Skip to main content
Phishing is the most widespread form of cybercrime in the world, and it’s responsible for the majority of data breaches, account takeovers, and malware infections that happen to everyday users. The reason it’s so effective is simple: it targets people rather than software. No matter how sophisticated your security tools are, a convincing enough message can still trick a real person into handing over their password, clicking a dangerous link, or opening a malicious file. Learning to recognize a phishing attempt is one of the most valuable digital skills you can develop — and it’s not as difficult as cybercriminals would like you to think.

What Phishing Actually Is

Phishing is a form of social engineering in which an attacker impersonates a trusted entity — your bank, a streaming service, a government agency, a shipping company, or even a colleague — to manipulate you into taking a harmful action. That action might be entering your login credentials on a fake website, downloading an infected attachment, approving a fraudulent payment, or providing sensitive personal information. The name comes from “fishing”: attackers cast a wide net of messages, knowing that even a small percentage of recipients will take the bait.

The Three Main Types of Phishing

Email Phishing

The classic form. You receive an email that mimics a legitimate organization, complete with logos, formatting, and official-sounding language. The message typically directs you to a fake login page or prompts you to open an attachment.

Smishing (SMS)

Delivered by text message, smishing attacks often impersonate delivery companies, banks, or government agencies. They create urgency — “Your package could not be delivered” or “Your account has been suspended” — and include a link to a malicious site.

Vishing (Voice)

Voice phishing involves a phone call from someone claiming to be tech support, the IRS, your bank’s fraud department, or a similar authority. They may already know some of your personal information, making the call feel disturbingly legitimate.

How to Spot a Phishing Attempt

1

Check the Sender's Real Address

The display name in an email can say anything — “PayPal Security Team” or “Apple Support” — but the actual sending address tells the real story. Click or hover on the sender name to reveal the full email address. Legitimate companies always send from their own domain (e.g., support@paypal.com). Watch for lookalike domains like paypa1.com, apple-support.net, or extra subdomains like paypal.account-alert.com.
2

Hover Over Links Before Clicking

Never click a link in a suspicious message without first checking where it actually leads. On a desktop, hover your cursor over the link and look at the URL preview in the bottom corner of your browser or email client. On mobile, press and hold the link to see the destination. If the URL doesn’t match the supposed sender’s official domain, do not click.
3

Look for Urgency and Fear Tactics

Phishing messages are engineered to override your critical thinking by creating panic. Phrases like “Your account will be closed in 24 hours,” “Unusual activity detected — verify now,” or “Final notice before legal action” are designed to make you act before you think. Legitimate organizations rarely demand immediate action through unsolicited messages. When you feel pressured, slow down.
4

Examine Branding and Language Carefully

Sophisticated phishing emails look nearly identical to legitimate ones, but inconsistencies often slip through. Look for mismatched fonts, low-resolution logos, awkward sentence structure, generic greetings like “Dear Customer” instead of your actual name, and unusual formatting. Even a single typo in an official-looking email is a red flag.
5

Verify Independently Before Acting

If a message asks you to take any action involving your account, payment information, or personal data, verify it through a channel you control — not through the message itself. Open a new browser tab and navigate directly to the organization’s official website. Call the company using a phone number from their official site, not one provided in the message. This single habit prevents the vast majority of successful phishing attacks.
Webroot’s real-time web filtering automatically blocks known phishing URLs before the page even loads in your browser. This provides a critical safety net for the moments when a convincing message slips past your guard, preventing your credentials from reaching attackers even if you do click a malicious link.
It happens to careful people too. If you think you’ve fallen for a phishing attempt, act quickly — the faster you respond, the better your chances of limiting the damage.
Do not wait to see if anything bad happens. Credential theft and malware installation can occur in seconds, long before any visible signs of compromise appear on your device.

Staying Ahead of Phishing

Phishing tactics evolve constantly. Attackers now use AI to generate flawless, personalized messages, making old advice like “look for poor spelling” less reliable than it once was. Your best defense is a combination of healthy skepticism, good habits, and tools built to catch what human instinct misses. Webroot’s layered protection — including real-time URL filtering, malicious download blocking, and identity theft protection features — works alongside your own judgment to keep phishing attempts from reaching their goal.
Share what you know about phishing with family members, especially those who are less experienced with technology. Older relatives and children are disproportionately targeted by phishing scams, and a brief conversation about red flags can make a significant difference in keeping your whole household safe.