How can I tell if a text message or email is a phishing scam?

The practical signs of phishing texts and emails — what scammers do, how to verify anything suspicious, and what to do if you already clicked.

Short answer: treat every unexpected message asking you to click, pay, or share information as guilty until proven innocent. Check the real sender, look for urgency and threats, never click links in the message itself, and verify through the company's official app or website instead.

Phishing works because it mimics routine communications — a package notification, a bank alert, a toll bill — at moments when you are distracted. The messages have gotten polished; spelling errors are no longer a reliable tell. What still gives them away is the structure: a problem, urgency, and a link.

You do not need to become a cybersecurity expert. You need a small set of habits, applied consistently, that make you a hard target.

What phishing is trying to do

Every phishing message has one of three goals: steal your login credentials, steal your payment information, or install malware on your device. Sometimes it is a blend — a fake bank login page captures your password, then asks for your card number "to verify."

The delivery keeps evolving. Email phishing is the classic form. Smishing — phishing by text message — has grown fast because texts feel personal and most people read them within minutes. There are also fake package delivery texts, toll road scams, parking ticket scams, and job offer scams, all following the same playbook.

Knowing the goal helps you see through the costume. Whatever the message claims to be about, ask: is it trying to get me to log in, pay, or download something through this message? If yes, slow down.

Red flag one: the sender is not who it claims to be

On email, check the actual sender address, not just the display name. A message displayed as "Your Bank" might come from an unrelated domain. Scammers use lookalike domains — a zero instead of an O, an extra letter — that pass a quick glance. Expand the sender details and read carefully.

On texts, remember that legitimate organizations rarely send important account notices from random long numbers or personal-looking mobile numbers. Banks, delivery companies, and government agencies have established short codes or verified sender profiles. A text about a "missed package" from an unknown number is almost certainly fake.

Also note: caller ID and sender names can be spoofed. A message that appears to come from someone you know, asking for an unusual favor or a gift card purchase, deserves a verification call on a number you already have — not a reply in the same thread.

Red flag two: urgency, threats, and too-good offers

"Irregular activity detected — verify within 24 hours or your account will be locked." "Your package could not be delivered — pay $2.99 now." "You have an unpaid toll — avoid a $50 fine." The pattern is manufactured urgency: act now, think later.

Legitimate organizations do send time-sensitive messages, but they do not threaten immediate account closure by text, and they do not ask you to resolve billing problems through a link in an unsolicited message. Real urgency comes with real channels — log into your account directly and you will see the same alert if it is genuine.

The mirror image is the too-good offer: a refund you did not expect, a prize you did not enter, a job paying far above market for little work. If you did not initiate it and it sounds generous, it is bait.

Red flag three: the link or attachment

Hover over links (on desktop) or long-press them (on mobile) to preview the destination before tapping. Phishing links lead to lookalike login pages — convincing copies of bank, email, or delivery sites designed to harvest what you type. The page may even show a padlock icon; that only means the connection is encrypted, not that the site is legitimate.

Be especially wary of URL shorteners and slight domain misspellings in links. And treat unexpected attachments with deep suspicion — invoices, shipping labels, and "voicemail" files you did not request are classic malware carriers. When in doubt, do not open it.

A useful rule: if a message says there is a problem with an account, open the company's official app or type its website address yourself. If the problem is real, it will be there. The link in the message is never the safe path.

How to verify anything suspicious

First, stop and do not click. Then verify independently: call the number on the back of your card, log into your account through the official app, or check the delivery company's site with your tracking number from your original order confirmation — not from the message.

For package texts, ask yourself whether you are even expecting a delivery. Most smishing is sent blind to thousands of numbers; the scammer does not know if you ordered anything. No expected package means no legitimate delivery text.

You can also search the message text online. Widespread scams get reported quickly, and you will often find the exact wording flagged within seconds. Forwarding suspicious texts to 7726 (SPAM) in the US helps carriers identify and block scam campaigns.

If you already clicked or shared information

Do not panic, but act quickly. If you entered a password, change it immediately on the real site — and change it anywhere else you reused it. If you entered payment details, call your bank or card issuer to report possible fraud and watch your statements closely.

Run a security scan if you downloaded anything, and consider that your device may be compromised until you have checked. If you gave remote access to your computer to a "support agent" who contacted you, disconnect and get help from someone you trust — that is a full takeover scenario.

Report the message: to the impersonated company (most have a phishing report address), to your carrier, and in the US to the FTC's fraud reporting site. Reporting feels thankless, but it is how patterns get detected and shut down.

Build defenses that work while you sleep

The single most effective protection is two-factor authentication on your important accounts — email first, then banking, then everything else. Even if a phisher steals your password, the second factor stops them. Authenticator apps or hardware keys beat text-message codes, which can be intercepted.

Keep a separate, strong password for your email, because email is the master key: password resets for everything else flow through it. A password manager makes unique passwords painless.

Finally, tell the people around you — especially older relatives, who are disproportionately targeted. A five-minute conversation about the "verify independently" rule protects people who will never read a cybersecurity article.

The newest scams to know about

Scammers iterate quickly, so it helps to know the current crop. Toll road scams have surged: texts claiming you owe a small toll balance with a link to pay, sent to thousands of people who never drove the toll road. Real toll agencies do not collect debts by text link. Similarly, fake parking ticket texts and jury duty scams use official-sounding threats to create panic.

Package delivery scams remain the most common text fraud — "your package could not be delivered" with a link to reschedule. They spike around holidays when everyone is expecting parcels. Remember: the scammer does not know whether you ordered anything. If you are not expecting a package, the message is fake by definition.

Job offer scams target people looking for work: unsolicited texts offering high pay for simple tasks, which evolve into requests for upfront "equipment" payments or overpayment check schemes. Real employers do not recruit by random text. And cryptocurrency or investment "advisors" who contact you out of the blue with guaranteed returns are running advance-fee fraud — the oldest scam in the newest costume.

Calls count too. Not all phishing arrives as text or email. Voice phishing — vishing — uses phone calls from fake bank fraud departments, tech support, or government agencies. The script creates panic ("fraud on your account"), then asks you to "verify" credentials, transfer money to a "safe account," or install remote-access software. No legitimate organization operates this way.

The defense is the same as for messages: hang up and call back on a number you trust. Do not use callback numbers the caller provides, and do not stay on the line while you "check" — scammers will coach you through fake verification steps. A real fraud department will never mind you hanging up and calling the number on your card. Anyone who pressures you to stay on the line is confirming they are a scammer.

Spotting phishing is not about catching every clever forgery. It is about one habit: never trust the message's own links or urgency — verify through channels you chose yourself. Sender oddities, manufactured urgency, and suspicious links are the tells, and they have not changed even as the messages got prettier. Slow down, check independently, and you will sidestep nearly all of it.