The Phishing Email Inspection: How to Check Any Email in 60 Seconds

Most phishing emails are not clever. They are sloppy, and they get through because nobody inspects them. A 60-second inspection catches the overwhelming majority, and it is a skill a parent can learn in one sitting. This page is the inspection itself, the tells to look for, and the script to teach a parent.

Last reviewed August 2026 Reading time: 6 minutes

four boring questions, not "is this real?"

The phishing email inspection

An email can claim anything, so the inspection never asks "is this real?" It asks four boring questions about the sender, the link, the pressure, and the ask. If any answer is wrong, the email does not get acted on.

  1. Q1Who actually sent it?Tap the sender name to see the full address: "Amazon.com" can display as anything, and the address after the @ is the truth. A real company sends from its own domain, not "@amazon-support.net" or "@gmail.com" wearing the logo.
  2. Q2Where does the link actually go?Hover, do not click, and read the address that appears: it should match the company's real domain. A "log in" link that goes anywhere except the real login page is the scam, full stop.
  3. Q3Is there a deadline or a threat?"Your account will be closed in 24 hours," "unpaid invoice," "final notice": legitimate emails do not need action in minutes, and the urgency is the pressure.
  4. Q4What is it asking for?A real company does not ask for a password, a one-time code, a Social Security number, or payment by gift card, wire, or crypto in an email. If the ask is any of those, the email is the scam no matter how official it looks, and the generic greeting and slightly off grammar are the tells that show up in almost every phishing email.

The rule, in one sentence: an email can claim anything, so the inspection never asks "is this real?" It asks four boring questions about the sender, the link, the pressure, and the ask. If any answer is wrong, the email does not get acted on.

The 60-second inspection (four questions)

  1. Who actually sent it? Tap the sender name to see the full address. "Amazon.com" can display as anything; the address after the @ is the truth. A real company sends from its own domain ("@amazon.com"), not "@amazon-support.net" or "@gmail.com" wearing Amazon's logo.
  2. Where does the link actually go? Hover (do not click) over any link or button and read the address that appears at the bottom of the browser or in the popup. It should match the company's real domain. A "log in" link that goes anywhere except the real login page is the scam, full stop.
  3. Is there a deadline or a threat? "Your account will be closed in 24 hours." "You have an unpaid invoice." "Final notice." Legitimate emails do not need you to act in minutes; the urgency is the pressure, and the pressure is the scam.
  4. What is it asking for? A real company does not ask for your password, your one-time code, your Social Security number, or a payment by gift card, wire, or crypto, in an email. If the ask is any of those, the email is the scam no matter how official it looks.

That is the whole method. It takes a minute and it does not require knowing what today's specific scam looks like, because it does not rely on recognizing the costume. It relies on the four things every phishing email has to fake, and fakes badly.

The tells that show up in almost every phishing email

  • The greeting is generic: "Dear Customer" or "Dear User" instead of the parent's name. Companies know their customers' names; scammers rarely do.
  • The grammar is slightly off, or the tone is oddly formal or oddly urgent. This is the tell that most people dismiss ("big companies make typos too") and it is exactly the one that matters.
  • The logo looks almost right. Blurry, stretched, or the colors are slightly wrong. Scammers copy logos from the web and they rarely re-create them perfectly.
  • The reply address is a free mailbox (gmail, yahoo, hotmail) even though the sender name says a big company. A real company sends from its own domain.
  • The attachment is unexpected. An invoice, a "statement," a "voicemail" as a .zip or .doc file. Legitimate companies link to documents on their own site; they do not email files that run code.

The script to teach a parent (print this)

Print this and keep it by the computer. It is the whole method in the parent's words:

Check any email in 60 seconds: 1. Who sent it? Tap the name, read the address after the @. 2. Where does the link go? Hover, read the address, never click first. 3. Is there a deadline or threat? Real companies do not rush you. 4. What does it want? Passwords, codes, SSN, gift cards, wire? = a scam. Do not reply, do not click, do not call the number. If in doubt: close it and ask me, or check the official website yourself.

What to do if the parent already clicked or replied

Clicking is not the disaster; entering information is. Work through this in order:

  • If they only opened it or clicked a link, close the browser tab. Nothing has been lost yet, but expect follow-up: the scammer now knows the address is active.
  • If they entered a password, change that password now, and change it on any other account that uses the same one. Email first, then the bank. See Your parent's account was hacked: the 60-minute response.
  • If they entered a card number, call the card issuer immediately and tell them the card may be compromised. Cancel and reissue; do not wait for a mystery charge.
  • If they entered the one-time code, treat every account as at risk: the code may have been used to reset a password. See the code read-back scam and the hacked-account response.
  • If money moved, the first hour matters. See Your parent sent money to a scammer. Now what?

Report the email: forward it to reportfraud.ftc.gov or use the FTC's phishing page (see Sources). And when in doubt about a specific message, run it through Scam Risk Check for a risk band in under a minute.

How to make the next one fail

  • Turn on the email's spam filtering if it is off, and teach the parent to mark junk instead of deleting: marking trains the filter.
  • Set up two-factor authentication on the email and bank accounts so a stolen password is not enough. See Two-factor authentication for parents.
  • Use the one-rule habit: "If an email asks for money, a code, or a password, we check it together before doing anything." One sentence, printed, beats any filter.
  • Do a digital spring clean: fewer accounts means fewer doors. See Digital spring cleaning.

Related

Sources

Found an error? Report it.