Phishing email examples: 8 real scams (with screenshots) and how to spot them

    Eight real phishing email patterns we see again and again, what tipped them off as fakes, and the simple 30-second habit that beats every one.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 7 min read

    Eight real phishing patterns we see again and again, what tipped them off as fakes, and the 30-second habit that beats every one.
    Phishing is still the single most common way ordinary people get hacked. Not because the emails are clever — most are clumsy — but because they arrive at the right moment, mimic a brand you trust, and ask you to do something that feels small. Click a link. Confirm a password. Approve a payment.

    Good to know

    🎯 Goal: By the end of this guide you'll be able to spot 95% of phishing emails in under 30 seconds, and know exactly what to do if you've already clicked something you shouldn't have.

    The 30-second check (do this every time)

    Before we get to the examples, here's the routine that catches almost every phishing attempt. Run it on any email asking you to click a link, log in, pay something, or 'verify' an account.
    1. Check the sender's full email address, not the display name. 'PayPal Support' might actually be from billing-update@paypa1-secure-mail.com. The display name is free to fake; the domain is not.
    2. Hover over (don't click) every link. On desktop, the real URL appears at the bottom of the screen. On mobile, press and hold to preview. Real PayPal links go to paypal.com. Anything else is a fake — no exceptions.
    3. Read the greeting and the request out loud. 'Dear Customer' from a service that knows your name is suspicious. So is urgency: 'within 24 hours', 'account will be suspended', 'final notice'.
    4. Still unsure? Don't click anything. Open a new browser tab, type the company's address by hand, and log in there. Real notifications will be visible in your account.

    Example 1 — The fake delivery notification

    Subject: "Your parcel could not be delivered (TRACKING #AU8392012)"
    Body: "Hi, We attempted delivery of your package today but no one was home. Please confirm your address and pay the AUD $1.99 redelivery fee within 48 hours or your parcel will be returned to sender."

    Why it works

    People are always waiting for a parcel. The fee is small enough that 'just paying it' feels easier than arguing. The link goes to a convincing fake of the courier's website, which captures your card details.

    Tells

    • The courier name is generic ('Parcel Delivery Service' rather than Australia Post or DHL)
    • Real couriers either redeliver free or hold at the depot — they almost never charge a redelivery fee by SMS or email
    • The tracking number doesn't exist on the real courier's site

    Example 2 — The bank 'security alert'

    Subject: "Unusual sign-in attempt from Lagos, Nigeria"
    Body: "We detected a sign-in to your account from a new device. If this wasn't you, secure your account immediately."

    Why it works

    The fear that someone is in your bank account is paralysing. The 'helpful' button feels like the responsible thing to click.

    Tells

    • The link goes to a domain that looks like the bank but isn't (e.g. commbank-secure.com instead of commbank.com.au)
    • Real banks tell you to log in via the app or by typing the address yourself — they don't send 'secure my account' buttons
    • If you're unsure, hang up and ring the number on the back of your card

    Example 3 — Microsoft 365 password expiry

    Subject: "Your password expires today — action required"
    Body: "Your Microsoft password expires in 4 hours. To avoid losing access, click below to verify your password and extend it for another 90 days."

    Why it works

    Office workers see real password-expiry emails routinely. The format is easy to copy.

    Tells

    • Microsoft never asks you to enter your current password to 'extend' it — you change passwords from inside account settings
    • The link goes to a Microsoft-themed login page on a non-Microsoft domain
    • Logging in hands the attacker your username, password, and (if you approve the prompt) your 2FA code

    Example 4 — The Apple ID receipt scam

    Subject: "Your receipt from Apple — Order #MY7-AB39201"
    Body: "Thank you for your purchase. Final Fantasy XVI — $79.99 USD. If you did not authorise this transaction, click here to dispute the charge."

    Why it works

    You panic at a charge you didn't make and click 'Cancel' before reading anything else. The cancel link asks you to log in to your Apple ID — which is exactly what the attacker wants.

    Tells

    • Real Apple receipts come from no_reply@email.apple.com and don't include 'Cancel and refund' buttons
    • To dispute a real charge, go to reportaproblem.apple.com — type that yourself, never click the link in the email

    Example 5 — The HR / payroll spoof

    Subject: "Updated payroll details — please review"
    Body: "Hi [first name], HR has updated your payroll information following the recent system migration. Please review and confirm by Friday."

    Why it works

    It looks internal. It uses your first name. It's a vague request you'd normally just action and forget.

    Tells

    • The 'Open document' link goes to a Microsoft-themed login page hosted outside your organisation
    • Real HR notifications come from a known internal address and usually don't require you to log in again
    • When in doubt, message HR via your normal channel (Teams, Slack, internal phone) before clicking

    Example 6 — The 'CEO needs gift cards' scam

    Subject: "Quick favour"
    Body: "Hi [name], are you available? I'm in a meeting and need you to grab some Apple gift cards for a client thank-you. Send me $500 worth and photograph the codes. Don't ring me, I'm in a workshop. — [Real CEO's name]"

    Why it works

    New employees especially. The pressure of a senior person asking a small favour combined with 'don't ring me' shuts down the obvious sanity check.

    Tells

    • The sender address is a free webmail account (gmail.com, outlook.com) using the executive's name as the display name
    • Real executives don't ask staff to buy gift cards over email
    • 'Don't ring me' is itself a red flag — that's exactly what a real boss wouldn't say

    Example 7 — Streaming service payment failed

    Subject: "Your Netflix payment was declined"
    Body: "We were unable to charge your card for the August billing cycle. Update your payment details within 48 hours to avoid suspension."

    Why it works

    Almost everyone has Netflix or a similar service. A small amount of effort to 'fix' it feels worth doing.

    Tells

    • The link goes to a Netflix-themed page on a domain like netflix-billing-update.com
    • Real streaming services let you update payment details inside the app
    • If you're truly behind on payment, the app will tell you when you next open it — there's no rush from email

    Example 8 — The 'shared document' from a colleague

    Subject: "[Colleague's real name] shared a document with you"
    Body: "View Q4 Budget — Final.xlsx. This document expires in 24 hours."

    Why it works

    It's an exact copy of a real Google Drive or OneDrive sharing notification. The sender name matches a real person you know. The 'expires in 24 hours' creates urgency.

    Tells

    • Hover the 'View' button. Real Google Drive links go to docs.google.com. Real OneDrive links go to onedrive.live.com or a *.sharepoint.com URL tied to your organisation
    • Anything else is a phishing page that captures your work login
    • If unsure, message the colleague directly to ask if they actually shared a document

    What to do if you clicked something you shouldn't have

    • Clicked the link only? Close the tab. Run a malware scan if you're on Windows or Android. You're almost certainly fine.
    • Entered your password? Change it immediately on the real site, and on every other site where you used the same password. Sign out of all active sessions.
    • Entered password AND approved a 2FA prompt? The attacker may already be in your account. Treat it as a real compromise: change the password, sign out everywhere, review forwarding rules and recovery email/phone, and follow our Recovery Tool.
    • Entered card details? Ring the number on the back of your card and have the card cancelled. Most banks reverse fraudulent charges if you report them within 24 hours.

    Three habits that stop almost all phishing

    1. Use a password manager. It will only auto-fill on the real domain — if it doesn't offer to fill, that's a strong signal you're on a fake.
    2. Turn on 2FA using an authenticator app (Authy, Aegis, Microsoft Authenticator), not SMS. Even if a phisher captures your password, they need the rotating code to get in.
    3. Treat every link in every email as suspicious by default. If something says 'urgent action required', open the website by hand. Real urgent things will be visible when you log in.

    Good to know

    🩺 Want to assess your overall posture? Our free Cyber Security Health Check takes 5 minutes and tells you where your weakest spots are — phishing-related and beyond.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security