How to Tell If an Email Is Phishing in 2026

Quick answer: The fastest checks in 2026 are the sender’s actual domain (not the display name), where a link really goes when you hover over it, unexpected urgency or pressure to skip a normal process, and any request for a password, card number, or two-factor code. Grammar mistakes are no longer a reliable sign, since AI now writes flawless phishing emails.

Phishing used to be easy to catch. Bad grammar, a misspelled company name, an email that looked like it was formatted in 2003. That version of phishing is mostly gone. Generative AI now writes phishing emails that are grammatically perfect and contextually convincing, so the old checklist needs an update. Here is what actually still works.

Why the Old Advice Stopped Working

For years, the standard advice was to look for typos, broken English, and clumsy formatting. That advice made sense when phishing emails were often written by non-native speakers using basic templates. It does not make sense anymore. Large language models now generate flawless, context-aware messages, and the median time it takes someone to click a phishing link and submit their information is now under 60 seconds, according to recent threat reporting. Writing quality has stopped being a useful filter, so the checks that still work have shifted toward process, context, and technical detail rather than surface polish.

Check the Sender’s Actual Domain, Not the Display Name

The name shown in your inbox can say anything. What matters is the domain after the @ symbol. An email claiming to be from “Amazon Support” that actually comes from a domain like amaz0n-security.com or a free email provider is a clear red flag, regardless of how convincing the message body looks.

Tap or click on the sender’s name to reveal the full email address, and check it against the company’s known domain. A single extra letter, a hyphen, or a different top-level domain (.net instead of .com, for example) is a common trick.

Hover Before You Click

Before clicking any link, hover your mouse over it without clicking, or press and hold on mobile. The real destination URL will appear at the bottom of your browser or in a small preview. If the destination does not match the text shown, or does not match the sender’s official domain, treat it as phishing.

This single habit catches a large share of phishing attempts, because the visible link text is easy to fake, but the actual destination is much harder for an attacker to disguise convincingly.

Ask Whether the Process Makes Sense

This is the check that survives AI-written phishing, because it does not depend on how the email reads. Ask yourself:

  • Would this person or company normally ask for this, through email, in this way? A finance department asking to change bank details through a single email, with no supporting process, should raise suspicion regardless of how well written it is.
  • Did I initiate this? Password reset emails, two-factor prompts, invoice notices, and delivery updates you did not trigger deserve extra scrutiny before you interact with them at all.
  • Is there unusual urgency or pressure to skip a normal step? A polished, professional-looking message can still be an attack if it is pushing you to act faster than your usual approval or verification process allows.

Watch for These 2026-Specific Attack Patterns

No Legitimate Service Asks for Your Password or Full Card Number by Email

Your bank, your email provider, and any legitimate service will never ask you to reply with your password, a full card number, or a two-factor code. Treat any email requesting this directly as phishing, no matter how official it looks.

Unexpected Instructions to Open a Run Dialog or Paste a Command

A newer attack pattern, sometimes called ClickFix, tricks people into pasting a malicious command into the Windows Run dialog or a terminal window, disguised as a way to “fix” a CAPTCHA or verification error. No legitimate verification process will ever ask you to open a command prompt and paste something copied from a webpage. If you see this instruction anywhere, close the tab immediately.

QR Codes in Emails

QR codes embedded in emails, sometimes called quishing, are increasingly used specifically to bypass corporate email filters, since the malicious link only appears once you scan the code on your personal phone. Treat any unexpected QR code in an email with the same suspicion as a suspicious link.

Unexpected Attachments

A .zip, .exe, .docm, or .html file you were not expecting is a major warning sign. Be especially cautious of any attachment that asks you to “enable content” or “enable macros” after opening it, since this is a common way malware executes on your device.

What to Do If You Are Not Sure

Verify through a second channel. If an email claims to be from your bank, your manager, or a supplier requesting money or credentials, contact them directly through a phone number or method you already know is correct, not one provided in the email itself. This single step defeats the vast majority of convincing phishing attempts, because it removes the attacker’s control over the conversation entirely.

If You Already Clicked

Act in this order:

  1. Disconnect the device from the network if you suspect a malicious attachment or script was involved.
  2. Change the password for any account associated with the email immediately.
  3. Enable or check two-factor authentication on the affected account.
  4. Review recent sign-in activity on the account for anything unfamiliar.
  5. Run a security scan on the device if you opened an attachment or followed a link that asked you to run something.

Some phishing pages can attempt to install something on your device simply by visiting, even if you never typed in a password, so a scan is worth doing even if you believe you stopped before entering any information.

Common Questions

How can I tell if an email is phishing if it has no typos?
Check the sender’s actual domain rather than the display name, hover over links to see where they really go, and verify any request involving money or credentials through a second channel, such as a phone call.

Are grammar mistakes still a reliable sign of phishing?
No. AI-generated phishing emails are now typo-free and often indistinguishable from genuine correspondence in tone and structure. Rely on domain checks, link destinations, and process red flags instead.

What should I do if I clicked a phishing link but did not enter any information?
Disconnect the device from the network, run a security scan, and reset the password for the account that received the email as a precaution, since some malicious pages can attempt to install something on a device simply by visiting.

Is a QR code in an email always phishing?
Not always, but an unexpected QR code in an email is increasingly used specifically to bypass email security filters, so it deserves the same caution as a suspicious link.

What is the single most reliable check?
Verifying any request involving money, credentials, or an urgent action through a second, independently known channel, rather than trusting anything provided within the email itself.

The Bottom Line

Phishing emails no longer give themselves away through bad writing. The checks that still work in 2026 are about process and verification rather than polish: check the real sender domain, hover before you click, question anything urgent or unusual, and verify significant requests through a channel you already trust. Build those habits, and a convincing phishing email becomes a near miss instead of a genuine problem.