Guides

How to Spot a Phishing Email in 2026: The Tells That Survived AI

AI fixed the typos, so the old phishing tells are dead. The ones that still work in 2026, with real cases and a 10-question test to check yourself.

How to Spot a Phishing Email in 2026 (Take the Test)

For about twenty years, the standard advice on spotting a phishing email went like this: look for spelling mistakes, clumsy grammar and “Dear Valued Customer”. It was decent advice while it lasted. It has stopped lasting. Even CISA, the US cyber agency, now says so on its own phishing page: poor grammar “used to be” a common sign, but “in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling.”

October is Cybersecurity Awareness Month. CISA is running it this year under the banner “Securing the Next 250”, and the National Cybersecurity Alliance’s 2026 theme is “Don’t Make It Easy for Them”. Both list recognising and reporting scams as one of four basic habits. So here’s an updated version of that habit: the tells that still work now that a chatbot can write a flawless email in any language, followed by a ten-question test with some genuine emails mixed in to keep you honest.

Why the old tells stopped working

Clean prose is now free. The UK’s National Cyber Security Centre saw this coming in January 2024, assessing that generative AI “will make it difficult for everyone, regardless of their level of cyber security understanding, to assess whether an email or password reset request is genuine”.

The research since has borne that out. In a late-2024 study with 101 volunteers, Fred Heiding, Bruce Schneier and colleagues had AI models dig up public information on each target and write a personalised phishing email. 54% of recipients clicked, exactly matching emails written by human experts, against 12% for a generic phish. A year earlier, the same group had found GPT-4’s efforts clearly trailing human-crafted ones. The caveats are real (a small, university-based sample, and a preprint rather than a journal paper), but the direction isn’t in doubt.

Keep AI in proportion, though. The FBI’s 2025 Internet Crime Report logged $3.05 billion in business email compromise losses, of which businesses tied just over $30 million to AI. The rest was ordinary fraud that never needed a language model. Phishing rarely works because it’s well written. It works because it asks for something plausible at a busy moment.

So stop grading the prose and check the structure: who the email is really from, where its links and replies really go, and what it wants you to do.

The tells that still work

The address behind the name

The display name on an email is free text. Anyone can call themselves “Microsoft 365” or use your chief executive’s name, and many phone apps show only that name until you tap it. Whenever a message asks you to do something, tap or hover on the sender and read the actual address.

Lookalike domains

Once the address is visible, the attacker’s job is to make it pass a glance: rnicrosoft for microsoft (an r and an n make a passable m), a zero for an o, an extra hyphen. CISA’s own example is amazan.com. Subdomains are the trickiest. In microsoft.com.account-verify.example, the domain that actually owns the address is account-verify.example, so read from the right, not the left.

Cousin domains exist for a reason. When a company enforces DMARC, mail providers reject or quarantine messages forging its exact address. A lookalike has no such problem, because it belongs to the attacker and can pass every authentication check.

Replies that go somewhere else

An email can show one address in the From line while sending your reply to another, via a Reply-To header most apps never display. The From line matches your supplier or your boss, and your answer quietly lands in a webmail account. Before you send anything that matters, look at the To field of your reply.

Link text is decoration: the words “www.yourbank.com” can point anywhere. Hover over a link on a computer, or long-press it on a phone, and read the real destination. Legitimate marketing email is full of ugly tracking redirects too, so this check throws false alarms. The sturdier habit is to never use an email link to log in or to pay. Type the address or open the app.

Pressure to skip the normal process

The NCSC’s current checklist doesn’t mention grammar at all. It lists authority, urgency, emotion, scarcity and current events. AI can polish the wording, but the email still has to get you to act now, outside whatever process would normally catch it. “Keep this between us.” “Email only, I’m in meetings.” That pressure is the point of the message, so it survives any rewrite.

Bank details that have “changed”

Business email compromise (BEC) is where the big money is: 24,768 complaints to the FBI in 2025, with losses second only to investment fraud. The classic move is a supplier, or a hijacked supplier mailbox, announcing new bank details, often as a reply in a genuine thread. The opener is usually mundane. Microsoft says generic lines like “Are you at your desk?” made up 87 to 92% of the first-contact BEC emails it saw each month in Q2 2026. The only reliable defence is procedural: confirm any change to payment details by phone, on a number you had before the email arrived.

QR codes

A QR code in an email is a link your mail filter struggles to read, which you then open on a phone outside your company’s security tools. In January 2026 the FBI warned that North Korean state hackers were doing exactly this to think tanks and academics, and that “quishing” often ends in stolen session tokens that get around multi-factor authentication. Microsoft counted 18.7 million QR-code phishing attacks in March 2026 alone. Scanning a code is normal on a settings page you opened yourself. It isn’t normal when the code arrives by email.

Callback phishing skips links entirely. The email is a receipt for a subscription you never bought, with a number to ring to cancel, and nothing for a filter to scan. The FBI’s May 2025 notice on the Silent Ransom Group describes the playbook: small fake charges, a call to cancel, a link that installs remote-access software, then data theft and extortion. Check your card statement, not the number in the email.

Login pages that pass your MFA along

Adversary-in-the-middle kits sit between you and the real site, relaying your password and MFA code and keeping the session cookie that comes back. Your MFA works and the attacker still gets in. The biggest, Tycoon2FA, was behind “tens of millions of phishing messages reaching over 500,000 organizations each month”, according to Microsoft, until Microsoft and Europol took down 330 of its domains in March.

The page will look perfect, so check the address bar and listen to your password manager: it matches saved logins to the real domain, so if it doesn’t offer to fill in your password, stop. Passkeys go further. They’re built on FIDO/WebAuthn, which CISA calls the only widely available phishing-resistant authentication, because a passkey only works on the domain it was made for.

And if your phone asks you to approve a sign-in you didn’t start, someone already has your password and is hoping you’ll tap Approve to make the prompts stop. That’s how Uber was breached in 2022: a contractor kept receiving approval requests and, in Uber’s words, “eventually, however, the contractor accepted one.” Deny it and change your password.

“This app would like to read your mail”

Consent phishing never needs your password. It sends you to a real Microsoft or Google sign-in page, then asks you to grant a third-party app access to your account, and because the consent screen is genuine, people accept. Microsoft notes that resetting passwords or requiring MFA doesn’t fix an illicit consent grant; the app has to be revoked. A close cousin is device code phishing, where a fake meeting invite asks you to enter a code on a real Microsoft page, as a group Microsoft links to Russian interests did against governments and NGOs.

If an email link ends at a permissions screen or an “enter this code” page you didn’t expect, close the tab rather than pressing anything. In one 2025 campaign tracked by Proofpoint, fake apps posing as Adobe and DocuSign sent people to a phishing page whether they clicked Accept or Cancel. (For the record, Microsoft’s own consent phishing guidance still tells you to check for poor spelling and grammar.)

Delivery and invoice notices you weren’t expecting

Fake parcel alerts were the most reported text scam of 2024, according to the FTC, with many victims paying a small “redelivery fee” that was really a card-harvesting trick. The same message turns up by email, alongside fake invoices. Check the order on the retailer’s site or the carrier’s own tracking page, never through the notice.

Voices and faces that “confirm” it

The follow-up call used to be the safety check. Now it can be part of the attack: in early 2024 an Arup employee in Hong Kong sent HK$200 million (about US$25 million) to criminals after a message purportedly from the CFO led to a video call in which the CFO and colleagues were deepfakes. The FBI has warned of AI-generated voice messages impersonating senior US officials, and Microsoft says weekly malicious call attempts over Teams were running at nearly ten times their mid-2025 level by June 2026.

A call the attacker arranged proves nothing. Verification only counts on a channel you chose: a number from your own records, or a colleague you can walk over to.

The phishing test: ten emails, some genuine

Ten messages, written the way they arrive in 2026: fluent and well formatted. Some are genuine. Decide on each before you open the answer.

The domains are placeholders. Your employer is yourco.example. For any outside company, example.com plays its genuine domain. Anything else belongs to someone else.

1. Your password expires today

From:    Microsoft 365 <security@m365-accounts.example.net>
To:      you@yourco.example
Subject: Action required: your password expires today

Your password expires at 17:00 today.

To keep your current password, verify your
account below. Unverified accounts will be
locked and mailbox data may be removed.

          [ Keep current password ]
Answer

Phishing. Flawless English, and still wrong three ways. The sender is on example.net, not Microsoft’s domain. It threatens data loss on a same-day deadline. And “keep current password” can only mean typing your password into whatever page the button opens. If your password genuinely needs changing, you can do it from your account settings without touching this email.

2. A new sign-in on Mac

You set up a new MacBook an hour ago and signed in to your Google account.

From:    Google <no-reply@accounts.example.com>
Subject: Security alert

A new sign-in on Mac

We noticed a new sign-in to your Google Account
on a Mac device. If this was you, you don't need
to do anything. If not, we'll help you secure
your account.

             [ Check activity ]
Answer

Legitimate. It comes from the genuine domain, asks for nothing, says you don’t need to act if it was you, and matches something you just did. Attackers copy these alerts closely, though, so the safe habit still applies: if you want to check, open your account’s security page yourself rather than pressing the button. Same destination, no risk.

3. The quick favour

Jane is your CEO.

From:    Jane Okafor <jane.okafor@yourco.example>
Subject: Quick one

Are you at your desk? Need a favour handled
discreetly today. I'm in back-to-back meetings
so email only please.

Jane
Sent from my iPhone

You press Reply. The To field fills in as jane.okafor.office@webmail.example.org.

Answer

Phishing. The classic business email compromise opener, with no link or attachment for a filter to catch. The tells are structural: replies go to an outside webmail address, and “email only” cuts off the one channel that would expose it. The next message asks for gift cards or an urgent payment. Message Jane on your usual chat instead.

4. Your parcel is on hold

You’re expecting a delivery this week.

From:    Parcel Delivery <notify@parcel-tracking.example.net>
Subject: Your parcel is on hold: £1.45 unpaid

We tried to deliver your parcel today, but
there is a £1.45 shortfall in postage. Pay within
48 hours or it will be returned to the sender.

Pay now: https://www.example.com/redeliver

Hovering over the link shows https://redeliver.example.net/pay?ref=88213.

Answer

Phishing. The link text shows the carrier’s real address, but it goes to a different domain, which on its own is disqualifying. The tiny fee is the hook: it gets your card details onto a page the scammer controls. If you’re expecting one, check it from the retailer’s order page or the carrier’s own site, using the tracking number in your order confirmation.

5. Passkeys are coming

From:    IT Service Desk <servicedesk@yourco.example>
Subject: Passkeys are coming next week

From Monday 19 October you'll be asked to set up
a passkey the next time you sign in to your work
account. It replaces the push-approval prompt.

There's nothing to do now and nothing to click.
The prompt will appear on the normal sign-in
page. Questions: #it-help on chat, or ext. 4400.
Answer

Legitimate. Internal sender, no link, no attachment, no deadline to miss, and it tells you exactly where the real action will happen: the normal sign-in page. It even offers two contact routes you already know. Hold other “IT” emails up against it: a fake version would need you to click something early.

6. New bank details

Acme Supplies is a real supplier you pay every month. This arrives as a reply in your existing email thread with them, from their usual address.

From:    Sam Hughes <sam.hughes@example.com>
Subject: RE: Invoice INV-4471

Hi, thanks for confirming the September order.
Quick note before Friday's payment run: we've
moved banks following an audit, so please use
the details on the attached letter for INV-4471
and all future payments.

Thanks,
Sam

Twenty minutes later “Sam” rings, from the number in his email signature, to check you got it.

Answer

Fraud, even though everything checks out. Right address, right thread, right invoice number: that’s what a compromised mailbox looks like, because attackers read the thread before they write. The phone call proves nothing, since the number came from the email. Before changing any payee details, call Acme on a number from your own records, such as an old invoice or the contract. This is business email compromise at its most convincing.

7. MFA re-enrolment

From:    IT Security <it-security@yourco-helpdesk.example.net>
Subject: MFA re-enrolment required (ref 5521-A)
Attachment: MFA_Reenrolment.pdf

Our authenticator records are being migrated.
Scan the QR code in the attached PDF with your
phone camera to re-register your device before
Friday. Unregistered devices will lose access.
Answer

Phishing. The QR code moves the attack onto your phone, beyond your company’s email filtering, which is exactly why attackers use it. The sender is a lookalike domain, not yourco.example, and the deadline threatens lost access. Setting up an authenticator does involve scanning a QR code, but one shown on a security settings page you opened yourself, not one that arrives in a PDF.

8. The paused card payment

From:    Example Bank <alerts@example.com>
Subject: Did you make this payment?

We've paused a card payment of £842.19 to
ELECTRO-WORLD ONLINE on 8 Oct at 21:14.

If this was you, approve it in the Example Bank
app. If it wasn't, call the number on the back
of your card. We will never ask for your PIN or
passcode, or ask you to move money.
Answer

Legitimate, and safe to act on even if it weren’t. It comes from the bank’s real domain, but the bigger point is where it sends you: the banking app you already have, or the number printed on your own card. Neither is controlled by whoever sent the email. Compare it with the next one, which has the same urgency but supplies its own phone number.

9. Thanks for renewing

From:    ShieldPro Billing <shieldpro.billing@webmail.example.org>
Subject: Order confirmation #SP-20931

Thank you for renewing ShieldPro Total Security
(3 devices, 1 year).

Amount charged:  $89.99
Payment method:  card on file

If you did not authorise this renewal, call our
billing team within 24 hours for a full refund:
+1 (555) 010-4471
Answer

Phishing (callback). A receipt for something you didn’t buy, from a webmail address, with a phone number to “cancel”. There’s nothing to click, which is the point: email filters have little to judge. On the call, you’ll be talked into installing remote-access software or handing over card details for a “refund”. If you’re worried a charge is real, check your card statement or banking app.

10. A shared spreadsheet

Maria is a colleague. Your company uses Microsoft 365.

From:    Maria Chen <maria.chen@yourco.example>
Subject: Q4 budget v3.xlsx

Hi, can you check the numbers on tab 2 before
Thursday's meeting? Thanks!

          [ Open Q4 budget v3.xlsx ]

You click. The sign-in page is genuine (the address bar shows login.example.com), and your password and MFA go through. Then this appears:

DocuView Pro
unverified

This app would like to:
  - Read your mail
  - Send mail as you
  - Read and write all files you can access
  - Maintain access to data you have given it

         [ Cancel ]      [ Accept ]
Answer

Phishing (consent). The sender, the sign-in page and your MFA were all real, which is what makes this nasty. The attack is the app: a document viewer has no business reading and sending your mail, and “unverified” is the platform warning you. Press neither button; close the tab. If you already accepted, revoke the app (Google’s linked apps page, or My Apps for Microsoft work accounts) and tell IT, because changing your password won’t remove it. Maria’s account is probably compromised too, so warn her through another channel.

Score: seven phishing, three genuine. If a genuine one made you suspicious, that’s the right way to be wrong. And if you run a team, this makes a decent ten-minute session for Cybersecurity Awareness Month.

If you already clicked

Speed beats embarrassment. IT teams would much rather hear about a click now than discover it next month.

  1. If you typed a password, change it now, by typing the site’s address yourself, and change it anywhere else you reused it.
  2. End every other session, because stolen session cookies are how MFA-bypass kits get in. In a Google account it’s Security & sign-in, then Your devices. Microsoft personal accounts have Sign out everywhere, which can take up to 24 hours. For work accounts, ask IT to revoke your sessions.
  3. Check what’s been added. Remove connected apps you don’t recognise, and look for forwarding addresses, filters or MFA methods you didn’t set up. Rules that forward mail to unknown addresses are among Microsoft’s listed symptoms of a compromised mailbox.
  4. If you gave card or bank details, call your bank on the number printed on your card.
  5. If you opened an attachment or installed anything, disconnect from the network, run a malware scan and tell IT. Uninstall any remote-access tool someone talked you into.
  6. Report it, even if you didn’t click. In the UK, the NCSC asks you to forward the email to report@phishing.gov.uk, and any losses go to Report Fraud on 0300 123 2040. It replaced Action Fraud in December 2025; in Scotland, call Police Scotland on 101. In the US, the FTC says to forward phishing to reportphishing@apwg.org and report it at ReportFraud.ftc.gov; business email compromise also goes to the FBI at ic3.gov. Scam texts go to 7726 in both countries.

Where your email client fits

A mail client helps at the margins. Opening a phish with remote images switched on can confirm to the sender that your address is live, one more reason to block tracking pixels. Clicking “unsubscribe” in obvious spam does the same, so report strangers instead.

Kanmail blocks remote images by default and, when you open a message, shows the sender’s full address beside the display name, so the first tell on this list is always on screen. It doesn’t scan links or flag lookalike domains; that’s down to your provider’s filtering and your own eye. The security overview covers how it handles your credentials and data. And if you triage on a kanban board, a “Verify” column for anything asking for money, credentials or access is a cheap habit: the email waits there until you’ve checked it on a channel you chose.

The bottom line

Stop proofreading phishing emails. The spelling will be perfect. Check who the email is really from, where its links and replies really go, and what it wants from you. Anything that asks for money, a password, a code, a scan, a call or a permission earns one extra check on a channel you chose. It costs a minute, and no amount of AI polish gets around it.

Frequently asked questions

What are the signs of a phishing email?

In 2026 the reliable signs are structural, not stylistic. Check the actual sender address rather than the display name, where your reply will really go, and where each link really points. Then look at what the email wants: urgency or secrecy, changed bank details, a QR code to scan, a phone number to call, or a screen asking for access to your mailbox. Spelling mistakes are no longer a useful signal, because AI writes clean prose for free.

Are AI-written phishing emails more effective?

The best evidence says yes, when they are personalised. In a 2024 study by Fred Heiding, Bruce Schneier and colleagues, AI-written emails tailored from public information about each target got a 54% click rate, the same as emails written by human experts and far above the 12% for a generic phish. The sample was small and university-based, but fluent, personal phishing is clearly now cheap to produce.

What should I do if I clicked a phishing link?

If you only clicked and typed nothing, close the page and run a malware scan. If you entered a password, change it straight away from a trusted device, sign out of all other sessions, and check for forwarding rules and connected apps you don't recognise. On a work account, tell IT immediately. If you shared card or bank details, call your bank on the number printed on your card.

How do I report a phishing email?

Use your mail provider's "Report phishing" option first. In the UK, also forward the email to report@phishing.gov.uk, the NCSC's reporting service, and report any money lost to Report Fraud, which replaced Action Fraud in December 2025. In the US, forward it to reportphishing@apwg.org and report it to the FTC at ReportFraud.ftc.gov. Scam texts can be forwarded to 7726 in both countries.

Is it safe to open a phishing email?

Usually, yes. Opening a message in an up-to-date mail client rarely does harm by itself; the risk is in clicking links, opening attachments, scanning QR codes, calling numbers or replying. The one thing opening can leak is that you exist: if remote images load, a tracking pixel tells the sender your address is live and that you read it. Blocking remote images by default closes that gap.

Nick Mills-Barrett

Builds Kanmail at Oxygem — the email client that turns your inbox into a kanban board. Writes here occasionally about email, focus, and independent software.

See your inbox as a board.

Try Kanmail free for as long as you need — no card, no subscription. Pay once when it clicks.

Download Kanmail free →