A few years ago, phishing emails were easy to spot — bad grammar, weird sender addresses, an obviously fake bank logo. Those days are over. AI-written phishing emails now sound natural, copy real branding pixel-perfectly, and reference details about your accounts that make them feel legitimate. Here’s how to evaluate any suspicious email before you click anything, and the specific scams we see most often when customers bring in compromised computers.

The Three-Second Test

Before you do anything else with a suspicious email, ask yourself three questions:

  • Was I expecting this? Unexpected invoices, package notifications, password resets, and “your account has been suspended” messages are red flags.
  • Is it pressuring me to act fast? “Your account will be closed in 24 hours” and “click here immediately” are classic urgency tactics.
  • Does it want me to click a link or open an attachment? Almost every phishing email leads to one of those two actions.

If the answer to all three is “yes,” treat the email as suspicious until you can verify it through another channel.

Check the Sender’s Real Address

The display name on an email can say anything — “Amazon Customer Service,” “Bank of America,” your boss’s name. The actual sending address is what matters. Click or hover on the sender to see the real address. If “Amazon” is sending you mail from “service@amazonn-billing.co” or some random Gmail account, you’ve got your answer.

Hover Over Links Before Clicking

On a desktop or laptop, hovering your mouse over a link shows the real destination URL at the bottom of your browser or email client. A button labeled “Verify your account” might actually point to a sketchy domain that has nothing to do with the company it claims to be. If the link doesn’t go to the real company’s website, don’t click it.

The Scams We See Most

When customers come in with compromised machines, these are the recurring offenders:

  • Fake delivery notifications. “Your USPS package couldn’t be delivered — confirm your address.” The link goes to a credential-stealing site.
  • Fake Microsoft or Apple security alerts. Pop-ups or emails telling you your computer is infected and to call a phone number. Real Microsoft and Apple never do this.
  • Fake invoices. An email claiming you bought something expensive, with an attached “receipt” that’s actually a malicious file.
  • “Your password was leaked.” Sometimes these are real, sometimes they’re phishing — always check by going directly to the service’s website rather than clicking a link.
  • Fake job offers. Especially common targeting students and recent grads. They eventually ask for personal information or a “deposit.”

What to Do If You Already Clicked

Don’t panic, but act quickly:

  • Disconnect from the internet (turn off Wi-Fi or unplug the ethernet cable).
  • If you entered a password, change it immediately on a different device — and change it anywhere else you use the same password.
  • Turn on two-factor authentication for any affected account.
  • If you downloaded a file or ran an installer, bring the computer in. Don’t keep using it for anything sensitive until it’s been checked.

If You’re Not Sure, Ask

If you’ve got an email you can’t decide about, take a screenshot and bring it by. We’ll tell you whether it’s legitimate, and if your machine is showing any signs that something has already gotten in, we can take a look. Stop in at our 9th Street location or call (919) 314-3327. There’s no charge for “is this real?” advice.

keyboard_arrow_up