Every red flag on this page, from US and UK government security guidance.
- Urgency
- It gives you minutes or hours to act, so you react before you think.
- Threat
- It warns of something bad, like a locked account or lost pay, if you do not respond at once.
- Emotion
- It tries to make you scared, excited or curious enough to click first.
- Too good
- It offers a prize, a bonus or free money you never asked for.
- Generic greeting
- It opens with Dear user or Dear customer instead of your name, because it went to thousands of people.
- Odd sender
- The address is on a free public mail service, or is a jumble that means nothing.
- Lookalike domain
- The address or link is a near miss of the real domain, with a letter or an ending changed.
- Wrong destination
- The link goes to a site that does not match the company or the thing it claims to open.
- Short link
- A shortened link hides where it goes until you have clicked it.
- Risky attachment
- It carries a dangerous file type, sometimes hidden inside a zip file, that can infect your computer when opened.
- Login request
- It wants your password, or sends you from the email to a sign-in page that passes it to someone else.
- Code request
- It asks for a verification code, and anyone who asks for one is a scammer.
- Approve prompts
- It asks you to approve sign-in prompts you did not start, which is how a stolen password gets past the second check.
- Personal data
- It asks for card numbers, bank details, an ID number or a date of birth by email.
- Bank change
- It says the bank account for a payment has changed and asks you to use the new one.
- Gift cards
- It asks you to buy gift cards and send the codes, a payment no real business asks for.
- Strange request
- It asks for something odd, or out of character for the person it claims to be from.
- Surprise invoice
- It carries an invoice or an overdue bill you do not recognize.
- Account problem
- It says something is wrong with your account and pushes you to act.
- QR code
- It asks you to scan a QR code, which hides the link from some mail filters and moves you to your phone.
- Known name
- It comes from a name you trust, sometimes from a real colleague's account that was taken over.
- Bad spelling
- It has poor spelling and grammar while claiming to come from a careful, official sender.
- Out of the blue
- You were not expecting the email, and you do not recognize the address it came from.