How to Spot Phishing Emails (And What to Do If You Clicked One)

SecurityEmailPhishing · 2026-09-13

Phishing emails are how most computer infections actually start. Not from visiting sketchy websites or downloading pirated software — from clicking a link in an email that looked real. Here’s how to spot them and what to do.

What Phishing Looks Like in 2026

Phishing has gotten much better in the last few years. AI tools let scammers generate perfect-sounding emails with no spelling mistakes. Here are the most common types you’ll see:

Fake “Account Problem” Emails

These claim your account has been compromised, your payment failed, or your account will be closed. They come from “Amazon,” “Netflix,” “Apple,” “Microsoft,” or your bank. The link takes you to a fake login page that captures your credentials.

Fake Delivery Notifications

“Your package couldn’t be delivered” from “UPS,” “FedEx,” or “USPS.” Especially common during holiday shopping seasons. The link either installs malware or asks for personal information.

Business Email Compromise

An email from your “boss” or “coworker” asking you to buy gift cards, wire money, or share login credentials. The email address is spoofed or comes from a compromised account.

5 Ways to Spot a Phishing Email

1. Check the Sender’s Actual Email Address

The display name might say “Amazon.com” but the email address is something like support@amaz0n-alerts.com. Always click on the sender name to reveal the full email address. Legitimate companies use their actual domain.

2. Hover Over Links Before Clicking

On a computer, hover your mouse over any link without clicking. The actual URL appears in the bottom-left of your browser or email client. If the link says “Amazon” but the URL goes to amzn-secure-login.xyz, it’s fake.

On a phone, long-press the link to preview the URL.

3. Look for Urgency and Threats

“Your account will be permanently deleted in 24 hours!” “Act now or lose access!” Legitimate companies don’t threaten you via email. They also don’t ask you to “verify your identity” through an email link.

4. Check for Generic Greetings

“Dear Customer” or “Dear User” instead of your actual name. Companies you have accounts with know your name and use it.

5. Suspicious Attachments

Never open unexpected attachments, especially:

What to Do If You Clicked a Phishing Link

  1. Don’t panic — clicking a link alone usually isn’t enough to compromise your computer
  2. Don’t enter any information — close the page immediately
  3. If you entered a password: Change it immediately on the real site. If you use that password anywhere else, change it there too.
  4. If you entered credit card info: Call your bank immediately and dispute the charge
  5. Run a malware scan: Windows Security → Virus & threat protection → Full scan
  6. Enable 2FA: Turn on two-factor authentication on any account you think was compromised

How to Protect Yourself Going Forward

Marion Remote Fix tip: If you’re not sure whether an email is real, forward it to us during a free remote diagnosis. We’ll check the headers and tell you if it’s legit.

Can’t fix it yourself?

Book a free remote diagnosis. We connect to your screen, find the problem, and fix it for $99 flat — or you don’t pay.

Book a Free Diagnosis

Related Articles

Protect Your Computer from Tech Support Scams

How to spot fake virus warnings, phishing calls, and remote access scams.

Read more →

Best Free Antivirus for Windows in 2026

No-BS guide to which free antivirus actually works and which ones are bloatware.

Read more →

Home Network Security: 8 Steps to Lock Down WiFi

8 free steps that take 15 minutes and make your network much harder to hack.

Read more →