Phishing emails range from obvious scams full of typos to highly sophisticated impersonations that have fooled experienced security professionals. Seeing real examples of each type — and understanding the tell-tale signs — is the most effective way to build the recognition pattern that keeps you from falling for them.
Type 1: The Urgency/Account Threat Email
Subject: “Your account has been compromised — immediate action required”
What it looks like: A professional-looking email from what appears to be your bank, Google, Microsoft, or a major retailer. It states that suspicious activity has been detected, your account will be suspended, or an unauthorized transaction is pending. There’s a prominent button or link: “Verify Your Account” or “Secure My Account Now.”
The tells:
- The sender address doesn’t match the claimed organization (look at the actual email address, not the display name)
- The link destination doesn’t match the company’s real domain (hover before clicking)
- Artificial urgency — “within 24 hours” or “immediately”
- Generic greetings (“Dear Customer”) rather than your actual name
- Slight branding differences — wrong colors, low-resolution logos, slightly off fonts
Type 2: The Invoice/Package Delivery Email
Subject: “Your package couldn’t be delivered” or “Invoice #47829 attached”
What it looks like: Either a fake shipping notification (FedEx, UPS, DHL, USPS) saying your package couldn’t be delivered and you need to click to reschedule, or a fake invoice for something you didn’t order, designed to provoke you into opening the attachment to dispute it.
The tells:
- You’re not expecting a package, or the tracking number doesn’t match any real order
- The attachment is a .exe, .zip, .docm, or .xlsm file (not a PDF)
- The link goes to a domain unrelated to the courier (fedex-delivery-update.com instead of fedex.com)
- No specific details about what was ordered or from where
Type 3: The “Your Password Is Expiring” Email
Subject: “Action required: Your Microsoft 365 password expires in 3 days”
What it looks like: An email impersonating your employer’s IT department or a major software provider. It says your password is about to expire and you need to click to reset it or you’ll lose access. Often targets corporate users to harvest work credentials.
The tells:
- IT departments don’t send password reset links via email — they use internal portals
- The link goes to a lookalike domain for the login page (microsoft-365-portal.com rather than microsoft.com)
- Often sent to your personal email rather than work email
- Unusual timing — sent on a weekend or outside business hours
Type 4: The CEO/Executive Fraud Email
Subject: “Quick favor needed” from [CEO’s name]
What it looks like: Appears to come from a senior executive at your company — often the CEO. The email is brief and informal, asking you to urgently purchase gift cards, wire money, or provide sensitive information. It often starts with “Are you available?” to confirm you’re there before making the request.
The tells:
- The actual sender email doesn’t match the executive’s work address
- Requests for gift cards or wire transfers — legitimate executives don’t do this over email
- Unusual urgency and a request to keep it confidential
- Replies go to a personal Gmail or Hotmail address, not a company domain
Type 5: The Tax/Government Agency Email
Subject: “IRS Notice: You have a pending tax refund” or “Action required on your account”
What it looks like: An email impersonating the IRS, HMRC, Social Security Administration, or another government agency, claiming you have a refund, owe a payment, or need to verify information to avoid penalties.
The tells:
- The IRS and most government agencies do not contact taxpayers by email for sensitive matters
- Government agencies never request payment via gift cards, wire transfer, or cryptocurrency
- The email address isn’t a government domain (.gov in the US)
- Threats of immediate arrest or suspension of benefits for non-compliance
Type 6: The Fake Job Offer / Recruiter Email
Subject: “Congratulations! You’ve been selected for a remote position — $45/hr”
What it looks like: An unsolicited “recruiter” offers a high-paying remote job after minimal or no interview process, often found via a job board application you don’t remember making. The next step usually asks for a scanned ID, bank details for “payroll setup,” or a purchase of equipment reimbursed later.
The tells:
- An offer of employment with no real interview, extended entirely over chat or email
- Requests for bank account details or a Social Security number before any formal hiring paperwork
- Being asked to buy equipment yourself with a promise of reimbursement — a classic advance-fee structure
- Recruiter’s email domain doesn’t match the company’s real domain (a Gmail address “recruiting” for a Fortune 500 company)
Type 7: The Fake Subscription Renewal Email
Subject: “Your Norton/McAfee/Netflix subscription has renewed for $499.99”
What it looks like: A fake receipt for an expensive annual renewal you supposedly just paid for, with a “customer service” number to call if this was a mistake — designed to trigger a panicked phone call. The follow-up phone call is where the actual scam happens: the “support agent” asks for remote desktop access or payment information to process a “refund.”
The tells:
- You don’t have (or don’t recall having) the subscription referenced
- The amount is unusually large, designed to provoke an immediate reaction
- The email pushes you toward calling a phone number rather than logging into your actual account to check
- Legitimate renewal receipts don’t ask you to call a support line to dispute a charge — you’d use the company’s official app or website
How These Campaigns Are Distributed at Scale
Most phishing emails aren’t hand-crafted for you individually — they’re sent in bulk to millions of addresses harvested from data breaches, purchased marketing lists, or scraped from public sources. Attackers rely on the law of large numbers: even a 0.1% click-through rate on a campaign sent to ten million addresses yields ten thousand potential victims. This is why the same five or six templates above keep circulating for years with only cosmetic changes — they don’t need to fool everyone, just enough people to be profitable. Spear phishing, which targets specific individuals with personalized details, is rarer but significantly more effective per-email because it defeats the generic-template recognition patterns most people have built up.
The Psychology Behind Why These Templates Work
Every example above leans on one or more of the same psychological triggers: urgency (act now or lose access), authority (an official-looking sender you’re conditioned to trust), fear (compromised account, tax penalty, legal threat), or opportunity (a job offer, a refund, a prize). Recognizing which trigger a message is using is often faster than analyzing its technical details — if an email is making you feel rushed, afraid, or unusually excited, that emotional reaction is itself the biggest red flag, regardless of how polished the email looks.
Quick Reference: All 7 Types at a Glance
| Type | Core Trigger | Biggest Tell |
|---|---|---|
| Account Threat | Fear of losing access | Sender domain doesn’t match the real company |
| Package/Invoice | Curiosity / obligation | No matching real order or tracking number |
| Password Expiring | Fear of lockout | IT never sends reset links by email |
| CEO Fraud | Authority / urgency | Reply-to address doesn’t match the executive |
| Tax/Government | Fear of legal consequences | Agencies don’t email about payment via gift cards |
| Fake Job Offer | Financial opportunity | Hiring without a real interview process |
| Subscription Renewal | Shock at a large charge | Pushes you to call a number instead of checking your account |
Training Yourself and Your Family to Spot These
Recognition is a skill that improves with repeated, low-stakes exposure. A few practical habits build it faster than any single article can:
- Review real examples periodically — re-reading a list like this one every few months keeps the patterns fresh, since new variants are mostly cosmetic changes to the same seven templates.
- Talk through borderline cases with family members, especially older relatives who are disproportionately targeted by government-agency and tech-support-style scams.
- Normalize asking “is this legit?” before acting on any unexpected email — there’s no such thing as a question too basic to ask when money or credentials are on the line.
- Use a password manager and 2FA as a safety net — even a successful phishing click on a login page does far less damage if the account also requires a second factor the attacker doesn’t have.
When You’re Not Sure About a Link
Copy the suspicious URL (right-click > Copy Link Address without visiting it) and run it through the Phishing Link Scanner for a full red-flag breakdown and verdict. For any link you’re genuinely uncertain about, going directly to the company’s website by typing the address yourself is always the safer path. If you’ve already clicked, see our guide on what to do after clicking a phishing link for immediate next steps.
Frequently Asked Questions
Q: Why do phishing emails still work if these patterns are so well known?
A: Because attackers only need a tiny fraction of recipients to respond, and campaigns are sent to millions of addresses at essentially zero marginal cost. Recognition patterns help individuals, but the economics still favor attackers at scale.
Q: Are AI-generated phishing emails harder to detect than older ones?
A: Yes, in terms of grammar and tone — AI tools eliminate the awkward phrasing that used to be a reliable tell. Structural red flags (mismatched sender domains, unexpected urgency, requests for credentials or payment) remain just as detectable, though, since those are inherent to the scam itself, not the writing quality.
Q: Can a phishing email come from a real, unhacked company address?
A: Yes, through email spoofing, which forges the “From” header without actually accessing the real account. This is why checking the full sender address (and ideally the message headers) is more reliable than trusting the display name alone.
Q: What should I do with a phishing email after I’ve identified it?
A: Report it using your email provider’s “Report phishing” option, then delete it. Don’t reply, even to say “stop emailing me” — that confirms your address is active and monitored.
Q: Are these examples specific to English-speaking countries?
A: The templates are global — the same account-threat, delivery-notice, and government-agency patterns appear in localized form worldwide, just referencing local banks, postal services, and tax authorities instead.
Related Reading
- How to Tell If a Link Is Phishing Before You Click
- Clicked a Phishing Link? What to Do Right Now
- Smishing vs Phishing vs Vishing: What’s the Difference?
- How to Report a Phishing Email or Website
- Try our free Phishing Link Scanner →
About This Article
Written and reviewed by the Sites Security Services editorial team. Our content is researched using AI-assisted tools and reviewed for accuracy before publication. We are committed to practical, jargon-free cybersecurity guidance for everyday internet users — with no products to sell and no data stored after your session.
Learn about our editorial standards →