How to Spot Phishing Emails and Texts Before You Click
Recognize phishing and smishing in 2026 — fake delivery notices, Microsoft/Apple lookalikes, urgent payment scams — and what to do if you already clicked.
Phishing works because it rushes you. The 2026 variants look like Royal Mail/USPS, Microsoft 365, Apple ID, payroll, and “HR updated the handbook.” Your job is not to become a forensic analyst — it is to slow down and verify outside the message.
Layer this with 2FA, a password manager, and malware cleanup if you already ran something. Web shields (affiliate card) help; they are not a substitute for reading the From domain.
The 30-second smell test
Ask:
- Was I expecting this?
- Does it force panic (account closes today, parcel held, CEO needs gift cards)?
- Does it ask for password, codes, crypto, or remote access?
- Does the link domain match the real company when I look carefully?
If two answers feel wrong, treat it as hostile.
Email: where to look
| Element | What to check |
|---|---|
| Display name | Anyone can set “Microsoft Support” |
| Real address | Click or tap to expand — secure-microsoft-login.example.biz is not Microsoft |
| Reply-To | Sometimes differs from From |
| Links | Hover on PC; long-press on phone — read the domain before the path |
| Attachments | Unexpected .html, .iso, .js, macros |
| Branding | Perfect logos mean nothing |
Common 2026 lures
- Shared document that opens a fake Microsoft/Google login
- Delivery fee unpaid
- Payroll / Direct deposit change
- Password expiring for a service you do not use
- Tax refund
- Voicemail transcription with a link
Passkeys reduce damage when available — but only if you refuse fake pages (passkeys guide).
Smishing (SMS) and messaging apps
Texts are shorter, so scammers lean harder on urgency.
Examples:
- “Your package is held — pay £1.50 / $2.99”
- “Your bank locked your card — verify here”
- “Mum changed numbers, send money” (also WhatsApp)
- Fake “WhatsApp verification” codes you did not request
Rules:
- Banks and tax agencies rarely ask you to sign in via SMS cold links
- Call the number on the back of your card, not the number in the text
- For WhatsApp desktop weirdness after a scare, see WhatsApp sync — and never “verify” via a stranger’s link
Voice and QR (“vishing” / “quishing”)
- IT will not call you out of the blue asking for Authenticator codes
- Police/crypto recovery callers demanding remote access are scammers
- QR codes on parking meters / parcel cards can be stickers over real codes — navigate to the company site manually if money is involved
Password managers as phishing brakes
A good manager will not autofill micr0soft.com when the saved site is microsoft.com. That alone stops many real-world phish.
Set one up properly: password manager setup.
If you already clicked
Link only, no login
- Close the tab
- Do not download anything
- Run a quick Defender scan if the page tried to push a file
You entered a password
- From a bookmark or typed URL, change that password
- Change it on any site where you reused it
- Enable 2FA
- Check email forwarding rules and sent folder
- Review bank accounts
You entered an MFA code / approved a prompt
- Change password
- Revoke sessions
- Remove unknown authenticators / app passwords
- Contact the provider’s fraud channel for high-value accounts
You ran a file / “allowed remote access”
- Disconnect network
- Follow malware removal
- Assume credentials stolen — rotate from a clean device
- For ransomware symptoms, see Controlled folder access / backups guide
How to report (US/UK)
- Gmail: Report phishing
- Outlook: Report → Phishing
- Apple: Report junk; forward samples if Apple publishes a current address
- US: IC3.gov for significant fraud
- UK: Suspected scam emails to report@phishing.gov.uk; Action Fraud for many crime reports; Suspected scam texts to 7726
Reporting trains filters that protect everyone else.
Hardening that compounds
| Control | Why |
|---|---|
| 2FA / passkeys | Stolen password ≠ account |
| Password manager | Unique passwords + domain match |
| Web shield / SmartScreen | Blocks known bad URLs |
| Controlled folder access | Limits ransomware blast radius |
| Scepticism on urgency | Human firewall |
Disable noisy notification spam so real MFA prompts stand out: silence Windows notifications.
Pocket checklist
- Pause
- Expand the real sender address
- Hover the link
- Navigate manually — never through cold mail
- Report and delete
- If you typed secrets — rotate + 2FA now
Phishing is a story about fear and shortcuts. You win by being slightly inconvenient to attackers: slow clicks, typed URLs, and passwords that never autofill on impostor domains.
Real-world examples to rehearse
Practice on safe samples from your junk folder: expand the From address, hover every link, and say out loud what the real domain is. Notice how display names say “IT Helpdesk” while the address is a free mail provider. For SMS, ask whether your bank usually texts payment links (most do not). For WhatsApp, verify money requests with a phone call on a known number.
After you almost clicked
Close the tab. Do not enter the same password “just to check.” Run a Defender quick scan if a file downloaded. If credentials were typed, rotate from a bookmark, enable 2FA, and review mail forwarding rules. Put future logins in a password manager so autofill refuses lookalike domains. If a file ran, use malware removal immediately.
Business email compromise basics
If a boss “emails” asking for gift cards or urgent wire transfers, verify by phone using a known number. Check the real domain for lookalikes (rn vs m). Finance teams should require dual approval for payment changes. Home users should apply the same scepticism to family emergency WhatsApp stories.
Frequently Asked Questions
Can phishing emails look perfectly real?
Yes. Logos and language are easy to copy. Always check the real domain and never enter passwords from a cold email link.
What is smishing?
Phishing via SMS or messaging apps — fake parcel, bank, or ‘your account will close’ texts.
I already entered my password — now what?
Change the password from a bookmarked official site, enable 2FA, check forwarding rules, and watch bank statements.
Are QR codes used in phishing?
Yes — ‘quishing.’ Do not scan parcel QR codes from unexpected posters or emails without verifying the sender.
Will a VPN stop phishing?
No. A VPN encrypts traffic; it does not tell you a fake site is fake. Use caution plus a password manager that warns on wrong domains.
Related fixes
Move Google Authenticator & 2FA Before a Phone Repair
Transfer TOTP authenticator apps before drop-off so a wiped phone does not lock you out of email, banking, and crypto — export codes, cloud backup, and printed recovery sheets.
Read the fixAndroid FRP Lock After Repair or Reset? How to Unlock Legally
Stuck on Google Factory Reset Protection after a shop wipe or motherboard swap — prove ownership, use your Google account, and avoid shady FRP ‘bypass’ tools.
Read the fixHow to Disable Copilot and Windows Recall on Windows 11 (2026)
Turn off Copilot, hide the taskbar button, and manage Windows Recall / AI snapshots for privacy and performance on Windows 11 in 2026.
Read the fix