Home Articles Get your free assessmentComing soon

Anatomy of a Phishing Email: Eight Tells and What They Look Like

Illustration: a printed email under a magnifying glass

Phishing — the fake email built to make you click, log in, or pay — was the most-reported cybercrime in America again in 2025: 191,561 complaints to the FBI’s Internet Crime Complaint Center, more than any other category. It holds that title year after year for a boring reason: it keeps working.

It keeps working partly because the training most people got is out of date. The old advice was “look for bad grammar and obvious typos.” CISA — the federal cybersecurity agency — now says plainly that generative AI has made well-written phishing routine. The clumsy Nigerian-prince era is over; the fakes are fluent now.

What hasn’t changed is the structure. A phishing email has a job to do — create trust, create pressure, deliver a click — and the machinery for doing that job leaves the same fingerprints it always has. Here are eight of them, each shown the way it actually lands in a church office inbox. The examples are composites, not real messages, but every pattern in them is drawn from the attacks this series has already decoded.

1. The display name that doesn’t match the address

From: Pastor David Reeves ‹pastordavid.stmarks@gmail‑mail‑secure.com›
Are you available? I need a favor handled discreetly.

Email lets anyone put any name in the “From” line — the display name is decoration, chosen by the sender. The tell is the actual address behind it. On a phone, that address is hidden by default, which is exactly why so much phishing succeeds on phones: tap the sender’s name and read the real address before you believe anything else about the message. Your pastor’s real address you know. Everything else is a costume.

2. Urgency with a deadline measured in hours

Your mailbox will be deactivated in 4 hours. Verify now to avoid interruption.

Legitimate organizations almost never need you to act within the hour, because nothing real works that way. Manufactured deadlines exist to keep you from doing the one thing that kills every scam: pausing to check. CISA lists urgent, consequence-laden language as the leading sign of phishing. When an email makes your chest tighten, that feeling is the payload.

3. The mismatched link

www.churchgivingportal.com/login

The words of a link and its destination are two separate things — the blue text can say anything while pointing anywhere. On a computer, hover over the link without clicking and read the true address in the corner of the window. On a phone, press and hold to preview it. Watch for near-misses built to survive a glance: `rnicrosoft.com` (r-n masquerading as m), `yourchurch-give.com` instead of `yourchurch.org/give`, or a real brand name buried in front of an unrelated domain: `microsoft.security-check-portal.com`. The only part that matters is the last two pieces before the first slash.

4. The login page you didn’t navigate to

Your document is ready: OfferingReport_Q2.pdf — Sign in to view.

The fake login page is where credentials actually get stolen. The email is just the ride there. The rule that beats it: a link you clicked in an email never gets a password. If a message says a document, invoice or voicemail is waiting behind a sign-in, close it and go to the service directly — type the address or use the app. If the document is real, it’s there. This habit also defeats attacks good enough to beat inspection, which some now are.

5. A request that switches channels or demands secrecy

Don’t call me, I’m going into the service. Just reply here.

Real requests survive verification; fake ones must prevent it. So the message forbids exactly the act that would expose it — “don’t call,” “keep this between us,” “I’m unreachable.” We’ve seen this lever in the gift card scam, in payroll diversion, and in voice cloning. Treat any instruction not to verify as the confession it is.

6. The attachment that needs something extra

Invoice attached. If the document appears blank, click Enable Content to view.

An attachment that requires you to click a button, enable macros, or install “a viewer” to read it isn’t a document with a problem — it’s a program wearing a document’s clothes. Modern office software disables that machinery by default precisely because it was the most common way malware got run. The email is asking you to overrule your own safety equipment.

7. The reply-to that goes somewhere else

From: finance@yourdenomination.org
Reply-To: finance.office.desk@outlook.com

Some phishing genuinely spoofs a trusted address in the “From” line — but the conversation has to route back to the attacker, and the hidden Reply-To field is where that happens. If you hit reply and the address in the compose window isn’t the one you thought you were talking to, stop. This is also why continuing an email thread is not verification: in business email compromise, the thread itself is the stolen property.

8. Almost right, at the wrong moment

Following up on the invoice from last month’s roof repair — updated remittance details attached.

The most dangerous phishing contains no visible mistakes, because it’s built from real information: your actual roofer, a real project, plausible timing. The tell isn’t in the text — it’s in the event: money or credentials being requested with any change from the established pattern (new bank details, new payment method, new address, unusual quiet urgency). At that point the email’s quality is irrelevant, because your procedure — confirm changes by phone on a number you already have — doesn’t care how good the writing is.

What to do this week

Print these eight, tape them by the office computer, and spend ten minutes at the next staff meeting reading the examples aloud — people recognize patterns far faster from specimens than from rules. Then set the reporting habit: CISA’s guidance is recognize, resist, delete — and in an organization, “resist” means report it to whoever handles your email before deleting, so one alert reader protects everyone. Make the report thank-worthy, never eye-roll-worthy; the person who forwards a false alarm is your early-warning system working.

And keep the fallback that underlies this whole series: when an email requests money, credentials, or account changes, the email itself is never the proof. Verification travels on a different channel — a phone number you already had, an address you typed yourself.

The MissionDefend assessment checks whether your organization has these habits in place — reporting culture, verification rules, MFA — and gives you a prioritized plan for what’s missing. Join the launch list.


Sources: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (phishing/spoofing complaint count); Cybersecurity and Infrastructure Security Agency, Recognize and Report Phishing.

Found this useful? Pass it on.

Facebook X LinkedIn Email