Unerdwear

Developer tools · lightweight guides · security notes

Phishing basics: how to spot it fast

A fishing hook on a plain background
Source: Unsplash.

Phishing is still the #1 “easy win” for attackers because it bypasses technical controls and targets people.

If you learn one habit, make it this:

Never log in from an email link. Navigate by typing the domain or using a bookmark.

The 30-second phishing check

  1. Who sent it? Expand the sender details (not just the display name).
  2. Where does the link really go? Hover on desktop; long‑press/copy on mobile.
  3. Does the message create urgency? “Account suspended”, “payment failed”, “security alert” are classic triggers.
  4. Is the domain slightly wrong? Extra hyphens, swapped letters, weird subdomains.
  5. Are you being asked for a code? Real support agents don’t need your MFA codes.

If you clicked (don’t panic)

Do these in order:

  1. Change the password from a clean device.
  2. Sign out of all sessions (“log out everywhere”).
  3. Turn on MFA (app-based where possible).
  4. Check recovery email and recovery phone.
  5. Check for new forwarding rules in your email.

Primary references (high trust)

Last updated: 2026-01-02