Good to know
The 30-second check (do this every time)
- Check the sender's full email address, not the display name. 'PayPal Support' might actually be from
billing-update@paypa1-secure-mail.com. The display name is free to fake; the domain is not. - Hover over (don't click) every link. On desktop, the real URL appears at the bottom of the screen. On mobile, press and hold to preview. Real PayPal links go to
paypal.com. Anything else is a fake — no exceptions. - Read the greeting and the request out loud. 'Dear Customer' from a service that knows your name is suspicious. So is urgency: 'within 24 hours', 'account will be suspended', 'final notice'.
- Still unsure? Don't click anything. Open a new browser tab, type the company's address by hand, and log in there. Real notifications will be visible in your account.
Example 1 — The fake delivery notification
Why it works
Tells
- The courier name is generic ('Parcel Delivery Service' rather than Australia Post or DHL)
- Real couriers either redeliver free or hold at the depot — they almost never charge a redelivery fee by SMS or email
- The tracking number doesn't exist on the real courier's site
Example 2 — The bank 'security alert'
Why it works
Tells
- The link goes to a domain that looks like the bank but isn't (e.g.
commbank-secure.cominstead ofcommbank.com.au) - Real banks tell you to log in via the app or by typing the address yourself — they don't send 'secure my account' buttons
- If you're unsure, hang up and ring the number on the back of your card
Example 3 — Microsoft 365 password expiry
Why it works
Tells
- Microsoft never asks you to enter your current password to 'extend' it — you change passwords from inside account settings
- The link goes to a Microsoft-themed login page on a non-Microsoft domain
- Logging in hands the attacker your username, password, and (if you approve the prompt) your 2FA code
Example 4 — The Apple ID receipt scam
Why it works
Tells
- Real Apple receipts come from
no_reply@email.apple.comand don't include 'Cancel and refund' buttons - To dispute a real charge, go to
reportaproblem.apple.com— type that yourself, never click the link in the email
Example 5 — The HR / payroll spoof
Why it works
Tells
- The 'Open document' link goes to a Microsoft-themed login page hosted outside your organisation
- Real HR notifications come from a known internal address and usually don't require you to log in again
- When in doubt, message HR via your normal channel (Teams, Slack, internal phone) before clicking
Example 6 — The 'CEO needs gift cards' scam
Why it works
Tells
- The sender address is a free webmail account (gmail.com, outlook.com) using the executive's name as the display name
- Real executives don't ask staff to buy gift cards over email
- 'Don't ring me' is itself a red flag — that's exactly what a real boss wouldn't say
Example 7 — Streaming service payment failed
Why it works
Tells
- The link goes to a Netflix-themed page on a domain like
netflix-billing-update.com - Real streaming services let you update payment details inside the app
- If you're truly behind on payment, the app will tell you when you next open it — there's no rush from email
Example 8 — The 'shared document' from a colleague
Why it works
Tells
- Hover the 'View' button. Real Google Drive links go to
docs.google.com. Real OneDrive links go toonedrive.live.comor a*.sharepoint.comURL tied to your organisation - Anything else is a phishing page that captures your work login
- If unsure, message the colleague directly to ask if they actually shared a document
What to do if you clicked something you shouldn't have
- Clicked the link only? Close the tab. Run a malware scan if you're on Windows or Android. You're almost certainly fine.
- Entered your password? Change it immediately on the real site, and on every other site where you used the same password. Sign out of all active sessions.
- Entered password AND approved a 2FA prompt? The attacker may already be in your account. Treat it as a real compromise: change the password, sign out everywhere, review forwarding rules and recovery email/phone, and follow our Recovery Tool.
- Entered card details? Ring the number on the back of your card and have the card cancelled. Most banks reverse fraudulent charges if you report them within 24 hours.
Three habits that stop almost all phishing
- Use a password manager. It will only auto-fill on the real domain — if it doesn't offer to fill, that's a strong signal you're on a fake.
- Turn on 2FA using an authenticator app (Authy, Aegis, Microsoft Authenticator), not SMS. Even if a phisher captures your password, they need the rotating code to get in.
- Treat every link in every email as suspicious by default. If something says 'urgent action required', open the website by hand. Real urgent things will be visible when you log in.
Good to know
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers