TontonTools
Security & Privacy

Phishing Explained: How to Spot and Avoid Scam Emails

Enyong Carinton Tegum· January 29, 2026· 2 min read
Suspicious email in an inbox representing phishing
Photo by Tara Winstead on Pexels

The most common cyberattack in the world doesn't hack computers — it hacks people. Phishing tricks you into handing over passwords, card details, or money by pretending to be someone you trust. It's behind a huge share of breaches, and the only real defence is knowing how to spot it. Here's your field guide.

What phishing is

Phishing is a fraudulent message — usually email, but also text ("smishing") or phone ("vishing") — designed to look legitimate so you'll click a malicious link, open an attachment, or reveal sensitive information. The attacker impersonates a bank, a delivery company, a colleague, or a service you use.

The red flags

  • Urgency and fear: "Your account will be closed in 24 hours!" Pressure stops you thinking.
  • Generic greetings: "Dear Customer" instead of your name.
  • Mismatched links: hover over a link and the real destination differs from the text.
  • Slightly-wrong sender addresses: [email protected] instead of paypal.com.
  • Unexpected attachments or requests for passwords, codes, or payment.
  • Spelling and grammar mistakes a real company wouldn't make.

The golden rule: check the link before you click

Hover over any link to see where it really goes (on mobile, long-press). Legitimate companies use their own domain. If a "bank" email links to a random or look-alike domain, it's fake. You can investigate a suspicious domain's registration with our WHOIS lookup and check its age with the domain age checker — scam domains are often days old.

When in doubt, go direct

Never use the link or phone number in a suspicious message. Instead, open a new browser tab and type the company's address yourself, or call the number on your card or their official site. This single habit defeats almost every phishing attempt.

What to do if you've been caught

If you entered a password, change it immediately (and anywhere you reused it — another reason not to). Enable two-factor authentication, which can save you even if a password leaks. Report the message to your email provider and the impersonated company. Organisations like the FTC also take reports.

Bottom line

Phishing preys on trust and urgency, not technical weakness. Slow down, check sender addresses and link destinations, never act on the message's own links, and go direct to the source when unsure. Combine that scepticism with 2FA and unique passwords, and you neutralise the most common attack on the internet.

Share X / Twitter Facebook LinkedIn WhatsApp

Keep reading

← Back to all posts

We use cookies for analytics and to keep the tools free via ads. See our Privacy Policy.