You open your inbox and there it is. “Your account will be suspended in 24 hours.” Or “Dear valued customer, we noticed unusual activity.” Your stomach drops a little. Is this real? Should you click? Should you panic?
Take a breath. Most of the time, that gut feeling of “something’s off” is right. You just need to know what to look for so you can trust it.
I get asked about this a lot, not just by clients but by family too (hi, Dad). So let’s break it down the easy way, no tech degree required.
AI Doesn't search the way Google used to
The First Clue: Who's Actually Sending This?
Here’s the thing scammers count on: you looking at the name, not the actual email address. “Amazon Support” sounds official right there in your inbox. But tap or hover on it, and the real address might be something like [email protected]. See that zero instead of an “o”? That’s the trick.
Real companies send from their real domain. Every time. If PayPal is emailing you, it’s coming from @paypal.com, not @paypal-secure-alerts.com or some other lookalike. So before you do anything else, check who’s really talking to you.
Words That Should Make You Suspicious
Scam emails have a “voice” of their own, and once you know it, you’ll spot it fast. Watch for:
- The generic greeting. “Dear Customer” or “Dear valued user” instead of your actual name. Real businesses that have your info usually know your name.
- The panic button. Lines like “immediate action required” or “your account will be closed” are built to make you click before you think.
- The weird phrasing. Odd grammar, random capital letters, or sentences that just sound a little… off. Real companies proofread. Scammers, often working fast and from templates, don’t always bother.
- The ask. Any request to “confirm your password” or “verify your account” by clicking a link. Legit companies almost never ask for that over email.
If you see two or more of these in the same message, that’s your answer.
Check the Link Before You Click It
This one’s simple but it saves you every time: hover your mouse over any link (or press and hold on your phone) before you tap it. A little preview pops up showing where it actually goes. If the email says “click here to view your invoice” but the link points to some random string of letters and numbers, don’t click it. Trust the preview, not the button text.
When in Doubt, Go Around the Email
If something seems urgent, like your bank saying there’s an issue, don’t use anything in that email to check it out. Don’t call the number listed. Don’t click the “login” button. Instead, open a new tab and go directly to the company’s website, or call the number on the back of your card. Scammers love putting fake contact info right in the email so you stay trapped in their setup. Google has a good rundown on how to spot and avoid phishing scams if you want another source to double-check yourself against.
A Quick Trick for the More Curious
If You Already Clicked... Don't Panic, Just Act Fast
We’ve all been there, you click before your brain catches up. Here’s what to do, in order:
- Disconnect from Wi-Fi for a minute so nothing keeps talking to that server in the background.
- Don’t type anything if a login page popped up. Just close it.
- Run a quick antivirus scan on your device.
- Change your passwords, starting with whatever account they were pretending to be, plus your email.
- Turn on two-factor authentication wherever you can.
- Report the email as phishing in Gmail, Outlook, or whatever you use. Takes ten seconds and helps flag it for others too.
The Bottom Line
Scam emails are getting smarter (thanks, AI), but the basics still work: check the real sender address, watch for pressure tactics and generic greetings, hover before you click, and when something smells off, verify it somewhere other than the email itself. Takes 30 seconds, saves you a giant headache.
And hey, if your business gets a lot of these impersonation attempts, or customers are getting fake emails pretending to be you, that’s usually a sign your domain needs some security setup (things like SPF, DKIM, and DMARC). Worth a conversation with whoever manages your website.
FAQ
How can I tell if an email is fake fast?
What should I do if I already clicked a suspicious link?
Can scam emails really look identical to real ones now?
Is it safe to just open a suspicious email?
Opening it is generally low-risk. The danger comes from clicking links, downloading attachments, or replying with personal info. Still, avoid opening anything from a sender you truly don’t recognize.