Anatomy of a Phishing Email
Stop trying to sense whether an email “feels off”. A phishing message has five jobs it must do to work, and every one of them leaves a mark you can check in about eight seconds.
The Nigerian prince has retired. He did very well for himself and he is not coming back.
What replaced him is a DocuSign notification that renders perfectly on your phone, uses the right shade of blue, arrives at 4:40pm on a Thursday, and is about an invoice you genuinely are expecting. There are no spelling mistakes. There is nothing to “feel off” about. If your entire defence is a vibe check, you are going to lose.
So let’s replace the vibe check with something that actually works.
The trick: a phish is a machine, and machines have moving parts
Here’s the reframe that makes this easy.
A phishing email is not a mood. It’s a device with a job to do, and that job puts hard constraints on it. It has to arrive in your inbox. It has to get read. It has to make you act quickly. It has to move you somewhere the attacker controls. And it has to extract something.
Five jobs. And every single one of them leaves a physical mark on the message — something you can look at, not something you have to intuit.
Step 1 of 5
1. The sender looks right and isn’t
The display name is the bit you read. The address is the bit that matters. Anyone can set the display name to "Microsoft Account Team" — that field is a nickname, not an identity. Look at the actual address, and look at the very end of the domain.
Step 2 of 5
2. It puts a clock on you
Twenty-four hours or your account is suspended. The payment failed and the order ships tonight. Sign before end of day. The deadline is not a detail of the story — the deadline IS the attack. It exists to stop you doing the one thing that beats it: pausing.
Step 3 of 5
3. The story is boring on purpose
A shared document. A failed delivery. An invoice. An HR policy everyone must acknowledge. Nobody phishes you with anything interesting, because interesting gets forwarded and discussed. Tedious admin gets clicked on autopilot, which is the entire idea.
Step 4 of 5
4. The link does not go where it says
Link text is just text — it can say anything, including a perfectly real web address. Hover on a laptop, long-press on a phone, and read the actual destination. The real site is the last thing before the first single slash, not the first thing you recognise.
Step 5 of 5
5. There is exactly one thing it needs you to do
Type your password. Approve the prompt. Open the attachment. Change the bank details on this invoice. Whatever the story, strip it away and there is a single action underneath that hands over a secret, some money, or control of your machine. Find that action and you have found the point of the email.
Reading a link properly (the two-minute skill)
If you learn one thing from this post, make it this one. It is the single highest -value skill in personal security and it takes about two minutes to acquire.
A web address has a part that matters and a lot of decoration. The part that
matters is the host: everything between https:// and the first single
slash.
https://accounts.google.com/signin → accounts.google.com ✅
https://google.com.account-verify.ru/signin → account-verify.ru ❌
https://account-verify.ru/google.com/signin → account-verify.ru ❌
Look at those last two. Both contain google.com. Neither has anything to do
with Google.
Your brain reads left to right, hits something familiar, and files the whole thing as “fine”. Attackers know this, and it is the entire basis of the trick. The domain is the bit immediately to the left of the first slash, and you read it backwards — rightmost label first.
Think of it as a postal address written in reverse. mail.support.evil.net is a
building called net, a floor called evil, a room called support. It does
not matter what the room is called. You are in the wrong building.
A quick way to make this concrete: paypal.com.security-check.io is not PayPal
any more than “Buckingham Palace Road” is Buckingham Palace.
Two more things worth knowing:
- The padlock proves nothing about honesty. Certificates are free and automatic now, so phishing sites have HTTPS for the same reason everything does. It means “nobody is eavesdropping on this conversation”, not “this conversation is with who you think”. That’s a whole post of its own — The Lock Icon Doesn’t Mean “Safe”.
- Shorteners hide the destination completely. If a link goes through a shortener you weren’t expecting, you cannot check it without visiting it. That’s not “probably fine”, that’s unverifiable, which is a different thing.
The tells that stopped working (please stop teaching these)
Outdated advice is worse than no advice, because it hands people confidence they haven’t earned.
“Look for bad spelling and grammar.” Dead. Utterly dead. Assume every phish you receive is impeccably written, because translation and drafting tools are free and everybody has them. If you are still using typos as your filter, you have effectively trained yourself to trust the well-written attacks.
“Be suspicious of external senders.” The most effective phishing in the world right now comes from inside. Compromise one person’s mailbox, then reply inside an existing thread — real history above your message, real signature, real address, correct authentication records. Your “[EXTERNAL]” banner will not appear, because the sender genuinely isn’t external.
“I wasn’t expecting it.” Attackers send invoice phishing during invoicing season, tax phishing in January, delivery phishing in December, and onboarding phishing to new starters whose LinkedIn just said “excited to announce”. A lot of phishing arrives precisely when you were expecting something like it.
“My spam filter would catch it.” Filters catch mass campaigns brilliantly. The messages that reach you are, by definition, the ones that got through. The filter’s successes are invisible; its failures are your inbox.
The mental shift that makes all of this easy
Here’s the bit I’d tattoo on people if that were legal.
You do not have to work out whether the email is real.
That’s a genuinely hard problem. A well-made phish can be indistinguishable from the real thing — not “hard to tell”, indistinguishable, because it may be a pixel-perfect copy sent from a real compromised account.
You just have to refuse to act on the email’s own terms.
Every phishing attack depends on you using the route it supplied. The link it gave you. The number in the signature. The button. The attachment. Take away that route and the attack has nothing left, whether or not you ever figure out that it was fake.
In practice:
Never log in via a link. If clicking something lands you on a login page — any login page, ever — close it. Open a new tab. Type the address yourself or use your own bookmark. Sign in there. This single habit defeats the overwhelming majority of credential phishing and costs you about four seconds.
Verify through a channel they didn’t give you. Your CFO emails asking you to change the payment details on an invoice? Ring them. Not on the number in the email — on the number in your phone. IT wants you to approve something? Message them on Teams. Bank says there’s a problem? Use the number on the back of your actual card.
Report it, don’t just delete it. Deleting protects you. Reporting protects the other four hundred people who got the same message this morning, and tells someone that a campaign is live. And if you already clicked — report it faster, not slower. The window where that’s a five-minute fix is measured in minutes. The window where it’s a six-week incident response is measured in days. Nobody has ever been fired for reporting quickly. Plenty of people have wished they had.
Try it on real examples
Reading about the five marks is not the same as spotting them at 4:40pm on a Thursday with thirty other things open. Our phishing course walks through real message structures and makes you make the call yourself:
The one thing to take away
Stop asking “does this look legitimate?”
Start asking: “what does this message want me to do, and can I do it a different way?”
The answer to the second half is almost always yes. And when it is, it genuinely does not matter whether the email was real — because you went round it, and the phish quietly failed without you ever having to be clever.