Phishing does not require sophistication; it requires haste. Every successful phishing attack exploits a moment where the target scans a link instead of reading it. This guide walks through the exact four checks a security engineer performs before clicking any unexpected link, the browser and account settings that stop the majority of attacks, and the recovery playbook if you already clicked.
Check 1 — Read the domain right-to-left
The real domain is the last two labels before the first single slash. In https://accounts.google.com.security-alert.co/login the real domain is security-alert.co — not google.com. Attackers stack subdomains to hide the true destination. Always read right to left, starting at the first slash.
- Ignore everything before the last two labels
- Watch for hyphens joining brand names (paypal-secure.com)
- Watch for country-code lookalikes (.co, .cm, .co.uk)
- Watch for Cyrillic and Greek homoglyphs (аpple.com)
Check 2 — Hover before you click
On desktop, hover reveals the real URL in the browser status bar. On mobile, long-press to preview. If the visible text says 'gov.uk' but the preview shows anything else, do not tap. HTML links can display any text over any target — the text is a suggestion, not a fact.
Check 3 — Match the sender to the ask
Legitimate senders match the ask to the channel. Your bank will not email you a login link. HMRC will not text you a refund link. Netflix will not text you about a suspended payment. When the channel and the ask do not match the sender's normal behaviour, treat the message as hostile until proven otherwise.
Check 4 — Refuse the urgency
Every phishing message manufactures urgency: 'account will be closed', 'parcel returned', 'fine doubles today'. Urgency is the payload, not a side effect. If a message would not be urgent from a stranger, it is not urgent from anyone. Close the message, open the real app, check the real account status.
The three settings that stop most phishing
Turn on multi-factor authentication with an authenticator app (not SMS) on email, banking and social accounts. Install a browser password manager that only auto-fills on the real domain — if it does not offer to fill, you are not on the real site. Enable phishing and malware protection in your browser settings.
What to do if you already clicked
Change the password on the affected account first, from a different device if possible. Sign out all other sessions in the account's security page. Enable MFA immediately if not already on. Watch the account for 30 days and report any unrecognised activity. If banking details were entered, call your bank on the number from your card.
Business-targeted phishing (spear-phishing)
Attackers scrape LinkedIn, invoices and press releases to craft messages that name a real colleague and a real project. Verify any payment-detail change out-of-band — call the person on their known number, do not reply to the email. A verification call costs one minute; a redirected supplier payment costs an average of £64,000.
Reporting phishing usefully
Forward suspicious emails to report@phishing.gov.uk (UK). Forward suspicious texts to 7726 (free). Report scam websites to the National Cyber Security Centre. Each report feeds threat-intelligence feeds that browsers and email providers use to block the same attack on other targets.
FAQ
Are password managers safe to use?
Yes — the leading managers have not been breached in ways that exposed user vaults, and the phishing-resistance benefit (only autofilling on the real domain) outweighs the theoretical risk. Enable MFA on the manager itself.
Is SMS multi-factor authentication good enough?
It is far better than none, but SIM-swap attacks defeat it. Move critical accounts (email, banking, primary social) to an authenticator app or hardware key. Keep SMS as a fallback.
- Protect yourself from online scams: 12 patterns and the counter-move for eachSafety · 12 min16% match
- Verification tiers explained: from claim to receipt-linked proofVerified Reviews · 12 min7% match
- How to collect more reviews in the UK: a 2026 playbookGrowth · 14 min6% match
- What makes a review truly verified: the four tiers explainedTrust · 9 min6% match
- Trades reviews UK: the plumber and electrician playbook 2026Trades · 12 min6% match
- How to avoid review sites that publish fake reviewsTrust · 7 min6% match
Keep reading
- 1SEO for review pages: how verified reviews lift organic rankingsSEO · 9 min
- 2How to spot fake reviews: a practical detection checklistTrust · 8 min
- 3Detecting inauthentic review trends across a sectorResearch · 11 min
- 4How to avoid review sites that publish fake reviewsTrust · 7 min
- 5How authentic reviews build a healthy business profile that ranks on GoogleSEO · 10 min
- Verified Reviews
- Trust & Safety
- Online Scams
- Phishing Defence
- SEO
- Marketing
- Growth
- Consumer Rights
- AI & Reviews
- Hospitality
Get the newsroom in your inbox every Friday.
Reviews reporting, scam alerts and playbooks. Free. Unsubscribe anytime.
Discussion (2)
- Priya S.· 2 days ago
Really practical breakdown — the four-part reply structure is now on our till-side crib sheet. Thank you.
- Dan (Cannock Plumbing)· 5 days ago
Went from 12 reviews to 47 in three months following almost exactly this playbook. It works.
