reads correctly at a glance. If the visible text says one thing and the real URL says another, do not click.

Then weigh the ask and the pressure. Phishing almost always wants you to log in, confirm details, open an attachment, or pay, usually right now, or something bad happens. Unexpected password-reset prompts, "unusual sign-in" warnings, invoices you do not recognize, and urgent security alerts are the classic hooks. The combination of an unexpected message, a request to authenticate or pay, and time pressure is the real signature of phishing.

The common phishing storylines to recognize

Phishing tends to reuse a handful of emotional storylines, and knowing them makes each one easier to catch. The "security alert" claims unusual activity or a sign-in from a new device and urges you to verify, steering you to a fake login page where your real password is captured. The "account will be closed" or "payment failed" story threatens loss of service unless you confirm your details or update a card right now. The "you have a document / voicemail / package" story dangles a link to something you supposedly need to open.

In workplaces, two variants do the most damage. Business email compromise impersonates an executive or a trusted vendor and requests an urgent wire transfer, a change of bank details, or gift cards, often timed for when the real person is traveling and hard to reach. Fake invoice emails attach or link to a document that either harvests credentials or requests payment to a new account. Both rely on authority and time pressure rather than any technical trick.

None of these storylines depends on bad writing to succeed; they depend on you reacting to the emotion. When you notice the plot, fear, loss, obligation, or authority combined with a link and a deadline, you can step back and verify through a channel you trust rather than the one the email handed you.

What happens if you take the bait

If you clicked a link but did nothing else, the immediate risk is lower, though the page may have tried to load something or collect your information. It is worth knowing what to do next and watching your accounts for a while. If you actually entered your password on the fake site, treat those credentials as compromised: change that password immediately, change it anywhere you reused it, and turn on two-factor authentication. Speed matters here, because stolen credentials are often used within minutes.

We keep the detailed recovery steps on their own pages so you can act quickly on the exact situation you are in. The two below cover the most common outcomes of a phishing email. Acting fast is what limits the damage, so do not let embarrassment slow you down, attackers move quickly, and so should you, one clear step at a time.

A safe way to verify a suspicious email

The safest response to a doubtful email is to never use anything inside it. Do not click its links, call its phone numbers, or reply to its address. Instead, verify through a path you control: open the company's app directly, type its website into your browser yourself, or call the number printed on your card or a statement. If the email is real, you will find the same notice waiting for you inside your account.

For a fast second opinion before you act, you can paste the email's text, the sender's address, or a link into Hunch. It flags the signal categories it recognizes, a lookalike domain, an urgent tone, a credential or payment request, so you can decide with more information and less pressure. Verifying costs a minute; entering your password on a fake page can cost far more.

One habit is worth building above all others: never authenticate or pay in response to an inbound message. Whenever an email prompts you to log in, confirm a code, or send money, make it a reflex to leave the email entirely and start from your own trusted starting point instead. If you internalize just that one rule, the vast majority of phishing simply stops working on you, no matter how convincing or well-written the message becomes.

FAQ

Can a phishing email look completely professional?

Yes. AI tools now produce clean, well-written phishing in any style or language, so good grammar and formatting no longer indicate a message is safe. Judge it by its intent, sender address, and links instead.

How do I check where an email link really goes?

Hover over the link on a computer, or long-press it on a phone, to reveal the true destination without opening it. Compare that address to the company it claims to be from and watch for lookalike spellings.

What is the difference between phishing and spear-phishing?

Phishing is sent broadly to many people, while spear-phishing is tailored to a specific person using details like your name or employer to appear more convincing.

What should I do if I clicked a link in a phishing email?

If you only clicked, watch your accounts and follow the clicked-link steps. If you entered a password, change it everywhere you used it and enable two-factor authentication right away.

Read more

Check a suspicious message now

Detection runs 100% locally on your device. We store nothing.

Please don’t paste other people’s personal data. Detection runs 100% locally on your device, and we store nothing.

Or try a real one:

Get it free

Or check it on Telegram