DEV Community

Cover image for How to Actually Spot Phishing (Before It Spots You)
The Duchess of Hackers
The Duchess of Hackers

Posted on

How to Actually Spot Phishing (Before It Spots You)

Hi Cyber Lovers

We talked tools last time, but honestly? No tool protects you as much as your own awareness. And phishing is still the #1 way people get hacked, not because attackers are geniuses, but because phishing plays on trust, urgency, and a moment of not paying attention.

I've almost fallen for one myself. So let's break down what to actually look out for.

1. Check the Sender, Not Just the Name

Names can be faked. Email addresses tell the real story.

  • "Support Team" can still come from a random Gmail address
  • Look closely for misspelled domains β€” paypa1.com instead of paypal.com
  • Hover over the sender name to see the actual email

Tip: If something feels slightly "off" about the sender, trust that instinct and dig deeper.

2. Watch for Urgency and Pressure

Phishing thrives on panic.

  • "Your account will be suspended in 24 hours"
  • "Immediate action required"
  • "You've won something β€” claim now"

Tip: Real companies rarely give you a countdown to act. Urgency is a red flag, not a reason to rush.

3. Inspect Links Before You Click

This one habit alone saves you constantly.

  • Hover over links to preview the actual URL
  • Look for slight misspellings or extra characters
  • If it looks weird, don't click β€” go to the site directly instead

Tip: On mobile, press and hold a link to preview it before tapping.

4. Be Wary of Unexpected Attachments

Especially ones you didn't ask for.

  • Invoices, receipts, or documents "you need to review"
  • Files from senders you don't recognize
  • Attachments paired with urgent language (see #2 πŸ‘€)

Tip: When in doubt, confirm with the sender through a different channel before opening anything.

5. Trust Your Gut, Then Verify

If something feels a little too convenient, or a little too urgent, or just... not quite right:

  • Don't click, don't reply, don't download
  • Go directly to the official website or app instead
  • Report and delete

Tip: It's always safer to double-check than to explain a mistake later.

A Little Reminder

Phishing isn't about being "smart enough" to avoid it , even experienced people get caught off guard sometimes. It's about slowing down for those extra five seconds before you click.

Up Next

Next post, we're going deeper into password security , why "strong passwords" aren't actually enough anymore, and what to do instead.

Stay curious, stay consistent

The Duchess of Hackers
Full-Stack Developer | Digital Marketer | Cybersecurity Enthusiast

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.