Home
Blog
Phishing Email Examples (Spot a Fake in 30 Seconds)

Phishing Email Examples (Spot a Fake in 30 Seconds)

Reviewed by
Table of Contents

Key Takeaways

Phishing is the #1 reported cybercrime in the United States, and it's not even close. According to the FBI's 2024 Internet Crime Report, phishing and spoofing topped the list of complaints received by the Internet Crime Complaint Center (IC3), with Americans losing $16.6 billion to internet scams in 2024 alone. Phishing accounts for 16% of all data breaches, with an average breach cost of $4.8 million per incident.

The scary part? Most phishing emails are meant to fool you in the first three seconds, before you even have time to think.

The good news? Once you know what to look for, you can spot them in 30 seconds or less. This guide breaks down the most common phishing email examples, the red flags hiding in plain sight, and a quick checklist you can use on every suspicious email.

What is a phishing email?

A phishing email is a fraudulent message meant to trick you into handing over sensitive information (passwords, credit card numbers, Social Security numbers) or clicking a link that installs malware on your device. Attackers disguise these emails as messages from companies and people you already trust: your bank, PayPal, Microsoft, the IRS, your boss, or a colleague.

The word "phishing" is intentional: cybercriminals cast a wide net, hoping someone bites. With billions of phishing emails sent every day, plenty of people do.

The 30-second phishing check: 7 red flags to scan for

When an email feels even slightly off, run through these seven signals:

  1. Suspicious sender address, Does the domain match the real company?
  2. Generic or wrong greeting, "Dear Customer" instead of your name?
  3. Urgent or threatening language, "Act now or your account will be suspended"?
  4. Unexpected attachments or links, Were you expecting a file from this sender?
  5. Hoverable link mismatch, Does the link text match where it actually goes?
  6. Requests for sensitive information, Legitimate companies never ask for passwords via email.
  7. Too-good-to-be-true offers, "You've won a $500 gift card. Click to claim."

If you check even two or three of these boxes, do not click, do not reply.

8 real phishing email examples (and how to spot them)

1. The fake invoice email

What it looks like:

Subject: Invoice #INV-00892, Payment Due Immediately
> Dear Accounts Team, please find attached invoice #INV-00892 for $3,240.00 due within 48 hours. Late payments are subject to a 5% penalty. Click here to review and approve payment.

Why it works: Urgency ("48 hours," "penalty") pushes finance teams to act without verifying. There's often no real vendor behind the request.

Red flags:

  • You don't recognize the vendor or invoice number
  • Pressure to pay immediately without a purchase order
  • The attachment is an executable or the link redirects to a suspicious domain
  • The "from" address looks like billing@inv-0892-services.net

2. The account suspension email

What it looks like:

Subject: Urgent: Your Microsoft Account Has Been Suspended
> Your account has been locked due to suspicious activity. Verify your identity immediately. Failure to verify within 24 hours will result in permanent account deletion.

Why it works: Fear of losing access triggers a hasty reaction. These emails mimic real Microsoft, Google, or Apple notifications almost perfectly.

Red flags:

  • Hover over "Verify", the URL likely leads to microsoftsupport-verify.com, not microsoft.com
  • Microsoft never threatens permanent deletion via email
  • Generic greeting ("Dear User") rather than your name

3. The fake PayPal alert

What it looks like:

Subject: You've sent a payment of $299.00 to TechStore LLC
> A payment of $299.00 has been made from your account. If you did not authorize this, click here to cancel and get a refund immediately.

Why it works: Panic over an unauthorized charge causes people to click without pausing. With roughly 430 million PayPal users globally, even a low hit rate yields big results.

Red flags:

  • Sender isn't service@paypal.com, look for variants like service@paypal-secure.net
  • Log into PayPal directly by typing the URL yourself, never through the email link
  • Real PayPal emails always include your full name, not "Hi" or "Dear Customer"

4. The Google Docs / file sharing scam

What it looks like:

Subject: [Colleague's Name] has shared a document with you
> [Colleague's Name] has shared a Google Doc: "Q3 Budget Review." Click "Open in Docs" to view.

Why it works: Attackers compromise one account and use it to send phishing links to the entire contact list. You click "Open in Docs," land on a fake Google login page, and hand over your credentials.

Red flags:

  • Were you expecting a document? A quick text can save you
  • The link doesn't go to docs.google.com, hover to check
  • You're asked to sign in again even though you're already logged into Google

5. The IRS / tax refund scam

What it looks like:

Subject: IRS Notice: You Are Eligible for a Tax Refund of $1,847.00
> Our records indicate you are owed a federal tax refund. Submit your banking information via our secure portal within 5 business days.

Why it works: Money owed to you feels urgent. The authoritative IRS name makes people act fast, especially during tax season.

Red flags:

  • The IRS never initiates contact by email, text, or social media asking for financial information, period
  • Sender domain won't be irs.gov, look for impersonators like irs-refund.org
  • Real IRS correspondence arrives by physical mail

6. The CEO or executive impersonation email (Business Email Compromise)

What it looks like:

Subject: Quick Favor, Confidential
> Hi [Employee Name], I'm in a meeting. I need you to process an urgent wire transfer of $18,500 to a new vendor today, I'll explain later. Keep this between us for now.

Why it works: Employees are conditioned to respond quickly to executive requests. The FBI's IC3 reports Business Email Compromise (BEC) caused over $2.9 billion in losses in 2023 alone.

Red flags:

  • The "from" address subtly differs from your CEO's real email (e.g., ceo@company-corp.net vs. ceo@company.com)
  • Requests for secrecy are a massive red flag, legitimate transactions don't work this way
  • Always verify wire transfers via a phone call to the sender's known number

7. The fake subscription / renewal email

What it looks like:

Subject: Your Netflix Membership Has Been Paused
> We're having trouble processing your payment. Update your billing information to continue enjoying Netflix without interruption.

Why it works: Subscription services like Netflix, Spotify, and Amazon Prime have hundreds of millions of users, making impersonation a high-probability bet.

Red flags:

  • Log directly into your account through the official app or website, not the email link
  • Real Netflix emails come only from @netflix.com
  • Hover over "Update Now" to see where it actually leads

8. The advance-fee / "Nigerian prince" scam

What it looks like:

Subject: Strictly Confidential Business Proposal
> I am Mr. Emmanuel Okafor, legal adviser to the late Chief Daniel Eze. He left behind an estate of $12.5 million USD with no named heir. I am reaching out to you as a trusted foreign partner to assist in transferring these funds...

Why it works: Running since the 1990s, this scam survives by filtering for the most vulnerable recipients. Scammers don't need a high hit rate, they string along a small percentage for months.

Red flags:

  • Unsolicited emails from strangers offering large sums are never legitimate
  • The story escalates, there are always "fees" or "taxes" to pay before you receive money (you never do)
  • Broken English, odd formatting, and elaborate backstories are hallmarks

How phishing emails have evolved

Modern phishing attacks are far more sophisticated than the badly spelled emails of the past:

  • AI-generated phishing: Hoxhunt's 2025 research found AI-powered spear-phishing attacks are 24% more effective than human-crafted ones. AI eliminates the grammatical errors that used to be the easiest red flags.
  • Spear phishing: Targeted attacks that include your name, employer, role, and recent activity scraped from LinkedIn or data breaches, making emails feel eerily personal.
  • Smishing and vishing: Phishing has spread to SMS (smishing) and phone calls (vishing), so apply the same skepticism to unexpected texts and calls.
  • QR code phishing ("quishing"): Malicious QR codes embedded in emails bypass link scanners and redirect you to fake login pages when scanned on your phone.

What to do if you clicked a phishing link

Clicked before you thought? Don't panic, act fast:

  1. Disconnect from the internet immediately to stop malware from communicating with attackers.
  2. Change your passwords for any compromised accounts, starting with email and banking. Use a separate, clean device.
  3. Enable multi-factor authentication (MFA) on your accounts, it's your best secondary defense.
  4. Scan your device with reputable security software to check for malware.
  5. Report it, forward phishing emails to reportphishing@apwg.org (Anti-Phishing Working Group) and to the FTC at ReportFraud.ftc.gov. If it impersonated a company, notify that company's fraud team.
  6. Alert your IT department if this happened on a work device or work email.

Guardio detects and blocks phishing sites in real time, so even if you click, the malicious page gets stopped before it can do damage. Get a free security scan with Guardio today and stay protected from phishing attacks.

Your 30-second phishing detection checklist

CheckWhat to Look ForSender addressDoes the domain exactly match the real company?GreetingIs it addressed to you by name?UrgencyIs it pressuring you to act right now?LinksHover first, does the URL match the display text?AttachmentsWere you expecting a file from this sender?RequestIs it asking for personal info, money, or credentials?Gut checkDoes something feel slightly off? Trust that feeling.

If you check even two or three of these boxes, stop. Verify through a separate channel before taking any action.

Conclusion

Phishing emails are crafted by professionals whose full-time job is to manipulate you. The best defense isn't paranoia, it's a consistent habit of pausing for 30 seconds before you click, download, or reply.

Bookmark this page, share it with someone who needs it, and remember: when in doubt, don't click. Verify.

Get started with a free scan today

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What are the most common types of phishing emails?

The most common phishing email types include fake invoice requests, account suspension alerts (impersonating Microsoft, Google, or Apple), fake PayPal payment notifications, IRS tax refund scams, CEO wire transfer requests (Business Email Compromise), and fake subscription renewal emails from Netflix or Spotify. Each uses urgency, fear, or trust in a known brand to pressure you into acting without thinking.

How can I tell if an email is a phishing attempt?

You can identify a phishing email by checking six things in under 30 seconds: whether the sender's domain exactly matches the real company, whether your name appears in the greeting, whether the email creates unusual urgency, whether link URLs match their display text when hovered, whether you were expecting any attachments, and whether it requests passwords, money, or personal data. Two or more of these signals together is a strong indicator the email is fraudulent.

What should I do if I accidentally clicked a phishing link?

Don't enter any information on the page. Close the tab immediately. Change the password for whatever account the link appeared to target. Run a malware scan. If you entered payment information, contact your bank immediately.

Can phishing emails look exactly like real emails?

Yes. Modern phishing emails can closely replicate the logos, color schemes, formatting, and sender names of legitimate companies like Microsoft, PayPal, and the IRS. AI-generated phishing attacks, which Hoxhunt's 2025 research found to be 24% more effective than human-crafted ones, remove the spelling errors and awkward phrasing that once made fakes easy to spot. The safest habit is always to verify through an official channel rather than trusting the email itself.

What is spear phishing and how is it different from regular phishing?

Spear phishing is a targeted form of phishing where attackers personalize the email using specific details about you, such as your name, employer, job title, or recent activity, often scraped from LinkedIn or past data breaches. Regular phishing casts a wide net with generic messages sent to millions of people. Spear phishing is far more convincing and harder to detect because it feels like a message from someone who actually knows you.

What is Business Email Compromise (BEC)?

Business Email Compromise (BEC) is a phishing attack where criminals impersonate executives, vendors, or colleagues to trick employees into sending money or sensitive data. A common scenario involves a fake email from a 'CEO' requesting an urgent wire transfer. The FBI's IC3 reported BEC caused over $2.9 billion in losses in 2023, making it one of the costliest forms of cybercrime targeting businesses of all sizes.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now