MDaemon Technologies Blog

12 Tips to Identify a Phishing Email

By Brad Wyro

Don’t Risk Losing your Life Savings to Scammers. Follow these 12 Tips to Identify a Phishing Email.

Whether you run a Fortune 500 organization or a small boutique, by now you should be aware of the threats posed by cyber criminals trying to trick you into clicking a link, downloading an attachment, scanning a QR code, or parting ways with your money.

Modern email scams keep getting more sophisticated, and generative AI has removed most of the friction that used to slow attackers down. According to Verizon's 2026 Data Breach Investigations Report (DBIR), the human element (phishing, social engineering, and stolen credentials) was a factor in 62% of breaches, and social engineering remained the third most common attack pattern overall, with email still the primary delivery channel. Verizon's research team, working with Anthropic's Safeguards team, found that attackers are now using AI assistance across a median of 15 distinct attack techniques per campaign, and phishing accounts for 44% of all AI-assisted initial access attempts, the single largest category. The volume of AI-generated text in malicious emails has roughly doubled compared to the prior year.

stat-01-human-element-62pct


That matters because it changes what a phishing email actually looks like. The days of confidently spotting a scam because of a misspelled word or awkward phrasing are fading. Today's phishing emails are often grammatically perfect, personalized, and written in a tone that matches the brand or colleague being impersonated. On top of that, attackers are increasingly moving beyond email entirely: the DBIR found that mobile-centric social engineering (fake texts and voice calls) now converts at a rate 40% higher than traditional email phishing, as people have gotten better at spotting scams in their inbox but remain far more trusting on their phones.

Scammers continue to reap huge payouts from Business Email Compromise (BEC), CEO fraud, and other phishing scams. The FBI's Internet Crime Complaint Center (IC3) reported $2.77 billion in BEC losses in a single recent year, and that figure has continued climbing as attackers pair AI-written emails with real-time, conversational manipulation over chat and voice.

Stat card reading "$2.77B Lost to Business Email Compromise in a single recent year," with a diagram showing a buyer wiring money to a spoofed agent via a real estate closing scam, sourced from the FBI IC3

 

The real estate industry remains a prime target for phishing because large sums of money change hands and there are multiple weak links in the transaction process. If any step in the process is compromised by a successful phishing email, the attacker can gain access to a legitimate email account to launch further attacks, scanning messages for financial or transaction details and then sending fraudulent wire instructions to an unsuspecting buyer, seller, or agent. This exact scenario has cost first-time homebuyers their entire life savings: a buyer under time pressure to close receives an "urgent" message claiming the wire instructions changed, can't reach anyone to confirm in time, and wires a down payment straight to the scammer. In 2026, that same scenario is increasingly reinforced with a follow-up phone call from a cloned voice that sounds exactly like the buyer's actual agent or lender, making the old advice to "just call and confirm" less reliable than it used to be unless you're calling a number you already had on file.

The phishing industry stays lucrative because the barriers to entry keep dropping. Between generative AI, phishing-as-a-service kits, botnets-for-hire, and Malware-as-a-Service (MaaS), attackers now have an impressive arsenal at their disposal to run convincing campaigns at scale. An educated user is still the best defense against phishing. With that in mind, here are 12 updated tips on how to identify and protect yourself from phishing attacks in 2026.

  1. Watch out for messages disguised as something expected, like a shipment, invoice, or payment notification. These often contain links to malware or credential-harvesting sites. Hover your mouse over any links to make sure they're safe before you click. Think before you click.
    Illustrative phishing email mockup for Tip 1: a fake SwiftParcel delivery notice to Frank Thomas, with red-flag callouts marking the mismatched sender domain, generic greeting, false urgency, and a suspicious link preview.

     

  2. Watch for messages asking for personal information, such as account numbers, Social Security numbers, or login credentials. Legitimate companies will never ask for this over email, and they generally won't ask you to "verify your identity" by typing a password into a link either.
  3. Beware of urgent or threatening messages claiming your account has been suspended, a payment failed, or that you must act immediately to avoid a penalty. This now includes fake security alerts and "MFA fatigue" attempts, a flood of real login-approval push notifications sent hoping you'll approve one out of frustration or confusion. Never approve a login prompt you didn't just initiate yourself.
    Illustrative phishing email mockup for Tip 3: a fake IT security alert demanding urgent sign-in approval, with red-flag callouts marking the alarming subject line, vague activity claim, and repeated MFA-fatigue prompts.

     

  4. Don't assume polished writing means it's legitimate. For years, poor grammar and spelling were reliable red flags. That's no longer true. AI tools now let attackers generate fluent, well-formatted, personalized emails with no typos at all, so this tip has flipped: perfect writing is no longer reassuring, and you need the other checks on this list more than ever. If anything, an oddly generic or overly formal tone that doesn't match how a real contact usually writes to you can be a red flag.
  5. Hover before you click! Phishing emails often contain links to malware or fake login sites. Don't trust the visible text of a URL. Always hover your mouse over the link (or long-press it on mobile) to preview its real destination. If a link claims to point to a known, reputable site, it's always safer to manually type the URL into your browser's address bar instead.
  6. Check the greeting. Is the message addressed to a generic recipient, like "Valued Customer" or "Dear Sir/Madam"? Be careful and think twice. That said, don't treat a personalized greeting as proof of legitimacy either. AI makes it trivial for attackers to pull your name from a data breach, LinkedIn, or a prior compromised account and personalize a message convincingly. I see this all the time in my personal, non-business Inbox -subjects like “Brad – Follow-up” or “For Brad.” Don’t fall for it!
    Illustrative phishing email mockup for Tip 6: a fake rewards notice opening with "Dear Valued Customer," with red-flag callouts marking the generic greeting, mismatched domain, and too-good-to-be-true offer.g


  7. Check the signature. Phishing emails often leave out important information in the signature block. Legitimate businesses will typically have complete, accurate contact details. If a signature looks incomplete, generic, or inconsistent with previous messages from that sender, treat it as a warning sign.
  8. Don't download unexpected attachments. Phishing-as-a-service kits make it easy for attackers to distribute malware-laden messages to thousands of targets at once, and a single successful ransomware infection can net a large payout. If there's any doubt about the sender's identity or the contents of an attachment, don't open it. Verify through a separate, known channel first.
  9. Don't trust the From address alone. Many phishing emails use a forged or spoofed sender address, and the display name shown by your email client can be easily faked even when the underlying address is not what it appears to be. Look for authentication signals: SPF, DKIM, and DMARC results, and any sender-verification indicators your email client shows (for example, MDaemon Webmail's From Header Screening and DKIM-verified sender indicator display the true From address and flag inconsistencies that many mail clients hide from you).
    Illustrative phishing email mockup for Tip 9: a fake PayHub billing notice, with red-flag callouts contrasting the friendly display name against the real lookalike sender address and a mismatched Reply-To domain.

  10. Scan QR codes with the same caution as links. QR-code phishing ("quishing") has surged, with Microsoft reporting a 146% rise in QR-based phishing attempts in early 2026 alone, and roughly 1 in 8 phishing emails now embedding a QR code instead of a plain link. Attackers like QR codes because they route the victim to a personal phone, often outside the reach of corporate email security, and because a QR code's destination isn't visible until after you scan it. Preview the URL your phone shows before tapping through, and be especially wary of QR codes claiming to be for MFA resets, payroll updates, or "document access."
    Illustrative phishing email mockup for Tip 10: a fake payroll MFA-reset notice containing a QR code, with red-flag callouts marking the fake sender domain, false urgency, and the unverifiable QR destination.e

  11. Don't assume phishing only arrives by email. Attackers are shifting to text messages (smishing), phone calls (vishing), and messaging apps precisely because people have gotten better at spotting email scams. Voice-cloning tools now make it possible to convincingly imitate a real colleague, executive, or family member's voice in a phone call. Treat an unexpected urgent request over text or phone the same way you'd treat a suspicious email: verify independently before acting, using a phone number or channel you already know is real, not one provided in the message itself.
  12. Be suspicious of any request to "enable content," disable a security warning, or run a script to view a file. Mainstream office software now blocks macros from internet-downloaded files by default, so attackers have shifted to alternate tricks: password-protected ZIP or ISO attachments, disguised shortcut (LNK) files, or instructions to "enable editing" that try to get you to manually bypass built-in protections. If you have to disable a warning to see the content, that's the warning.

While anti-spam, anti-phishing, and AI-assisted email filtering tools are effective at catching the majority of scams, there's still no substitute for good, up-to-date user education, and phishing-resistant multi-factor authentication (like passkeys or FIDO2 security keys) for anything financial or sensitive, since it's one of the few defenses that holds up even against real-time, AI-assisted attacks. Know the potential costs to your business, stay current on how these attacks are evolving, and don't become the next statistic.

 

 

Tags: Email How To, Email Security, Cybersecurity, Stop Spam Email, Spear Phishing, Phishing, Email Security Best Practices

Brad Wyro

Written by Brad Wyro

Brad has worked in technical and marketing roles at MDaemon Technologies, where he contributes as Content Marketing Manager. Brad balances technical and creative information to develop easy to understand videos and content to educate prospects and customers.

BACK TO ALL ARTICLES

Subscribe to Email Updates