How can you recognise a classic phishing email before you fall for it?
It impersonates a company you know, invents urgent pressure ("your account will be blocked"), and pushes you to click a look-alike link and type your credentials.
* Each step looks routine on its own; together they exploit familiarity plus time pressure. *
Phishing (a blend of "password" and "fishing") means spying out your login details, classically by email. A textbook phishing message stacks a few recognisable ingredients — each harmless on its own, dangerous together:
- A familiar sender — it claims to be a bank, shop, or service you actually use, so it reads as routine business.
- Manufactured urgency or threat — an imminent consequence (account lockout, a failed payment, a security "alert") to make you act before you think.
- A call to click — a button or link to "the company's website" that really points to a look-alike domain the attacker controls.
- A data-entry demand — the fake page asks for username, password, card number, and the like, which the attacker then abuses (often to move money at your expense).
Why it works: none of these elements is individually suspicious — a real bank email also has a sender, a link, and a login page. Phishing weaponises that familiarity plus time pressure, so the victim clicks and types on autopilot.
Tip: The two reliable giveaways are (1) a mismatch between a link's displayed text and its real target, and (2) any inbound message manufacturing urgency. The structural defence is never to follow the email's link — reach the service via your own saved bookmark and check the real domain (see the safe-login card).
Go deeper:
Phishing test — eBanking but secure! — try to tell phishing mails from legitimate ones.
CISA — Avoiding Social Engineering and Phishing Attacks — a concise defender's checklist.
Phishing — Wikipedia — techniques, variants, and countermeasures.