Home / Guides / Spot phishing

How to recognize phishing before you click

Updated: August 2026 · By César Cerrudo

A message can have the right logo, the right colors, and even read exactly the way your bank would write it. That doesn't make it real.

Attackers can easily copy a company's appearance. The goal is to make you react before you think.

Signal 1: artificial urgency

"Your account will be blocked in 30 minutes."
"We detected a suspicious payment."
"You must verify your identity immediately."

Urgency is designed to reduce your ability to analyze the situation.

Signal 2: prizes or easy money

"You won a prize." · "You have a pending refund." · "You've been selected."

When something seems unexpectedly beneficial, ask yourself why.

Signal 3: an almost-correct address

Attackers register domains that look like the originals. For example, faceb00k.com can look like facebook.com if you glance at it quickly.

Don't just look at the page design. Look at the exact address.

Signal 4: shortened links

A short link can hide where you'll actually end up. It doesn't automatically mean it's malicious, but it should raise your level of caution.

Signal 5: unexpected files

An unexpected invoice, document, receipt or compressed file can contain malicious software. Don't open a file automatically just because it looks important.

"But the message looks completely real"

That is exactly the point. Logos, names, images and corporate text can all be copied. A professional appearance does not prove authenticity.

Phishing no longer means just email

The same technique shows up in different places:

Attackers change the channel. The psychological technique stays much the same.

What to do when you receive a suspicious message

Don't use the link in the message. Open the official app or type the company's known address yourself.

If it's supposedly your bank, call the official number. If it's supposedly a relative, call them directly.

The golden rule

Doubt. Verify. Then trust.

Keep it handy

The project's free phishing and scams infographic sums up these signals on a single page, ready to print or share on WhatsApp.

Can you spot the traps before you click? Train your eye with real and fraudulent messages.

TRY THE FREE "REAL OR TRAP?" SIMULATOR →
César Cerrudo
About the author

César Cerrudo is a professional hacker and cybersecurity researcher with more than 25 years of experience. He helped secure technologies from Microsoft, Oracle, Twitter and IBM, and is the author of A Hacker's Security Guide, a free guide that helps people, families and organizations learn to protect themselves in the digital world.

DOWNLOAD THE BOOK FREE →