Eight signals that show up again and again in phishing emails and texts — and what to do in the second before you tap.
What's on the page
Veridex is a second opinion, not a gatekeeper. The page below describes the eight categories of rule the checker actually runs against your email and text message — same shapes, same weights, same band cutoffs as the live verifiers. Every example pattern below is an abstracted shape borrowed from the live rulebook; nothing here is invented from a specific real-world incident.
The signal list mirrors the methodology page. If you want the rule-by-rule breakdown of how a score becomes 0–100, read that next; this post is the recogniser's cheat sheet for the inbox.
Before you click
When a message lands and your thumb is already on the link, slow down long enough to ask four questions. If any one of them fails, the link can wait — the verification on a separate channel cannot.
In your mail client, expand the sender and read the part after the @. The display name lies; the domain is the truth.
A genuine bank will not close your account in twenty-four hours via an emailed link. Urgency is the cheapest tool a scam has — it short-circuits the part of your brain that asks "why?".
A code-request is a credential-theft shape: the attacker wants the code your bank just sent you. Banks do not ask for codes back; only scammers do.
If a message claims your account is locked, open a new tab and type the brand URL by hand. The account state you see at the brand is the truth; the link in the message is a door someone else controls.
The eight signals
A single phishing email rarely trips more than two or three of these categories — that is the rule of thumb we use to set the band cutoffs on the score. If you can spot three of these without help, you don't need the checker; if you can't, running the checker before you click is a habit worth carrying across the inbox.
The email's sender domain is impersonating a widely-trusted brand. The display name reads like a brand you know, but the actual sender host belongs to someone else — usually a freshly-registered look-alike.
The Reply-To address lives on a different domain than the From:. Replying routes your message to an attacker-controlled inbox that need not belong to the brand that sent it.
Less common top-level domains (.top, .xyz, .click …) are cheaper to register in bulk and over-represented in scam infrastructure. A known-bad TLD combined with another signal is dispositive.
"Act now or your account will be closed." Banks do not threaten; they notify. The lexicon shared by BEC, sextortion, and package-redelivery scams reads like a script — short, urgent, and unreasonable.
Attorney invoices, vendor payment changes, and rental deposits increasingly ask for wire transfer or crypto wallet addresses instead of the established card-on-file. The wording is the signal — the recipient is the trap.
Hosting a brand token as a subdomain on an unrelated registry is the canonical phishing shape. A brand-name subdomain on a domain the brand does not own is not the brand.
A shortened link hides the destination, so the URL pipeline cannot fingerprint it before you click. The checker recognises the host and never resolves the redirect — that keeps the checker from being weaponised into a phishing payload.
Punycode (xn--) hosts, mixed-script tokens, and digit-substituted brand names (paypa1, g00gle) are designed to slip past human eyes. The IDN is decoded and the brand list compared.
Honest about what spotting a signal does — and does not — let you do.
Run it against a real message
Pick the verifier that matches the message you're staring at. The same eight signal categories above drive every pipeline.