What Is Phishing and How to Spot It
Phishing is a fake message (email, SMS, chat or call) that tricks you into clicking a bad link, opening a bad file, or giving away a password or one-time code. Spot it by checking the real sender address, hovering every link before you click, refusing any request for passwords or MFA codes by message, and reporting the message instead of engaging.
Friends, inboxes fill with "Urgent: account locked – verify now". Panic leads to a click, then a password or OTP. Phishing is that game of breaking trust to steal credentials. Today we learn a simple spot checklist — for a US workplace and for personal Gmail / Outlook.
मित्रांनो, इनबॉक्समध्ये "Urgent: account locked – verify now" अशीपत्रे येतात. घाईत क्लिक होतो आणि मग पासवर्ड किंवा ओटीपी दिला जातो. फिशिंग म्हणजे विश्वास तोडून ओळखपत्ते मागण्याचा खेळ. आज आपण ओळखण्याची सोपी यादी शिकू – कार्यालय आणि वैयक्तिक Gmail / Outlook दोन्हीसाठी.
मित्रों, इनबॉक्स में "Urgent: account locked – verify now" जैसे पत्र आते हैं. घबराहट में क्लिक होता है और फिर पासवर्ड या ओटीपी दे दिया जाता है. फ़िशिंग यानी विश्वास तोड़कर पहचान माँगने का खेल. आज हम पहचानने की सरल सूची सीखेंगे – दफ़्तर और निजी Gmail / Outlook दोनों के लिए.
Quick answer
Before you click or reply, run this checklist one line at a time:
- Read the full From address, not only the display name.
- Hover every link; read the real URL in the status bar (do not click yet).
- Ask: did this org ever ask me for a password or MFA code by email? If yes here → stop.
- Look for urgency + fear ("account closed in 1 hour", "wire now").
- Prefer the official app or bookmark, not the message link.
- Report with your mail client's Report phishing / Report junk, then delete.
Safe habits (copy as your personal rule card):
Never share passwords or MFA codes by email/SMS/chat
Type the site address yourself or use a bookmark
Enable MFA on email, bank, work and cloud accounts
When unsure: forward to IT / security, do not click
What do I need before this guide?
- An email account you use daily (Gmail, Outlook, work Microsoft 365, and similar).
- Curiosity, not fear — phishing is common and learnable.
- Optional: MFA already on (see How to enable MFA on Google, Microsoft and AWS).
How does a typical phishing attempt flow?
A fake email looks urgent and asks you to click. Check the real sender, hover the link and never send a password or MFA code by message — then report it.
खोटी पत्र घाई दाखवते आणि क्लिक करायला सांगते. खरा पाठवणारा बघा, दुव्यावर फिरवा आणि पासवर्ड किंवा MFA क्रमांक संदेशाने कधीही पाठवू नका — मग तक्रार नोंदवा.
नकली पत्र जल्दी दिखाता है और क्लिक करने को कहता है. असली भेजने वाले को देखो, लिंक पर फिरकाओ और पासवर्ड या MFA कोड संदेश से कभी मत भेजो — फिर शिकायत दर्ज करो.
Attackers usually follow a short path. Read it as a vertical list, not a blur:
- They pick a trusted brand (bank, Microsoft, Google, HR, courier).
- They send a message that creates urgency or fear.
- The link goes to a lookalike site or a malware download.
- You type a password, approve an MFA prompt, or open a file.
- They use that access for mail rules, money, or further phishing from your account.
Your job is to break the chain at step 2–3 — before credentials leave your hands.
How do I spot phishing in practice?
Step 1 — Check the sender (display name vs address)
Display names are easy to fake. Expand the From header and read the real address.
- Open the message.
- Click the sender name to expand details.
- Confirm the domain matches the real organisation (for example
@microsoft.com, not@micros0ft-secure.com). - For internal-looking mail, confirm it really came from your company domain and not a lookalike.
Step 2 — Hover links; never trust the underlined text
- On desktop, move the pointer over the link and read the URL preview.
- On phone, long-press to preview (do not tap open).
- Reject links with random subdomains, IP addresses, or misspellings.
- If you must visit the service, open a new tab and type the official address yourself.
Step 3 — Refuse credential and MFA harvests
- No bank, Google, Microsoft or HR team needs your password by email.
- No support chat needs your SMS or authenticator code.
- Unexpected MFA push on your phone? Choose No / Deny and change the password from a trusted device.
Ravindra Bagale's Tip
💡 Many students trust a message just because it says "Dear Customer" and shows a logo. Logos take seconds to copy. Your first reflex must be the From address + link target — not the display name. Remember: panic is part of the attacker’s design.
Ravindra Bagale's Tip – मराठी
💡 खूप students फक्त "Dear Customer" आणि logo बघून trust करतात. Logo copy करायला 10 seconds लागतात. तुमचा पहिला reflex हवा: From address + link target. Display name नाही. लक्षात ठेवा – panic = attacker ची design.
Ravindra Bagale's Tip – हिंदी
💡 बहुत students सिर्फ "Dear Customer" और logo देखकर trust कर लेते हैं. Logo copy करने में 10 seconds लगते हैं. आपका पहला reflex हो: From address + link target. Display name नहीं. याद रखो – panic attacker की design है.
Step 4 — Watch language and attachments
- Generic greetings plus exact account panic is a classic mix.
- Unexpected
.html,.iso,.img, double extensions (.pdf.exe) or macros from strangers → do not open. - "Invoice attached – enable macros to view" from an unknown sender → stop and verify by phone using a number you already know (not the number in the email).
Step 5 — Report and move on
- Use Report phishing in Gmail or Report → Phishing in Outlook / Microsoft 365.
- If it is a work account, also tell IT / security with the original message (not just a screenshot).
- If you already clicked, go straight to the errors table below — speed matters.
How do I fix common phishing mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| You clicked but did not type anything | Drive-by risk still possible | Run OS + browser update; scan with your normal antivirus; watch for new mail rules |
| You typed a password on a fake page | Credential theft | Change that password from a bookmark / official app; enable MFA; check sessions / devices and sign out unknowns |
| You approved an MFA prompt you did not start | MFA fatigue / push bombing | Deny further prompts; change password; prefer number-matching or security keys |
| Mail still looks "from IT" | Display-name spoof | Expand From; verify via known IT channel, not reply-all to the suspect thread |
| Colleague got the same mail | Targeted or blast phish | Report so mail filters can block the campaign for everyone |
Try it at home
Pick three recent promotional or security-looking emails in your inbox. For each one, write three lines only:
- Real From address
- Real link target (hover / long-press)
- Would you click? Why or why not?
Keep that habit for one week.
Learn it properly
This guide is the short path. The free Cyber Security course goes deeper:
Got it? Phishing = trust + urgency + fake link. Your defence: From address, hover, never send password/MFA by message, report it. Break the panic-click habit and you are already safer. Next, enable MFA.
समजलं का? फिशिंग = विश्वास + घाई + खोटा दुवा. तुमचा बचाव: पाठवणारा पत्ता, दुवा फिरवणे, पासवर्ड/MFA संदेशाने नको, तक्रार. घाईत क्लिकची सवय तोडली की तुम्ही आधीच सुरक्षित. आता MFA सुरू करूया.
समझ में आया? फ़िशिंग = विश्वास + जल्दी + नकली लिंक. आपका बचाव: भेजने वाले का पता, लिंक देखना, पासवर्ड/MFA संदेश से नहीं, शिकायत. घबराहट में क्लिक की आदत तोड़ी तो आप पहले से सुरक्षित. अब MFA चालू करें.
Frequently asked questions
What is phishing?
A fake message that tricks you into clicking a bad link, opening a bad file, or giving a password or one-time code.
How do I spot a phishing email quickly?
Check the real From address, hover the link target, refuse any request for passwords or MFA codes, and report instead of engaging.
Is a matching logo enough to trust a message?
No. Logos are easy to copy. Trust the address, the link target and out-of-band verification.
What if I already typed my password on a fake page?
Change that password from an official app or bookmark, enable MFA, sign out other sessions and tell IT if it is a work account.
Should I open the link to “check” it?
No. Preview by hovering or long-press, or use an approved sandbox tool. Do not open suspect links in your daily browser profile.
Where can I learn more on this site?
See the Cyber Security lessons on social engineering awareness and the related SOC phishing analysis guide.