Blog

How to Spot a Phishing Scam

Eight signals that show up again and again in phishing emails and texts — and what to do in the second before you tap.

What's on the page

A second opinion, not a guarantee.

Veridex is a second opinion, not a gatekeeper. The page below describes the eight categories of rule the checker actually runs against your email and text message — same shapes, same weights, same band cutoffs as the live verifiers. Every example pattern below is an abstracted shape borrowed from the live rulebook; nothing here is invented from a specific real-world incident.

The signal list mirrors the methodology page. If you want the rule-by-rule breakdown of how a score becomes 0–100, read that next; this post is the recogniser's cheat sheet for the inbox.

Before you click

Four checks that take ten seconds.

When a message lands and your thumb is already on the link, slow down long enough to ask four questions. If any one of them fails, the link can wait — the verification on a separate channel cannot.

Read the actual domain, not the display name.

In your mail client, expand the sender and read the part after the @. The display name lies; the domain is the truth.

If it threatens a deadline, slow down.

A genuine bank will not close your account in twenty-four hours via an emailed link. Urgency is the cheapest tool a scam has — it short-circuits the part of your brain that asks "why?".

Never paste a verification code into the message that asked for it.

A code-request is a credential-theft shape: the attacker wants the code your bank just sent you. Banks do not ask for codes back; only scammers do.

Reach the brand by typing its URL yourself.

If a message claims your account is locked, open a new tab and type the brand URL by hand. The account state you see at the brand is the truth; the link in the message is a door someone else controls.

The eight signals

What the checker actually looks for.

A single phishing email rarely trips more than two or three of these categories — that is the rule of thumb we use to set the band cutoffs on the score. If you can spot three of these without help, you don't need the checker; if you can't, running the checker before you click is a habit worth carrying across the inbox.

Sender domain mismatch

Pattern

The email's sender domain is impersonating a widely-trusted brand. The display name reads like a brand you know, but the actual sender host belongs to someone else — usually a freshly-registered look-alike.

  • Sender host takes a known brand token and parks it as a look-alike
  • Display name says one brand, but the actual domain isn't theirs

Reply-to divergence

Pattern

The Reply-To address lives on a different domain than the From:. Replying routes your message to an attacker-controlled inbox that need not belong to the brand that sent it.

  • From: a trusted brand — Reply-To: an unrelated help-desk subdomain
  • Any time the two domains differ, the divergence is recorded

Suspicious TLDs

Pattern

Less common top-level domains (.top, .xyz, .click …) are cheaper to register in bulk and over-represented in scam infrastructure. A known-bad TLD combined with another signal is dispositive.

  • Uncommon sender TLD on an email From: address
  • Uncommon host TLD on a URL the message links to

Urgency and pressure language

Pattern

"Act now or your account will be closed." Banks do not threaten; they notify. The lexicon shared by BEC, sextortion, and package-redelivery scams reads like a script — short, urgent, and unreasonable.

  • Urgency phrasing shared by email and SMS scam scripts
  • Legal-threat or law-enforcement mentions
  • Asks you to reply with a verification code or PIN

Payment redirection to wire or crypto

Pattern

Attorney invoices, vendor payment changes, and rental deposits increasingly ask for wire transfer or crypto wallet addresses instead of the established card-on-file. The wording is the signal — the recipient is the trap.

  • Asks for payment to a new recipient (wire, gift card, crypto wallet)
  • Mentions an attachment or tap-to-view media carrying the redirect

Brand impersonation patterns

Pattern

Hosting a brand token as a subdomain on an unrelated registry is the canonical phishing shape. A brand-name subdomain on a domain the brand does not own is not the brand.

  • Brand name used as a subdomain of an unrelated registry
  • In-message link points at a brand-spoofing host
  • Display name mentions a brand the sender domain is not

URL shorteners

Pattern

A shortened link hides the destination, so the URL pipeline cannot fingerprint it before you click. The checker recognises the host and never resolves the redirect — that keeps the checker from being weaponised into a phishing payload.

  • Known URL shortener used as a host
  • Shortener link embedded in an email or SMS body

Homoglyphs

Pattern

Punycode (xn--) hosts, mixed-script tokens, and digit-substituted brand names (paypa1, g00gle) are designed to slip past human eyes. The IDN is decoded and the brand list compared.

  • Punycode in the host IDN
  • Brand token with a digit replacing a letter (paypa1, g00gle)
  • Numeric label parked next to a brand token in the host

After you spot the signal — then what?

Honest about what spotting a signal does — and does not — let you do.

  • Heuristic, not a verdict. Spotting one signal doesn't prove the message is malicious — it proves the check is worth running. Two or three signals together, on the other hand, are almost dispositive.
  • Don't reply to the message. Replying confirms your address is live. Mark as phishing in your mail client and move on — even if you're curious, the reply is a free signal for the next round.
  • Verify on a separate channel. The fastest fix is the slowest one: open a new tab and reach the brand yourself. The link in the message goes through someone else's door.
  • Paste it into the checker first. If the four-question check leaves any doubt, paste the link or the email headers into the appropriate verifier before you act on it. The click stays yours.

Run it against a real message

The score shifts when the signals fire.

Pick the verifier that matches the message you're staring at. The same eight signal categories above drive every pipeline.