Phishing is a type of cyberattack in which a scammer impersonates a trusted person, brand, or organization, typically by email, text message, or phone call, to trick someone into handing over passwords, financial details, or other sensitive information, or into installing malware.
Phishing is one of the oldest tricks in cybercrime, and it is still the most reported one. The FBI’s Internet Crime Complaint Center logged more phishing and spoofing complaints in 2024 than any other type of cybercrime it tracks, and business email compromise scams, which almost always start with a phishing message, cost victims $2.77 billion in 2024 alone. What has changed is how those scams are built. AI tools now let attackers write flawless, personalized emails in minutes and clone a real person’s voice from a few seconds of audio. The good news: phishing is still one of the easiest attacks to defend against once you know what to look for.
Learn how to spot these scams below, and how to protect yourself and your organization against them.
Signs That You May Have Received a Phishing Email
- Suspicious “from” address: Official emails about passwords and personal information come from official email addresses, not personal accounts or close copies of a real domain. Scammers register addresses that look almost right, like a company name with an extra word or hyphen tacked on. Compare the sending address against the contact information listed on the company’s real website, not against what’s in the email itself.
- Odd tone/sense of urgency: A generic greeting, an unnecessary sense of urgency, or phrasing that feels “off” are still worth trusting your gut over. Spelling and grammar mistakes used to be one of the most reliable tells, and AI writing tools have made that signal far less useful (more on this below). Don’t assume a well-written email is automatically safe. Unnecessary calls to urgent action can also indicate the email isn’t authentic.
- Links to fake websites: A convincing phishing email leads to a convincing fake URL, something like
paypal-secure.onlineinstead ofpaypal.com. Some scams go further and mix in real links to the company’s actual site alongside the fraudulent one. Don’t click links in an unexpected email. Instead, open a new browser tab and navigate to the site yourself, or use a bookmark you already trust. - No digital signatures: If a company signs emails with S/MIME, that signature is proof of identity before you even open the message. It’s still worth verifying the rest of the email’s contents, and confirming the certificate is genuinely CA-issued, but a missing or untrusted signature on a message that should have one is a red flag.
If your email client supports S/MIME (most do), it’s easy to check for and inspect a digital signature. Here’s how to do it in Gmail:
1. Click the triangle to the right of the sender’s name to Show details.

2. The green check mark and Verified email address message mean that the message has been signed by a trusted digital signature. For more information, click the Sender info link. If the certificate is not trusted by Gmail, you will see the messageThe certificate is not trusted. For unsigned email, no certificate information will be displayed.

3. Now check the signer’s email address, the issuing certificate authority (CA), and the certificate’s validity period.

- No mention of known contact info: A legitimate password-reset or account email will typically reference details that match what you already know about the organization. Compare it against past emails, printed statements, or the contact page on the company’s real website. When in doubt, reach out using contact details you already know to be correct, not the ones in the message.
How AI Has Changed Phishing
The fundamentals of phishing haven’t changed. Someone is still trying to impersonate a trusted person or brand to get you to hand over information or access. What has changed is how convincing, fast, and multi-channel those attempts have become.
AI writes better lures, faster: In a controlled test, IBM’s X-Force Red social engineering team pitted an AI-written phishing email against one written by its own human experts. The AI version was produced in five minutes from five prompts, compared to roughly 16 hours for the human-crafted one, and it came close to matching the human email’s success rate (an 11 percent click-through rate for the AI version versus 14 percent for the human one), according to IBM’s research. The upshot for anyone reading their inbox: flawless grammar and a professional tone are no longer reliable proof that a message is legitimate.
Voice cloning has made phone-based phishing (vishing) the fastest-growing attack type: According to CrowdStrike’s 2025 Global Threat Report, voice phishing intrusions jumped 442 percent between the first and second half of 2024. AI voice-cloning tools can recreate a recognizable voice from a short public sample, such as a webinar clip or an earnings call, so “I recognized their voice” is no longer a safe way to confirm a caller’s identity.
Attacks increasingly span multiple channels: An AI-written email might be followed by a text message and then a phone or video call reinforcing the same false story, sometimes using synthetic audio or video to add credibility. If an unexpected request, especially one involving money or credentials, arrives through more than one channel in a short window, treat that as a bigger warning sign, not a smaller one.
The practical takeaway: verify unusual or urgent requests through a second, independent channel (a callback to a known number, an in-person check, a message through a separate app) rather than relying on how convincing the message, voice, or video looks.
Signs You May Be on a Phishing Website
- Check the URL: Some fake URLs look obviously wrong. Others convincingly imitate the real thing while running on a lookalike domain. Check that the company name is spelled correctly, that the top-level domain matches what you’d expect (
.comor.devs.orgor.gov, for example) and do the URLs start with the same prefix (e.g.https://)? The safest way to reach a site you need to log into is a bookmark you saved previously, or a fresh search rather than a link from an email or text. - Aggressive Pop-Ups: Be cautious of sites that push hard for your password through pop-up windows layered over what looks like a real page.
- Things don’t “feel” right: Slightly off colors, fonts, or phrasing often register before you can consciously name what’s wrong. Trust that instinct and stop to double-check.
- No lock, no login: Browsers show a closed padlock for sites using
https, and legitimate sites don’t ask you to log in without it. If your browser shows a warning or an unlocked padlock, stop before entering any information. That said, a padlock alone doesn’t guarantee a site is trustworthy, since free certificates make it easy for phishing sites to enablehttpstoo. Treat the padlock as a minimum bar, not a green light.
How To Defeat Phishers
- Close your browser: If something above raised a flag, close the tab and start over rather than continuing to follow the link.
- Enable two-factor authentication (2FA): 2FA means access requires more than a password alone, such as a code sent to another device or a biometric check. It’s one of the single most effective ways to stop a stolen password from turning into a compromised account, so turn it on for any account that offers it, starting with email and banking.
- Check website certificates: While checking for security is no longer as easy as looking for HTTPS or the “green bar” that once was the standard in indicating Extended Validation (EV) certificates, it’s still a good move to look for these certificates, as we’ve explained previously. Many sites have made the choice to use cheap (or free) Domain Validated (DV) certificates that provide some assurances, such as knowing your communication with the site is encrypted. However, DV certificates don’t provide the necessary assurance that you know who is actually operating the website. We’ve laid out how to find that info, for each browser, here.

- Stay protected with digital certificates from SSL.com: As more of work and life happens online, verifying identity is central to avoiding phishing. SSL offers a few ways to help:
- S/MIME, Document Signing, and Client Certificates: Fight phishing directly with digitally signed email and documents, so recipients know a message or PDF genuinely came from you. Client certificates add an extra authentication factor for remote teams.
- SSL/TLS Certificates: Give visitors and customers assurance about your website’s identity and security.
- Code Signing Certificates: Assure customers that your downloadable code is from a trusted source and does not contain malware or been tampered with.
Make your brand’s real emails easy to recognize with a Verified Mark Certificate
One of the newer, and most direct, ways to fight email impersonation is to make your organization’s genuine emails visually unmistakable before a recipient even opens them. SSL’s Verified Mark Certificate (VMC) does exactly that.
A VMC ties your registered trademark logo to your sending domain under the BIMI (Brand Indicators for Message Identification) standard. Once it’s set up:
- Your verified logo appears next to your sender name in supporting inboxes. Gmail requires a Mark Certificate before it will display any brand logo at all, and Yahoo Mail also supports BIMI logo display when a VMC is present.
- The logo is tied to your active trademark registration (through offices such as the USPTO, EUIPO, UKIPO, CIPO, or IP Australia), and SSL revokes the certificate if that trademark lapses, so the badge stays meaningful over time.
- Because a VMC can only be issued to the organization that legitimately owns the trademarked logo, a phishing attempt impersonating your brand cannot obtain one, which makes a verified logo one of the harder signals for scammers to fake.
To qualify, a domain needs DMARC enforcement at quarantine or reject, plus a logo converted to the SVG Tiny P/S format BIMI requires. SSL handles that logo conversion, hosts the file, and provides the exact DNS record needed to go live. Organizations without a registered trademark may still qualify for a Common Mark Certificate or Government Mark Certificate.
For any brand whose name gets impersonated in phishing emails, whether that’s a bank, a healthcare provider, or an e-commerce company, a verified logo in the inbox gives recipients an immediate visual cue that a message is genuinely from you, on top of the technical authentication already happening behind the scenes.
Finally, everyone can do their part by reporting phishing emails to spam@uce.gov and reportphishing@antiphishing.org, and by giving a heads-up to organizations being impersonated so they can protect others moving forward.