Phishing is a social engineering attack that impersonates a trusted person or organization to trick you into revealing credentials, sending money, or installing malware. It doesn't rely on breaking software - it relies on breaking your judgment for a few seconds, usually by combining a fake identity with a deadline. Email is the most common channel, but the same trick works over text message, phone calls, and fake websites.
- Phishing is deception, not a technical exploit - it targets human judgment, not a software vulnerability.
- The delivery channel varies (email, text, phone, QR code) but the mechanism nearly always pairs impersonation with pressure - usually urgency, sometimes authority, fear, or curiosity.
- Spear phishing and business email compromise are personalized and far more convincing than generic mass phishing.
- A correctly spelled sender address or a professional-looking email is not proof of anything on its own.
- Phishing is a subset of "scam" - the broader category also includes schemes that never impersonate anyone.
- Manual vigilance helps, but automated detection is what makes checking every email realistic.
What phishing actually means
Phishing gets its name from "fishing": an attacker sends out a large batch of near-identical fraudulent messages and only needs a small fraction of recipients to bite. Wikipedia's entry on phishing defines it as a form of social engineering where an attacker sends a fraudulent message designed to trick a person into revealing sensitive information or deploying malicious software. That framing matters because it draws a line most people miss: phishing isn't a virus you catch by clicking the wrong thing - it's a con someone runs on you, and the "malicious" part is optional. Plenty of phishing emails contain no malware or bad link at all, just a convincing request. CISA describes it the same way: messages designed to look like they come from a trusted person or organization, delivered by email, text, direct message, or phone call, to get you to respond before you think it through.
We built Email Scam Checker around that distinction. Our heuristic checks don't just look for malicious attachments - most of what we flag is language and metadata: a display name that doesn't match the sending domain, a link whose visible text disagrees with where it actually goes, a request phrased to make you skip verifying it. Phishing is a communication problem before it's a technical one, and that's why detecting it looks less like antivirus scanning and more like fact-checking a message against what it claims to be.
Why phishing keeps working
Phishing remains the most reported form of cybercrime because volume beats sophistication. The FBI's Internet Crime Complaint Center annual report logged 191,561 phishing and spoofing complaints - the single most reported category, more than double the 89,129 complaints for extortion, the next-highest type - with business email compromise alone responsible for $3.04 billion in reported losses. The Anti-Phishing Working Group counted nearly a million unique phishing attacks in a single quarter in its most recent trends report. At that scale, an attacker doesn't need a high success rate - they need you to be the one distracted recipient out of a thousand.
The mechanism behind that success rate is social engineering: exploiting trust, authority, and urgency instead of a software flaw. A message that looks like it's from your bank, your employer, or a service you already use borrows that entity's credibility for free. Add a countdown - "act within 24 hours" - and most people's instinct to double-check gets overridden by their instinct to avoid a bad outcome. This is also why phishing scales in ways that other fraud doesn't: the same email template works whether it's sent to five people or five million, and the attacker only needs the deadline to feel real to a fraction of them.
How to tell if you're looking at one
Three checks are the fastest way to catch a phishing attempt, in this order: does the sender's actual domain match who they claim to be, does a link's real destination match its visible text, and is the message pressuring you to act immediately. Any single failure is a reason to stop and verify independently, rather than clicking through and hoping it's fine.
None of these checks is bulletproof alone - a compromised legitimate mailbox can pass the sender check, and a company's real marketing emails sometimes use urgency language too - which is exactly why they're meant to be combined rather than trusted individually. For the full breakdown of sender, link, and language red flags with an annotated real-world example, our guide on how to spot a phishing email walks through each one in detail.
The main types of phishing attacks
Every type of phishing below uses the same core trick - a borrowed identity paired with pressure, whether that's urgency, authority, or curiosity - delivered through a different channel or aimed at a different target. The channel changes the tell you should look for; the underlying deception doesn't change at all.
| Type | Delivery channel | Typical target | Typical tactic |
|---|---|---|---|
| Email phishing | Email, mass-sent | Anyone with an email address | Generic account-suspended or failed-delivery notice |
| Spear phishing | Email, individually researched | A specific named person | Real personal or work details used to build trust |
| Whaling | Email, individually researched | Executives and senior staff | Impersonating a board member or regulator |
| Business email compromise | Email, impersonated colleague or vendor | Finance and accounts-payable staff | Payment or invoice-detail change request, often no link at all |
| Smishing | SMS / text message | Mobile phone users | Fake delivery or toll-payment link |
| Vishing | Phone call, often spoofed caller ID | Anyone reachable by phone | Live authority pressure from a "bank" or "agency" |
| Quishing | QR code, printed or digital | Anyone who scans the code | Fake parking, menu, or payment QR code |
Email phishing
Email phishing is the mass-sent, untargeted version: the same fraudulent message - "your account has been suspended," "your package couldn't be delivered" - goes out to thousands of addresses with no personalization at all. It's also the type our detection engine is built for. We run 24 independent heuristic checks against every email opened in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail, covering sender mismatch, lookalike domains, link and language red flags, and combine the results into a risk score from 0 to 100. Below 20 is safe, 20 to 49 is suspicious, and 50 or above - or any single critical trigger - is a scam verdict.
Spear phishing and business email compromise
Spear phishing swaps volume for research: the attacker learns your name, employer, job title, or a recent purchase, and builds one message specifically for you instead of a template for everyone. Business email compromise is the financially damaging variant - impersonating your boss or a vendor to request a wire transfer, gift cards, or a change to invoice payment details, often with no malicious link or attachment at all, which is exactly what makes it harder for filters to catch.
Cryptocurrency exchange users are a common spear-phishing target, which is why we built anti-phishing codes: a personal secret phrase you configure once for a service like Coinbase, Gate, Binance, or Proton Mail. If a message claims to be from that service and includes an anti-phishing code label, we check whether it matches yours - a mismatch is treated as a critical signal, independent of how convincing the rest of the email looks.
Phishing myths that get people caught anyway
One of the most common assumptions we hear from users is "I'd notice the bad grammar" - and it's outdated advice. Well-produced spear phishing and business email compromise messages are often grammatically clean, because the attacker took the time to write one message for one target instead of translating a template at scale. Grammar mistakes are still a real signal in mass email phishing - they're one of our own 24 checks - but their absence proves nothing about a targeted attack.
The second myth is "phishing only happens over email." Text-message smishing, phone-call vishing, and QR-code quishing all use the exact same psychological playbook, and none of them pass through an email inbox's spam filter at all. A QR code on a parking meter or a fake delivery text bypasses every protection built for email, which is exactly why the sender-domain-and-link checks that work for email don't transfer cleanly to those channels.
When something that looks like phishing isn't
Not every urgent-sounding email is an attack. Genuine marketing platforms like HubSpot, Mailchimp, and SendGrid legitimately use countdown language - "sale ends tonight" - that superficially resembles a phishing deadline. The difference is context: a working unsubscribe link, a real physical address in the footer, and a sender domain that actually belongs to the company sending it are supporting legitimacy signals - none of them proof on its own, since a well-prepared scam can fake any single one, but genuine in combination with a matching domain. A single urgency phrase next to those signals is a weak flag, not a verdict.
A first-time sender is another case worth a second look rather than instant alarm. An email from a domain with no history in your inbox deserves a caution, not because it's automatically phishing, but because it's the same pattern spoofing and business email compromise rely on - and it's exactly why we add a first-time-sender flag rather than treating it as proof either way.
How to protect yourself from phishing
Start with the same three checks that catch most attempts: verify the sender's actual domain, hover over links to see their real destination, and treat any deadline as a reason to slow down rather than speed up. If a message claims to be from a service you use, open that service directly in your browser instead of clicking through the email. Browsers already block some of this on their own - Google Safe Browsing uses automated crawling and machine-learning models to flag sites it has already detected or classified as malicious - but a brand-new domain registered for this week's campaign may not be classified yet.
Nobody has time to run three mental checks on every message that lands in an inbox - that's a job for software, not willpower. For emails, we run heuristic checks automatically the moment you open a message, and for anything that passes the rules but still feels off, an on-device AI model gives a second opinion - our guide on AI phishing detection, on-device vs cloud explains why where that model runs matters for your privacy. If you're weighing detection approaches more broadly - browser warnings, antivirus suites, or a dedicated extension - our best phishing protection comparison lines them up side by side. And if you ever do get caught out, CISA's phishing reporting guidance covers exactly what to do next.
Final verdict - what is phishing
Phishing is impersonation paired with pressure - usually urgency, sometimes authority or curiosity - aimed at getting you to act before you verify. The channel, whether email, text, phone, or QR code, is just the delivery mechanism. Knowing the definition and the types is what lets you recognize an attack you've never seen the exact wording of before, because the shape of the trick stays the same even as the details change. Since checking every message manually doesn't scale, that recognition works best paired with automated detection running quietly in the background.