How to Avoid Phishing and Online Scams
Every day thousands of people lose access to their email, social accounts, banking apps, and money — not because someone “hacked” a sophisticated defence, but because they entered their own credentials in the wrong place. That’s phishing: the most widespread and most profitable way to steal accounts and funds online. The victim doesn’t need to download a virus or be “technically naive”: one email that looks like a bank notification and one fake login page indistinguishable from the real one are enough. The good news is that almost any phishing attempt can be spotted in a minute if you know what to look for and keep a couple of free checking tools handy. This article is a practical breakdown of how to avoid phishing, how to spot scammers, and what to do if the worst has already happened.
How phishing steals accounts and money
The mechanics are almost always the same. First you get a message: an email, an SMS, a messenger push, or even a phone call. It gives you a reason to act right now: “your account is locked,” “a suspicious login was detected,” “your parcel couldn’t be delivered, pay the storage fee,” “you have a refund, confirm your card.” The message contains a link. You click it and land on a page that looks like your bank, a government portal, a marketplace, or a social network. You type in your login, password, sometimes an SMS code — and at that moment the data goes straight to the scammer.
Everything after that happens in seconds. The stolen login and password are automatically replayed on the real site. If you also entered a one-time code, the attacker logs in, changes the password and the linked email, drains the money, or sends the same phishing to your contacts in your name. That’s why the key defence is to never let the data escape in the first place. Everything else is just damage control.
What phishing is
Phishing (a play on “fishing”) is a form of fraud in which an attacker impersonates a trusted organization or person to trick you into handing over confidential data: passwords, confirmation codes, card numbers, personal IDs. The name fits: the scammer casts “bait” (a plausible message) and waits for someone to bite.
Phishing comes in several flavours, but the essence is the same — abusing trust:
- Mass phishing. Identical emails are blasted to millions of addresses, counting on even a fraction of a percent entering their data.
- Spear phishing. The email is crafted personally for you: your name, your job title, references to real colleagues or services. These attacks are more dangerous because they look more convincing.
- Smishing and vishing. The same phishing, but over SMS (smishing) or a voice call (vishing) — for example, a “bank security team” calls and asks you to read out a code.
- Pharming. Hijacking a site at the DNS or router level, so that even the correct address leads to a fake page.
The key thing to understand: phishing exploits not a flaw in software, but human emotions — fear, haste, greed, curiosity. So defending against it is, first and foremost, about attentiveness, and only then about technical tools.
Signs of a phishing email and site
Almost every phishing message carries a few telltale signs. On its own, any one of them might also appear in a legitimate email, but when two or three show up together, it’s almost certainly a scam.
Urgency and pressure
The scammer’s main lever is to make you act without thinking. “Your account will be deleted in 24 hours,” “confirm your details now or money will be withdrawn,” “only 2 spots left in the promo.” Real services very rarely demand that you do something “right now or lose everything.” If you feel rushed and frightened, that’s the first cue to stop.
A suspicious domain and sender address
Scammers register domains that resemble the real ones: paypa1.com (with the digit 1 instead of the letter l), apple-support-id.com, bank0famerica.com, amazon.security-update.com. Look at the address carefully: extra words, hyphens, subdomains, unusual zones (.top, .xyz, .click), letters swapped for lookalike characters. An email “from your bank” sent from an address like [email protected] is already a reason not to trust it.
Typos, broken layout, and an impersonal greeting
Large companies proofread their mailings. Grammatical errors, awkward phrasing, mismatched fonts and a collapsed layout, a “Dear Customer” instead of your name — these are typical traces of phishing, especially when it’s thrown together quickly or machine-translated.
A request for data you should never be asked for
Remember the rule: banks, government agencies, and legitimate services never ask you to send, or to enter via a link in an email, your full card number, CVV, password, or one-time SMS code. If you’re being asked for any of these, it’s a scam, full stop. An SMS code exists solely so that you can confirm an action — never share it with anyone under any circumstances.
Buttons and attachments instead of an address
Emails that, instead of a normal link, show a big “Confirm” button or an attached file (especially .zip, .html, .exe, or a document with macros) call for double caution. The button hides the real address, and the attachment may lead to a fake form or contain malware.
How to check a link and domain BEFORE you click
The single strongest security rule goes like this: verify before you click, and certainly before you enter any data. A few simple habits and free tools handle most of the problem.
First, see where the link actually goes
Don’t click right away. On a computer, hover the cursor over the link (or the button) — the real address appears at the bottom of the browser window or in a tooltip. On a phone, press and hold the link to see the address in a pop-up menu without opening it. Often that’s enough: the link text says “yourbank.com” but it actually points to http://yb-verify.net/login.
Check the domain’s owner and age
Phishing sites are short-lived: they’re registered in batches and abandoned within days. That makes a domain’s age one of the best indicators. A real bank or service has had its domain for years, even decades. The domain from a scam email is often just days or weeks old.
Copy the domain from the link (without visiting the site!) and check it with our Whois tool. It shows who registered the domain and when, in which country, through which registrar. If a domain was created just days ago, hides its owner behind “privacy,” and is pretending to be a major bank — that’s a red flag.
Check whether the domain is on any blacklists
Many phishing and malicious domains are already known to reputation systems and end up on blacklists. Run the suspicious domain or IP through the Blacklist Check: if it shows up in spam and threat databases, the verdict is obvious — close it and don’t come back.
Combining the two checks — a fresh, anonymous domain in Whois plus a presence on blacklists — lets you filter out the vast majority of phishing sites without ever typing a single character into them.
Checking the email sender
The sender address in an email is easy to fake visually, but a genuine email has technical signs of authenticity a scammer cannot forge. These are the SPF, DKIM, and DMARC records — mechanisms that confirm an email really was sent from servers authorized by the sender’s domain.
Parsing email headers by hand is hard, so it’s easier to use the Email Check tool. It analyses the sender’s domain and shows whether SPF, DKIM, and DMARC are configured and how strictly. If an email is supposedly from a major bank, yet the sender’s domain has none of these records or fails the checks — you can’t trust it. This isn’t a hundred-percent guarantee (legitimate mail is sometimes configured sloppily too), but combined with the other signs it helps a lot.
A simple rule: if an email asks you to act on money or passwords, don’t follow its link at all. Open the bank’s or service’s site manually — type the address yourself or use the official app. That way you’re guaranteed to land on the real site, not a copy of it.
Defence: making sure phishing simply doesn’t work
Attentiveness is the foundation, but people get tired and make mistakes. So build your defences such that even an accidental slip doesn’t turn into a catastrophe.
- Enable two-factor authentication (2FA). This is the single most important step. Even if a scammer steals your password, without the second factor they can’t get in. Prefer authenticator apps (or hardware keys) over SMS codes — SMS can be intercepted or coaxed out of you by the same phishing.
- Use a password manager. It not only stores unique, strong passwords for every site, it also acts as anti-phishing protection: a manager autofills a password only on the genuine domain. If you’ve landed on
yourbank-online.cominstead ofyourbank.com, the manager won’t “recognize” the site and won’t offer the credentials — a signal that something is off. - Don’t enter data via links in emails and messages. This is the key behavioural rule. Need your bank? Open the app or type the address by hand. No clicking a “button in an email” to enter your login and password.
- Keep your system and browser updated. Modern browsers have built-in protection against known phishing sites and warn you about them. Fresh updates also close the technical vulnerabilities that some attacks rely on.
- Never share SMS codes with anyone. Not with a “security team,” not with a “bank employee,” not with “support.” Real staff never ask for them.
Don’t forget the network either. Phishing via DNS hijacking or traffic interception on an untrusted network (a café, a hotel) is a real threat. Encrypting your traffic and protecting against DNS tampering make such attacks much harder. We covered protecting your whole home network in detail in How to Secure Your Home Network.
What to do if you already fell for it
If you entered data on a phishing site or told a scammer a code, act fast — every minute counts. Panic doesn’t help; a clear plan does.
- Immediately change the password on the affected service. If you used the same password anywhere else, change it there too (and stop reusing passwords). Do this from a device you know is clean.
- Terminate all active sessions. Most services have a “log out of all devices” button in their security settings — hit it to kick out the attacker if they’ve already logged in.
- Enable 2FA if you hadn’t already. This locks out access even if the password has leaked.
- Contact your bank if cards or money are involved: freeze the card, dispute the transactions. The sooner you act, the better your chances of getting funds back.
- Check your passwords for breaches. Find out whether your email or password has appeared in known breach databases using the Password Breach Check. If a password shows up, it’s compromised and must be changed everywhere it was used.
- Warn your contacts if your account might have sent out messages — so they don’t take the same bait in your name.
A short FAQ
How do I spot a scammer from a single email? Look at the combination of signs: urgency and threats, a suspicious sender domain, a request to enter a password or code via a link, typos. Any one of them on its own is a reason to be wary; two or three together are almost a guarantee of phishing.
A phishing site — how do I check that it’s fake? Without entering anything, copy the domain and check its age and owner via Whois, and its presence on blacklists. A fresh, anonymous domain pretending to be a well-known service is phishing.
Is it dangerous just to click a link without entering anything? The click itself is usually less dangerous than entering data, but there is some risk: the page could exploit a browser vulnerability or push a malicious attachment. It’s better to check the link before clicking and keep your browser updated.
Does a VPN protect against phishing? A VPN encrypts your traffic and protects against DNS hijacking and interception on untrusted networks, which closes off some vectors (pharming, for instance). But a VPN won’t stop you from entering a password on a fake page yourself — that’s what attentiveness, 2FA, and a password manager are for.
What should I do if I already entered my data? Change the password right away, terminate all sessions, enable 2FA, freeze the card if needed, and check the password for breaches.
Guard your data
Phishing works not because scammers are clever, but because they rely on volume and haste. Build the habit of pausing before every link that asks you to “log in” or “confirm,” and almost every attack passes you by. Check domains with Whois and blacklists, senders with the Email Check, and your passwords for breaches. Turn on 2FA and a password manager, never enter data via links in emails — and phishing stops being a threat to you.
Want to harden the network side too — encrypt your traffic and shut down DNS tampering? Try GANVAS VPN: fast servers, DNS-leak protection, and support for your own configs.