Why the message looks right
The mental model most people carry is a decade out of date. Broken English, a Nigerian prince, a sender address that reads like keyboard noise — that was the low-effort end of the trade and it still exists, but it is not what gets ordinary careful people. The current version copies the real company's template because the template is public: anyone can sign up, receive the genuine shipping notification, and reuse the HTML.
Two technical facts are worth internalizing because they remove the checks most people rely on. The first is that the display name on an email, and often the visible address, can be set to anything the sender wants. Mail providers do run authentication checks behind the scenes, and those checks catch a great deal, but what you see in the "From" line of a phone mail app is not a verified identity. The second is that phone numbers on caller ID and the short codes that text messages appear to come from are equally easy to imitate. A message can land inside the same thread as genuine messages from your bank, because threading is done on the displayed number.
Add one more thing: the sender frequently knows something true about you. Your name, the last four digits of a card, the fact that you shop somewhere, a recent order number. None of that requires having compromised you — it comes from data that leaked out of some company years ago and has been traded ever since. A message that contains one accurate detail feels verified, and it is not. See what to do after a data breach for where that detail came from.
What every phishing message is actually after
There are only four ends. Recognizing which one a message is steering toward is faster than trying to judge whether it is genuine.
| The goal | How the message gets there | What it looks like to you |
|---|---|---|
| Your password | A link to a login page that looks like the real one | "Verify your account", "Unusual sign-in", "Your session expired". The page asks for the password you already have. |
| Your one-time code | The sender already has your password and needs the second factor | A call or text saying "we are sending a code to confirm it is you — read it back". No legitimate service asks you to read a code to a person. |
| A payment | An invoice, a fee, a fine, a shortfall | Small amounts, because small amounts get paid without thinking. A $2.94 toll, a $3.99 redelivery fee, a subscription renewal you want to cancel. |
| Card or bank details | A form that asks for the full number, expiry and security code | Framed as confirming a refund, updating a payment method, or claiming a package |
The invoice pattern deserves a note. A message claiming you have been charged several hundred dollars for antivirus you never bought is not trying to collect money — it is trying to get you to call the number in the message to dispute it. The refund conversation that follows is where the damage happens, and it is covered in phone scams.
Tells that still work
| Signal | Why it holds up |
|---|---|
| Urgency with a deadline measured in hours | Account closure today, a package returned tonight, a fine that doubles tomorrow. Real organizations move slowly and write again. Urgency exists to stop you checking. |
| An unusual payment rail | Gift cards, wire transfer, cryptocurrency, or a payment app sent to someone you have not met. Nothing legitimate needs these, and all of them are effectively final once sent. |
| A link that does not go where the text says | On a desktop, hover and read the status bar. On a phone, press and hold to see the destination without opening it. Read the domain right-to-left from the first single slash: the part immediately before that slash is the real site. |
| A service you do not use, or an account you do not have | These go out in bulk. If you have never banked there, the message is not for you specifically. |
| A request that you not discuss it | Confidentiality, an ongoing investigation, "do not tell the branch staff". No genuine institution asks this. |
| An attachment you did not expect | Especially anything asking you to enable content, or a document whose only content is a picture of a link |
What is no longer a tell: spelling and grammar. Generated text is fluent now, and the older advice to look for awkward English gives false confidence. Judge the request, not the prose.
Text messages, and the two patterns that dominate
Text-based phishing works better than email because the medium strips away context. There is no header to expand, no hover preview, and links are shortened by default so the domain is invisible until you open it.
Two campaigns run more or less permanently. The first is the failed delivery: a carrier name, a tracking number, a small fee to reschedule. The second is the unpaid toll — a state tolling authority, a balance of a few dollars, a threat of a late fee. Both work because the amounts are trivial, both are national in scale, and both send to numbers at random, which is why people receive toll notices for states they have never driven in.
The response is the same for both and takes no judgment at all. Do not tap. If you genuinely have a package, open the carrier's own app or type the carrier's address yourself. If you genuinely drive a toll road, log in to the account you already have. Then delete the message. Reporting it to your carrier by forwarding to 7726, which spells SPAM, is free and takes a few seconds.
The one rule: never use a route the message supplied
Everything above collapses into a single habit, and it is worth more than any amount of message analysis. Assume you cannot reliably tell a good message from a bad one — that is a reasonable assumption, not a defeat — and change how you respond instead.
If a message says something about your bank, close it and call the number printed on the back of your own card. If it says something about your account with a retailer, open the app you already have installed or type the address by hand. If it says something about a government matter, look up the agency yourself. The link, the phone number, the QR code and the email address in the message are all supplied by the sender, and every one of them can lead to a convincing replica staffed by people who are expecting your call.
You clicked. Now what
| What you did | Actual risk | Do this |
|---|---|---|
| Opened the message, tapped nothing | Essentially none on a modern phone or mail client | Delete it. Marking it as junk helps your provider filter the next batch. |
| Tapped the link, saw a page, entered nothing | Low. The main harm is that the sender may learn the address is live. | Close the tab. Do not go back to "check" it. |
| Entered a password | High, and it spreads | Change that password immediately from a different device if you can, then change it everywhere you reused it. Sign out all sessions in the account's security settings, and turn on multi-factor authentication while you are there. |
| Entered a one-time code, or approved a push prompt | High and immediate — someone was logging in as you at that moment | Change the password, sign out all sessions, and check the account for added recovery emails, forwarding rules and new authorized devices. Attackers add a mail forwarding rule so they keep seeing your reset messages after you lock them out. |
| Entered card details | Moderate. Cards are the most recoverable thing on this list. | Call your issuer using the number on the card, have it replaced, and ask about their dispute process for anything already charged. What that process covers is set out in your cardholder agreement — read it or ask them directly rather than relying on a general claim. |
| Installed something, or granted access to an account | High | Disconnect from the network, run a full scan with the security tool already on the machine, and review the "third-party apps with account access" list on your mail and cloud accounts. If the machine handles money or work, treat a clean rebuild as the safe option — resetting Windows covers how. |
Making the next one fail
You will be targeted again; the defense that matters is the one that limits what a successful attempt costs. In rough order of value:
A different password on every account, kept in a password manager. This is the single highest-value change, because it converts one compromised site into one problem instead of twelve. The manager also happens to be a phishing check: it fills credentials based on the domain, so on a lookalike site it simply will not offer to fill, and that silence is information. If you want to see how the length and mix of a candidate password actually affects guessing difficulty, the password strength checker runs in your browser.
Phishing-resistant multi-factor authentication where it is offered. A passkey or a hardware security key is bound to the real domain, so it cannot be handed to a replica site by mistake. An authenticator app is the next best thing. Codes by text message are meaningfully weaker: they can be read from a lock screen, and they can be redirected by a SIM swap, where someone persuades a carrier to move your number to their device. SMS is still far better than nothing — the point is to prefer the stronger option when a service offers it.
Separate the email that resets everything. Your primary mail account is the master key to every other account. Give it a unique password and the strongest second factor available, and consider keeping a different address for shopping and newsletters.
Reporting is worth the two minutes. The FTC takes consumer fraud reports at reportfraud.ftc.gov, and forwarding a phishing message to the real company's abuse address helps them get the lookalike taken down. Neither will get money back on its own, and it is honest to say so — the value is aggregate.
If you remember one line from this page, make it this one: the safest response to any message about your money is to close it and reach the institution by a route you chose yourself.
Questions people ask
The email came from the company's real address. Does that mean it is genuine?
No. What you see in the sender line of a mail app is display text, and it can be set to anything. Providers run authentication checks in the background that catch a lot of forgery, but those results are usually invisible on a phone, and messages sent from a genuinely compromised account inside a real company pass every check there is. The same applies to text messages and caller ID — both are routinely imitated, including into the same conversation thread as legitimate messages. Judge the request rather than the sender: urgency, an unusual payment method, or any prompt to log in from a supplied link.
I clicked a phishing link but did not type anything. Am I infected?
Very probably not. On a current phone or browser, loading a page is not enough to install software by itself; the overwhelming majority of these pages are just forms waiting for you to fill them in. Close the tab, do not return to it, and do not enter anything if you have already reopened it. The one case worth taking seriously is if the page prompted a download and you ran what it gave you, or if you granted an app access to your email or cloud account — then treat it as a compromise, scan the device, and review the connected-apps list in your account settings.
What do I do first after typing my password into a fake site?
Change that password, starting with any account where you reused it, and do it from a device you trust. Then, in the real account's security settings, sign out all active sessions — otherwise a session opened with the stolen password stays valid after the change. While you are in there, check for things added on the attacker's side: a new recovery email or phone number, a mail forwarding rule, or an unfamiliar authorized device. Turn on multi-factor authentication if it is not already on. If the account was your primary email, treat that as the priority above all others, because it can reset everything else.
Are those unpaid toll and failed delivery texts ever real?
Sometimes a real notice exists, which is exactly why the fakes work. The way out is to stop trying to tell them apart. If you might genuinely owe a toll, log in to the tolling account you already have or look the agency up yourself; if you are expecting a package, use the carrier's own app. Never the link. The fakes go out to numbers at random, which is why people get toll notices for states they have never driven in, and the fee is always small enough to pay without thinking — that is deliberate.
Is a password manager safe to use?
For nearly everyone it is a clear improvement on the alternative, which in practice is a handful of passwords reused across dozens of sites. A manager lets every account have a different long random password, which means one breached site stays one problem. It also resists phishing in a way people do not expect: it fills credentials by matching the domain, so on a lookalike site it will not offer to fill at all. The trade-off is real — you are concentrating risk in one vault — so protect it with a long unique passphrase you have never used elsewhere and the strongest second factor the manager supports, and make sure you have a recovery path you have actually tested.