What a Phishing Email Looks Like, in Plain English
September 28, 2026 · by Porchswing Technology
A phishing email is a fake message that pretends to be from a company or person you trust, like your bank, Amazon, the IRS, or even a friend. Its real goal is to get you to click a link, open an attachment, or type in a password so a scammer can steal it.
These emails have gotten harder to spot. The old advice — "look for bad spelling" — still helps sometimes, but many phishing emails today are polished and use real logos. This article walks through what to actually look at, so you can tell a real email from a fake one before you click anything.
You don't need to be a computer expert to catch these. A few careful habits go a long way.
Where the email really comes from
The name shown at the top of an email ("Amazon Support" or "Wells Fargo Security") is easy to fake. What matters more is the actual email address underneath it.
On an iPhone or iPad, tap the sender's name at the top of the message. On a Windows or Mac computer, hover your mouse pointer over the name without clicking, or click the little arrow next to it. Either way, look at what shows up after the @ symbol.
A real Amazon email comes from an address ending in @amazon.com. A phishing email might use something close but wrong, like @amazon-support.net or @amaz0n-help.com (with a zero instead of the letter O). If the ending doesn't match the company's real website address, that's a strong sign it's fake.
Urgent language is a warning sign, not a reason to hurry
Phishing emails almost always create pressure to act fast: "Your account will be suspended in 24 hours," "Unusual sign-in detected," "Your package couldn't be delivered." The rush is the point — it's meant to stop you from thinking clearly or asking someone else for a second opinion.
A real company rarely threatens to lock your account over email within a day. If a message makes you feel scared or rushed, that feeling itself is a clue. Take a breath. You can always contact the company directly using the phone number on your bank statement, a bill, or the back of your card — never a number or link from the email itself.
Check the link before you tap or click
Phishing emails almost always want you to click a link. On a computer, hover your mouse over the link without clicking, and look at the address that appears at the bottom of the screen. On an iPhone, press and hold the link (don't tap it) to see a preview of where it actually leads.
Compare that address to the company's real website. Watch for small changes: extra words, misspellings, or a different ending than you'd expect (like .info or .xyz instead of .com). If the link doesn't match, don't click it — close the email instead.
If you're ever unsure whether a pop-up warning or a link is real, what to do when a pop-up says your computer is infected walks through a similar situation step by step.
Requests for passwords, gift cards, or personal information
No legitimate company will ever email you asking you to reply with your password, your Social Security number, or your full credit card number. Real companies also don't typically ask you to pay a bill or a "fee" using gift cards — that request, by itself, is one of the clearest signs of a scam, in email or over the phone.
If an email asks you to "verify your account" by logging in through a link, don't use that link. Instead, open a new browser tab yourself and type in the company's website address directly, or use the app you already have on your phone.
Attachments you weren't expecting
Be cautious about opening an attachment you didn't ask for, especially one named like an invoice, a shipping label, or a document you need to "review immediately." These attachments can contain malware — that means harmful software that can damage your computer or steal information once it's opened.
If you weren't expecting a file from that person or company, it's safer to delete the email than to open the attachment to check.
What to do if you already clicked a link in a phishing email
If you clicked a link or opened an attachment and now feel uneasy, don't panic, and don't feel embarrassed — these emails are designed by professionals to fool careful people. Disconnect from the internet if you can, and avoid entering any more passwords until your computer has been checked. If you typed a password into a site you now think was fake, change that password on the real site as soon as possible, from a computer you trust.
If something already feels wrong, or you'd rather a person walk through it with you, we can help in your home or remotely.
A calmer way to stay ahead of it
You don't have to catch every phishing email perfectly on your own. If you want quiet protection on your Windows or Mac computer — with a real Porchswing person to call — learn about PorchswingProtect. Or call us at (916) 521-0065 and we'll help you set it up.
Common questions
Can a phishing email infect my computer just by opening it?
Simply opening most emails is safe. The risk comes from clicking a link, opening an attachment, or entering information on a fake website the email links to.
Why do I keep getting these emails if I never gave out my address?
Email addresses get shared, sold, or leaked in ways you have no control over. Getting phishing emails isn't a sign you did something wrong — it happens to almost everyone with an email account.
Should I reply to a phishing email to tell them to stop?
No. Replying confirms your email address is active and being read, which can lead to more attempts. It's better to simply delete the email or mark it as spam or junk.