An email can seem completely innocent, even when it's designed to steal your passwords, personal information, or even money. The good news is that, in most cases, it only takes 30 seconds to spot the key signs of a phishing email.
See also: Microsoft: Tycoon2FA disruption reduced phishing attacks by 92%
The first thing to check is the sender. Don't just look at the display name, but the actual email address. If, for example, a message claims to be from a bank, but the sender's address uses a strange or unrelated domain, be extra careful. Cybercriminals often use addresses that look like the real thing, but contain minor changes.

Then, read the message carefully. Phishing emails often try to create panic or a sense of urgency. Phrases like “your account will be closed today” or “confirm your details immediately” are intended to get you to act without thinking.
See also: Forg365: New phishing platform targets Microsoft 365 accounts

Links also require special attention. Before clicking, hover your mouse over the link, without opening it, and check the address that appears. If it leads to an unknown domain or to an address that is not related to the supposed company, do not proceed.
Finally, look out for any unusual attachments, spelling errors or strange wording. None of these signs alone prove an email is a scam, but their combination is a strong indication.
See also: Evilginx: Three phishing operations revealed by mistake

The basic rule is simple: don't be in a hurry to click. If a message is pressuring you to give out information, log in to an account, or open a file, stop and check it first. 30 seconds of attention can protect you from much greater harm.
