Scams · guide

What is a phishing email example: one, taken apart

By Alberto Gulotta · Updated · 19 min read

What is a phishing email example, in practice, is one specific message the Federal Trade Commission publishes and takes apart. Its three signs are below, along with the one sign that has stopped working and the three places a message actually gets reported.

No security product is named here and nothing is sold. Everything below is quoted from the FTC, CISA and Google’s own Gmail documentation, each read in full on 10 September 2026.

The Federal Trade Commission’s worked example, and the three signs it names The FTC publishes one specific phishing email as a worked example and lists the three things that give it away even though it carries the company’s real logo: the email has a generic greeting, it says the account is on hold because of a billing problem, and it invites you to click a link to update your payment details. The FTC then states the rule underneath all three: legitimate companies will not email or text you a link to update your payment information. THE THREE SIGNS, IN THE FTC’S WORKED EXAMPLE 1 A generic greeting not your name, though the company knows it 2 A billing problem the account is “on hold”, so you must act now 3 A link to pay “update your payment details” The third one is the rule, and it does not need the other two The FTC: “legitimate companies won’t email or text with a link to update your payment information.” The logo in the header is worth nothing at all. AI Tools Primer · figure
The example, the three signs and the closing rule are the Federal Trade Commission’s, from its guide on recognising phishing. Figure drawn by AI Tools Primer.

A worked example, and the three things wrong with it

The Federal Trade Commission publishes one specific message as its example and then lists what gives it away. Its framing is worth keeping, because it starts from the difficulty rather than from the answer: “At first glance, this email looks real, but it’s not. Scammers who send emails like this one are hoping you won’t notice it’s a fake.”

Then the three signs, “even though it looks like it comes from a company you know — and even uses the company’s logo in the header”:

One, the greeting is generic. A company that has your money also has your name, and uses it.

Two, the reason is a billing problem. The FTC’s wording: the email “says your account is on hold because of a billing problem”. That is a story chosen because it produces urgency without alarming you enough to phone anybody.

Three, it invites you to click a link to update your payment details — and this is the one that does not need the other two. The FTC states the rule flatly: “legitimate companies won’t email or text with a link to update your payment information.” That single sentence settles most of these on its own, without any inspection of the message at all.

The FTC also lists the stories these messages tell, each with its own correction attached. They may “say they’ve noticed some suspicious activity or log-in attempts — they haven’t”; “claim there’s a problem with your account or your payment information — there isn’t”; “say you need to confirm some personal or financial information — you don’t”; “include an invoice you don’t recognize — it’s fake”; “say you’re eligible to register for a government refund — it’s a scam”; or “offer a coupon for free stuff — it’s not real”.

What to look at, in order of how much it is worth The display name a message shows is chosen by whoever sent it and establishes nothing. The address behind it is worth a little more, though a lookalike domain defeats a quick glance at it. What the message asks you to do is worth everything, because the request is the part that cannot be disguised: a message asking for a password, a payment detail or a verification code is the same request regardless of how convincingly it is dressed. READ IT BACKWARDS: THE REQUEST FIRST The display name chosen by the sender — worth nothing The actual address worth a look, but a lookalike domain survives a quick one What it asks you to do worth everything — the request cannot be disguised Google’s own list of what a phishing message does Asks for personal or financial information; asks you to click links or download software; impersonates an organisation, or somebody you know. AI Tools Primer · figure
The four behaviours in the bottom band are quoted from Google’s Gmail help page on avoiding and reporting phishing. Figure drawn by AI Tools Primer.

What to look at, and what is worth nothing

Most advice on this subject starts at the top of the message and works down, which is the order that suits the attacker. The useful order is the reverse.

The display name is worth nothing. It is a free text field chosen by whoever sent the message; there is no check on it anywhere in the system. A message can say it is from your bank for the same reason a letter can say it is from your bank: because somebody wrote that.

The address behind it is worth a look, and only just. A lookalike domain survives a glance perfectly well. CISA gives the shape of it: “Incorrect email addresses or links, like amazan.com” — the bold letter is CISA’s own. If you are hunting for a swapped letter you have already spent longer on the message than it deserves.

What it asks you to do is worth everything. The request is the only part that cannot be disguised, because it is the point of sending the message at all. Google’s own list of what these messages do is four items long: they may “Ask for your personal or financial information”, “Ask you to click links or download software”, “Impersonate a reputable organization, like your bank, a social media site you use, or your workplace”, and “Impersonate someone you know, like a family member, friend, or coworker”. Google adds the sentence that closes off the visual approach entirely: such a message may “Look exactly like a message from an organization or person you trust.”

So the check that works is not about the message. It is: does what this is asking me to do make sense as a thing this organisation would ask by email? If the answer is no, nothing about how convincing it looks changes that. And if the answer is unclear, the FTC gives the exit — “contact the company using a phone number or website you know is real — not the information in the email.”

The sign that has stopped working

Bad spelling and clumsy grammar are no longer a reliable tell, and a great deal of advice still in circulation teaches them as the first thing to check. CISA says so plainly: “A common sign used to be poor grammar or misspellings although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”

This matters more than it sounds. Somebody trained on the old sign does not merely miss the new messages — they actively conclude that a well-written message is safe, which is worse than having no rule at all. The signs that survive are the ones on the list above, and the strongest of them is the request rather than the prose.

CISA marks that page as archived content, which its own banner says may not reflect current policy or programs. The observation is quoted here because it is a statement about how these messages read rather than a statement of policy, and because nothing on the first page of results for this question mentions it at all.

Recognise, resist, delete

CISA reduces the whole of it to three words, and the middle one is the one people skip.

Recognise. Its list of signs: “Urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately”; “Requests to send personal and financial information”; “Untrusted shortened URLs”; and the lookalike addresses above.

Resist. In CISA’s words: “If you suspect phishing, resist the temptation to click on links or attachments that seem too good to be true and may be trying to access your personal information. Instead, report the phish to protect yourself and others.”

Delete. And this one has a detail worth having: “Delete the message. Don’t reply or click on any attachment or link, including any ‘unsubscribe’ link. Just delete.” The unsubscribe link is the trap inside the trap, because using it feels like the responsible thing to do and confirms the address is read by a person.

If you are unsure whether a message might be genuine, CISA gives the same exit the FTC does, with the extra case for a message that appears to come from somebody you know: “Use another way to reach the person to confirm whether they contacted you.”

Where a phishing message actually gets reported, by channel The Federal Trade Commission gives three destinations and they are not alternatives to each other. A phishing email is forwarded to the Anti-Phishing Working Group at reportphishing at apwg dot org. A phishing text message is forwarded to SPAM, which is 7726 on the keypad. Either one is also reported to the FTC at ReportFraud dot ftc dot gov. Reporting inside your mail program is a fourth, separate thing: it trains the filter but does not reach any of these. THREE DESTINATIONS, AND THEY ARE NOT ALTERNATIVES An email forward it to the Anti-Phishing Working Group A text message forward it to SPAM — that is 7726 Either of them report the attempt to the FTC at ReportFraud.ftc.gov Clicking “report phishing” in your mail app is a fourth thing It trains that provider’s filter. It does not reach any of the three above. AI Tools Primer · figure
The three destinations and their wording are the FTC’s, from its guide on recognising and avoiding phishing scams. Figure drawn by AI Tools Primer.

How to report a phishing email, in three places

The three destinations are not alternatives to one another — they do different jobs, and most advice on this subject names one and stops.

An email goes to the Anti-Phishing Working Group. The FTC’s instruction: “If you got a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org.” That is an industry body that pools reports across providers, so a message reported there can be blocked for people who do not use your mail provider.

A text message goes to 7726. “If you got a phishing text message, forward it to SPAM (7726).” Those four digits spell the word on a keypad, and the report goes to your own mobile network.

Either of them also goes to the FTC. “Report the phishing attempt to the FTC at ReportFraud.ftc.gov.” That is the one that feeds enforcement rather than filtering.

And reporting inside your mail program is a fourth, separate thing. It is worth doing and it is not a substitute. In Gmail the route Google publishes is four steps: open the message, click More next to Reply, and click Report phishing. Google notes what that does with the message: “When you manually move an email into your Spam folder, Google receives a copy of the email and any attachments”, which it may analyse “to help protect our users from spam and abuse”. It trains that provider’s filter. It does not reach the APWG, your mobile network or the FTC.

If the message arrived in Outlook, the clicks are different and they have their own page, which also explains why reporting does not block the sender.

If you already clicked, or already replied

The FTC splits this into two cases, and they need different things.

If you gave up information. “If you think a scammer has your information, like your Social Security, credit card, or bank account number, go to IdentityTheft.gov. There you’ll see the specific steps to take based on the information that you lost.” That site is run by the FTC and it costs nothing; what it does and the deadlines that start now are set out separately.

If you clicked or opened something. “If you think you clicked on a link or opened an attachment that downloaded harmful software, update your computer’s security software. Then run a scan and remove anything it identifies as a problem.” If the scan finds something, or if the machine has started behaving differently, removing it is a separate job.

And in both cases, if a password was typed into the page the link led to, that password is gone — not just for that site but for every site it was reused on. Changing it there and everywhere else is the actual repair, and how to stop reusing them is the thing that makes the next one of these harmless.

The FTC’s own preventive list is four items and the third is the one that survives a successful phish: “Protect your accounts by using multi-factor authentication… Multi-factor authentication makes it harder for scammers to log in to your accounts if they do get your username and password.” Which is exactly why the next message asks for the code instead — and why a code you did not request is worth understanding before somebody asks you for one.

The check, in the order that works

Read the message backwards. Everything above the request is decoration.

Ask what it wants you to do A link to update payment details settles it. The FTC: “legitimate companies won’t email or text with a link to update your payment information.”
Ignore the display name entirely It is a free text field. Google notes that these messages can “look exactly like a message from an organization or person you trust”.
Do not use good spelling as evidence CISA: in the era of AI “some emails will now have perfect grammar and spelling, so look out for the other signs”.
If in doubt, leave the message Contact the company on a number or address you already have. Never one printed in the message.
Report it, then delete it without replying Email to reportphishing@apwg.org, texts to 7726, either to ReportFraud.ftc.gov. And not even the unsubscribe link.

Where this sits. An email is one of the doors in phishing and scam calls, and the same script arrives through the others. When it arrives as a phone call with a trusted number on the screen, the screen is the part that proves nothing. When it arrives as a text, reducing the volume is a different job from judging one message. And the endpoint of a great many of these is somebody asking you to read out a verification code, which is the one request that is always a scam.

The words for the other doors. The same attack delivered by text is called smishing and by telephone vishing, and the distinction earns its keep in one place only — what you can do afterwards differs by channel. The single most impersonated name in the text version is a delivery service, and the rule that circulates about it is the wrong one: the post office does send texts. And when the message carries no name at all, only digits, who can say who leases them, and who cannot.

Where to start

Four ways into this page.

“Show me a real one.”
The FTC’s worked example — the example
“What do I check first?”
Read it backwards — what to look at
“Where do I report it?”
Three places, three jobs — reporting
“I already clicked.”
The two cases, and what each needs — if you clicked

Reporting, by where it arrived

The clicks differ by program, and none of them reaches the industry bodies on their own.

If one of them worked

A message that succeeded leads to one of these, and they are in the order the damage happens.

Questions people also ask

What is a phishing email example?

The FTC publishes one: an email carrying a real company logo, saying the account is on hold because of a billing problem, and inviting you to click a link to update your payment details. The three signs it lists are the generic greeting, the billing story and that link.

What are the warning signs that an email is a phishing attack?

CISA lists urgent or emotionally appealing language claiming dire consequences, requests to send personal and financial information, untrusted shortened URLs, and lookalike addresses. The strongest single one is the FTC’s rule that legitimate companies do not email a link to update payment information.

Is bad grammar still a sign of phishing?

No longer reliably. CISA: “A common sign used to be poor grammar or misspellings although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”

How to report a phishing email?

Three places, doing three different jobs. The FTC: forward a phishing email to the Anti-Phishing Working Group at reportphishing@apwg.org; forward a phishing text to SPAM (7726); and report the attempt to the FTC at ReportFraud.ftc.gov. Reporting inside your mail program is separate and trains only that provider’s filter.

What happens if you open a phishing email?

Opening one is not the dangerous act; clicking a link, opening an attachment or typing something in is. The FTC’s instruction if you did: update your security software, run a scan, and remove anything it identifies. If information was given up, go to IdentityTheft.gov.

Should I click unsubscribe to stop them?

No. CISA is specific about this one: delete the message and do not reply or click on any attachment or link, “including any ‘unsubscribe’ link”. Using it confirms that a person reads the address.

Not covered here. It does not reproduce a usable phishing message. The example is described in the FTC’s words rather than reprinted, and no link, address or attachment from a real one appears anywhere on the page.

It does not name a security product, a training course or a simulation service. Several of the most prominent pages on this subject are selling one, which is worth knowing while reading them.

And it does not promise you will be able to spot the next one. The signs below are the ones that still work today; the rule about what a message asks you to do is the one that will survive the ones written next year. What holds instead is simple: the example and its three signs are quoted from the FTC with the date read, the point about grammar is quoted from CISA together with the fact that CISA marks that page as archived, the reporting routes are given in full with what each one actually reaches, and no product is named or sold.

Sources

  1. Federal Trade Commission — How To Recognize and Avoid Phishing Scams: the list of stories these messages tell with the correction attached to each, the published worked example and its three signs, the rule that legitimate companies will not email or text a link to update payment information, the four protective measures including multi-factor authentication, the instruction to contact a company on a number or website you know is real, the three reporting destinations, and what to do if you clicked or gave up information — consumer.ftc.gov, read 10 September 2026.
  2. CISA — Recognize and Report Phishing: the three-step Recognize, Resist and Delete framing; the list of common signs including urgent or emotionally appealing language and lookalike addresses; the instruction not to click any link including an unsubscribe link; and the statement that poor grammar and misspellings are no longer a reliable sign because in the era of AI some messages will have perfect grammar and spelling. CISA marks this page as archived content which may not reflect current policy or programs — www.cisa.gov, read 10 September 2026.
  3. Google — Avoid & report phishing emails (Gmail Help): the definition of phishing as an attempt to steal personal information or break into accounts using deceptive messages and sites, the list of what such messages do including impersonating an organisation or somebody you know and looking exactly like a message from a trusted source, the four steps to report a message as phishing, and the note that Google receives a copy of a reported message and its attachments and may analyse them — support.google.com, read 10 September 2026.
  4. Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): that anyone asking for an account verification code is a scammer, which is the request a successful phishing email usually leads to next — consumer.ftc.gov, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026 · last checked 11 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.