AI has taken away the easiest tell of phishing: bad grammar. Fluent, polite, well-formatted scam emails are now cheap to produce. But five signals still work in 2026. Learn them once and use them every time.
What changed
Older phishing was often easy to spot:
– Bad grammar (“Your account has been compromise”)
– Odd formatting (random capitals, mixed fonts)
– Obvious typos in the domain (paypa1.com)
Today, generative AI tools can write a convincing email in any language in seconds. Grammar is no longer a reliable signal.
Five signals that still work
1. Check the sender’s domain (zoom in)
Real: support@netflix.com
Fake: support@netf1ix.com (a 1 instead of an l)
Fake: support@netflix.support-team.com (the real domain here is support-team.com)
Un passo avanti. Sempre.
Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.
Entra nel Canale
Action: do not trust the display name. On a phone, tap or hold the sender to see the full address. When in doubt, go to the site yourself.
2. Check where the link really goes
Phishing emails contain links that look right (“Click here to update your account”) but lead somewhere else.
Action:
– On a computer: hover over the link and read the address that appears at the bottom of the window
– On a phone: press and hold the link to see the real address
– If you are unsure: do not click, and go to the official site yourself
3. Urgency and fear
Be suspicious when a message:
– Threatens that “your account will be deleted in 24 hours”
– Demands that you “verify within 1 hour or lose access”
– Keeps shouting “URGENT” or “IMMEDIATE ACTION REQUIRED”
Real organizations usually give you reasonable time, and they do not rely on a threatening email alone.
4. A request that makes no sense
Things legitimate organizations do not ask for by email:
– Your password (no real IT department asks for it)
– Your full card number or bank login
– Your 2FA codes (those codes are for you to type, never to share)
– Payment with gift cards or cryptocurrency: the US Federal Trade Commission says that only scammers tell you to pay that way
If the email asks for one of these, treat it as phishing.
5. A pretext that does not fit the sender
If your bank writes about a parcel delivery, it is almost certainly phishing.
If a courier writes about your bank account, it is almost certainly phishing.
If an email claims to come from the IRS, be very suspicious: the IRS says it does not start contact with taxpayers by email, text or social media to ask for personal or financial information. Most of its first contacts arrive by post.
Ask yourself: is this the way this sender would normally contact me, about this subject?
Three realistic examples
These are examples we wrote to show the signals; they are not real emails.
Example 1: a fake bank alert
From: security@chase.bank-verification.com
Subject: Action required: Suspicious activity on your account
Dear customer,
We detected unauthorized login attempts on your Chase account from
IP 192.168.x.x located in [your city]. To prevent account suspension,
please verify your identity within 24 hours.
[Verify identity now]
Thank you for choosing Chase.
Signals:
– Domain: chase.bank-verification.com, not chase.com
– Urgency: “24 hours”
– Request: “verify” through an outside link
– Perfect grammar, which proves nothing
Example 2: the fake boss (business email compromise)
From: ceo@your-company-name.com
Subject: Quick task
Hey, need your help.
I'm in a meeting and can't take calls. Can you wire $5,000 USD to
[vendor name] for an urgent invoice? I'll explain when out.
Don't loop in finance, I'll handle that.
Sent from my iPhone
Signals:
– An urgent money request by email, with the phone ruled out
– Pressure to skip the normal procedure (“don’t loop in finance”)
– A vague reason (“vendor invoice”)
– “I’m in a meeting”: a reason not to check
Example 3: fake tech support
From: noreply@apple-id.support
Subject: Your Apple ID has been disabled
We have temporarily disabled your Apple ID due to security concerns.
To reactivate within 24 hours, sign in:
[Restore Apple ID]
Apple Support
Signals:
– Domain: apple-id.support, not apple.com
– Urgency: “24 hours”
– A link to an outside site
What to do if you clicked
Don’t panic. In most cases the damage comes from typing your credentials, not from the click itself.
- Don’t enter any credentials once you realize what happened
- If you entered them: change the password right away on the real site, and turn on 2FA
- Check Have I Been Pwned to see whether your email appears in known breaches
- Run a malware scan with a reputable tool (Windows Security is built into Windows)
- Report it: to your email provider, and to your IT team if it was a work account
- Watch your accounts: check bank statements and, in the US, your credit reports over the following weeks
Defenses that work even if you click
- A password manager: it will not autofill your password on a fake domain, which is itself a warning
- A hardware security key for 2FA (for example a YubiKey): designed to resist phishing
- Bookmarks: open important sites from your bookmarks, never from email links
- Your email provider’s filters: Gmail, Outlook and Proton Mail all filter phishing; keep them on
Bottom line
Phishing in 2026 looks legitimate. Don’t trust grammar or formatting. Use the five signals, a password manager and 2FA. When in doubt, go to the site yourself and never log in from an email link.
Sources
- US Federal Trade Commission, “Only scammers tell you to buy a gift card to pay them”, October 2024: https://consumer.ftc.gov/consumer-alerts/2024/10/only-scammers-tell-you-buy-gift-card-pay-them ; and “What To Know About Cryptocurrency and Scams”: https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-scams
- IRS, “Security Summit warns of new IRS impersonation email scam; reminds taxpayers the IRS does not send unsolicited emails”: https://www.irs.gov/newsroom/security-summit-warns-of-new-irs-impersonation-email-scam-reminds-taxpayers-the-irs-does-not-send-unsolicited-emails
- Anti-Phishing Working Group, how to report phishing: https://education.apwg.org/report-phishing/overview/
- UK National Cyber Security Centre, report suspicious emails: https://www.ncsc.gov.uk/report-suspicious-emails
Frequently asked questions
What if I clicked a phishing link?
Don't panic. (1) Don't enter any credentials. (2) If you did, change the password right away on the real site and turn on 2FA. (3) Check your email address on Have I Been Pwned. (4) If you gave financial details, call your bank and consider freezing your credit. (5) Run a malware scan. In most cases the damage comes from typing your credentials, not from the click alone.
Un passo avanti. Sempre.
Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.
Entra nel Canale
Is reporting phishing useful?
Yes: reports help providers block the senders and take down the fake sites. Use the 'report phishing' button of your email service. In the US you can also forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org, and emails pretending to be the IRS to phishing@irs.gov. In the UK, forward it to report@phishing.gov.uk. For a work email, tell your IT helpdesk.
AI-generated phishing: how do you spot it?
It is the hardest kind to spot, because the grammar is perfect. Focus on (1) the sender's domain, (2) where the link really goes, (3) pressure to act now, and (4) what is being asked: a real IT department never asks for your password by email.




Leave a Reply