Clear, practical technology insights
Recognize Phishing and ScamsLesson 4 of 15

Spot common phishing signals

Modern phishing messages can use correct spelling, copied logos, real names and details from previous conversations. A single clue such as poor grammar is therefore unreliable. The stronger method is to compare the message with what you expected, inspect the actual sender and requested action, and verify through a channel that the message did not provide. This lesson builds a repeatable triage process for email, text messages, collaboration apps and phone calls.

12 min Beginner Recognize Phishing and ScamsReviewed 2026-07-30 00:00:00
Learning objectives

What you will learn

  • Identify high-risk request patterns without relying on grammar.
  • Separate display names from actual sender addresses.
  • Recognize urgency, secrecy and payment manipulation.
  • Verify a request without replying to the suspicious message.
Before you start

What you need

  • A suspicious example or a harmless training message.
  • Access to a known contact method for the claimed sender.

Start with context, not appearance

The FTC warns that phishing messages commonly invent an urgent story and ask the recipient to click a link, open an attachment or provide personal or financial information.

CISA lists recognizing and reporting phishing as one of the core actions that reduce common online risk.

Ask whether you expected the message, whether you normally communicate this way and whether the requested action matches an established process. A real logo and familiar signature can be copied in seconds.

Phishing review funnel showing context, identity, request and independent verification.
No single clue proves phishing; combine context, identity and a trusted verification channel.

Inspect identity beyond the display name

Expand the full sender address and reply-to address. In collaboration tools, open the user profile and organization information. For phone calls, remember that caller ID can be spoofed. A compromised real mailbox can also send malicious requests, so a correct address is evidence—not proof.

  1. 1

    Read the complete sender address, including the domain after @.

  2. 2

    Compare the domain with a known previous message or official website.

  3. 3

    Check whether Reply-To differs from From.

  4. 4

    Look for a newly created conversation that imitates an old thread.

  5. 5

    Treat requests from a real account as suspicious if the action is unusual.

Classify the requested action

High-risk requests often seek credentials, MFA codes, gift cards, urgent bank changes, cryptocurrency, confidential files, remote-access software or secrecy. Some phishing messages contain no link; they begin a conversation and introduce the harmful request later.

  1. 1

    Write down exactly what the sender wants.

  2. 2

    Mark whether the request changes payment, payroll, recovery or account access.

  3. 3

    Do not open the link or attachment during triage.

  4. 4

    Do not call a number supplied only in the message.

  5. 5

    Preserve the message if your workplace has a reporting process.

Verify through a trusted route

Use an address, app, phone number or conversation you already trust. Contact the person directly, begin a new message thread or open the organization account independently. Verification is not an accusation; it is a normal control for unusual requests.

  1. 1

    Open the official app or type the known website.

  2. 2

    Use a saved contact or published phone number.

  3. 3

    Ask the claimed sender to restate the request through that channel.

  4. 4

    Report the suspicious message using the platform or workplace tool.

  5. 5

    Delete it only after any required evidence is preserved.

Verification checklist
  • The verification route did not come from the suspicious message.
  • No credentials, codes or payments were shared.
  • The message was reported when appropriate.
Hands-on practice

Triage three sample messages

Use one email, one text and one phone scenario.

  1. 1

    Describe the context and whether the message was expected.

  2. 2

    Record sender identity evidence.

  3. 3

    Classify the requested action and possible impact.

  4. 4

    Choose an independent verification channel.

  5. 5

    Write the safe response without clicking or replying.

Common mistakes to avoid

  • Trusting a message because the grammar is good.
  • Treating a familiar display name as identity proof.
  • Using the phone number or link supplied in the request.
  • Assuming a real compromised mailbox cannot send phishing.
Lesson recap

Key takeaways

  • Context and requested action matter more than visual polish.
  • Correct sender details reduce uncertainty but do not eliminate risk.
  • Independent verification breaks the attacker-controlled path.

Frequently asked questions

Can a message from a real colleague still be phishing?

Yes. Their account may be compromised, or the request may be an impersonation in a new channel. Verify unusual actions independently.

Should I reply asking whether the message is real?

Use a separate trusted channel. Replying keeps you inside the path controlled by the suspicious message or compromised account.

Evidence and updates

Sources and further reading

  1. Phishing scams can be hard to spotFederal Trade Commission
  2. Use Strong PasswordsCISA
Finish this lesson

Ready to continue?

Mark the lesson complete so your Learning Path progress stays current on this device.