Phishing Protection: How to Spot and Avoid Scam Messages
Jordan Pierce
Cybersecurity Writer, SecurFig
Phishing is the practice of pretending to be a trusted sender to trick you into giving up passwords, codes, or money. It arrives by email (phishing), text (smishing), and phone (vishing). The good news: the same handful of tells appears in almost every case, and a calm verification habit defeats most of them.
The Most Common Red Flags
- Urgency or threats. "Your account will be closed in 24 hours," "Unusual activity detected — confirm now." Pressure is designed to bypass your judgment.
- Requests for secrets. No legitimate organization asks for your password, full card number, or one-time code by message.
- Mismatched or look-alike links. The visible text says one thing; the underlying domain is slightly off (swapped letters, extra words, a different country code).
- Unexpected attachments. Invoices, shipping notices, or "voicemail" files you did not ask for are common malware carriers.
- Too-good offers and odd context. Prizes you never entered, a "boss" asking for a urgent wire, a "relative" stranded abroad.
Verify Instead of Clicking
When a message asks you to sign in, don't use its link. Open the service in a new tab by typing the address yourself or using a bookmark you trust. If the alert was real, it will be visible in your account. Hover over links on desktop to preview the true destination, and judge the domain — not the display label.
Protect Your Codes
One of the most damaging phishing goals is your two-factor code. Never read a code from your authenticator app into a page you reached from a message, and never give one to someone who calls. Real support staff do not need it.
On Your Phone
Text scams often impersonate a bank, delivery company, or government agency with a link to "track" or "resolve" something. The same rule applies: go to the official app or site directly. Don't reply "STOP" to a scam text either — that just confirms your number is active and invites more.
What to Do If You Slip Up
- Change the affected password immediately, and change it anywhere you reused that password.
- Review account activity and 2FA settings for anything unfamiliar.
- If you downloaded or ran a file, scan the device and consider it compromised until cleared.
- Use your email provider's "report phishing" button so filters learn from it.
Report It
In the United States, phishing can be reported to the FTC at ReportFraud.ftc.gov, and suspicious texts can be forwarded to SPAM (7726). Your email provider's report button also helps. Reporting does not undo the message, but it strengthens defenses for everyone.
Disclaimer
This article is for general educational purposes only. Scam techniques change constantly. Follow current guidance from the FTC and CISA, and contact the relevant organization through its official channels if you are unsure. This guide does not constitute professional security advice.
Frequently Asked Questions
What is the easiest way to tell if a message is phishing?
Look for pressure to act now, a request for passwords or verification codes, and a sender or link you do not recognize. A message that creates urgency — "your account will close," "unusual sign-in" — and asks you to click a link is the most common phishing pattern. When in doubt, open the site by typing the address yourself instead of clicking.
Is it safe to give a 2FA code if a company "calls" to verify me?
No. Legitimate companies do not call to ask for your password or one-time code. Anyone who does is almost certainly trying to defeat your two-factor authentication. Hang up and contact the company through its official number.
What should I do if I clicked a phishing link?
Change the password of the account involved immediately, enable or review 2FA, and run a scan if you downloaded anything. If the same password is used elsewhere, change it there too. Report the message through your email provider's "report phishing" option so filters improve.
How do I check a link without clicking it?
On desktop, hover over the link to preview the real destination, and look at the domain — not just the display text. Phishers use look-alike domains with swapped letters or extra words. When unsure, navigate to the organization's site directly from a search or your own bookmark.