Cybersecurity

Five signs a message is trying to trick you

3 min read

Most scam messages share the same handful of tells. Learn the five to look for, and the one habit that protects you even when a message looks perfect.

In brief

Phishing is a message, by email, text, phone call or chat, that pretends to come from someone you trust so that you hand over a password, a payment or a code. The messages have become more polished, but the tricks underneath them have not changed. Five signs catch most of them, and one habit catches the rest.

1. It wants you to act right now

Urgency is the engine of nearly every scam: an account "will be closed today", a parcel "cannot be delivered", a payment "failed". The pressure exists to stop you thinking. Real organisations rarely need you to act within minutes, and never need you to do it from a link in the message.

2. The sender does not quite match

Look at the actual address, not the display name. A bank does not write from a free webmail address, and a company's name with a letter swapped or an extra word added is a copy, not the original. On a phone, tap or long-press the sender name to see the address behind it.

3. The link goes somewhere unexpected

Hover over a link on a computer, or press and hold on a phone, to see where it really leads. The part that matters is the last piece before the first single slash: example.com/login belongs to example.com, but example.com.secure-verify.net belongs to secure-verify.net.

4. It asks for something a real message would not

No legitimate organisation asks you to reply with a password, read out a one-time code, move money to a "safe account" or buy gift cards. A request like that is the scam, whatever else the message says.

5. Something is slightly off

Odd greetings, a logo that looks stretched, a mixture of fonts, a reply address that differs from the sender, or an attachment you were not expecting. None of these proves anything alone; together they are a pattern.

The one habit that beats a perfect message

Sometimes a message has no tells. So do not use the message at all. If your bank, a delivery company or a colleague appears to need something, close the message and go to them directly: type the website address yourself, open the official app, or call the number on your card or their real website. If the request was genuine, it will be waiting there. If it was not, you have lost nothing.

If you already clicked

Change the password for that account straight away, and for any other account where you used the same one. Turn on two-step sign-in if it is not already on. If you entered card details, tell your bank. Reporting the message to your email provider helps the next person.

Sources and scope

This piece is ByteNib editorial analysis written for general readers. It reflects the consistent guidance published by consumer-protection and cybersecurity agencies, including the UK's National Cyber Security Centre and the US Federal Trade Commission, on recognising and reporting phishing. Examples are illustrative rather than drawn from a specific campaign.

Continue exploring: Cybersecurity analysis, the related implementation tutorial, and the structured learning path.