Scams · guide
What is a phishing email example: one, taken apart
By Alberto Gulotta · Updated · 19 min read
What is a phishing email example, in practice, is one specific message the Federal Trade Commission publishes and takes apart. Its three signs are below, along with the one sign that has stopped working and the three places a message actually gets reported.
No security product is named here and nothing is sold. Everything below is quoted from the FTC, CISA and Google’s own Gmail documentation, each read in full on 10 September 2026.
A worked example, and the three things wrong with it
The Federal Trade Commission publishes one specific message as its example and then lists what gives it away. Its framing is worth keeping, because it starts from the difficulty rather than from the answer: “At first glance, this email looks real, but it’s not. Scammers who send emails like this one are hoping you won’t notice it’s a fake.”
Then the three signs, “even though it looks like it comes from a company you know — and even uses the company’s logo in the header”:
One, the greeting is generic. A company that has your money also has your name, and uses it.
Two, the reason is a billing problem. The FTC’s wording: the email “says your account is on hold because of a billing problem”. That is a story chosen because it produces urgency without alarming you enough to phone anybody.
Three, it invites you to click a link to update your payment details — and this is the one that does not need the other two. The FTC states the rule flatly: “legitimate companies won’t email or text with a link to update your payment information.” That single sentence settles most of these on its own, without any inspection of the message at all.
The FTC also lists the stories these messages tell, each with its own correction attached. They may “say they’ve noticed some suspicious activity or log-in attempts — they haven’t”; “claim there’s a problem with your account or your payment information — there isn’t”; “say you need to confirm some personal or financial information — you don’t”; “include an invoice you don’t recognize — it’s fake”; “say you’re eligible to register for a government refund — it’s a scam”; or “offer a coupon for free stuff — it’s not real”.
What to look at, and what is worth nothing
Most advice on this subject starts at the top of the message and works down, which is the order that suits the attacker. The useful order is the reverse.
The display name is worth nothing. It is a free text field chosen by whoever sent the message; there is no check on it anywhere in the system. A message can say it is from your bank for the same reason a letter can say it is from your bank: because somebody wrote that.
The address behind it is worth a look, and only just. A lookalike domain survives a glance perfectly well. CISA gives the shape of it: “Incorrect email addresses or links, like amazan.com” — the bold letter is CISA’s own. If you are hunting for a swapped letter you have already spent longer on the message than it deserves.
What it asks you to do is worth everything. The request is the only part that cannot be disguised, because it is the point of sending the message at all. Google’s own list of what these messages do is four items long: they may “Ask for your personal or financial information”, “Ask you to click links or download software”, “Impersonate a reputable organization, like your bank, a social media site you use, or your workplace”, and “Impersonate someone you know, like a family member, friend, or coworker”. Google adds the sentence that closes off the visual approach entirely: such a message may “Look exactly like a message from an organization or person you trust.”
So the check that works is not about the message. It is: does what this is asking me to do make sense as a thing this organisation would ask by email? If the answer is no, nothing about how convincing it looks changes that. And if the answer is unclear, the FTC gives the exit — “contact the company using a phone number or website you know is real — not the information in the email.”
The sign that has stopped working
Bad spelling and clumsy grammar are no longer a reliable tell, and a great deal of advice still in circulation teaches them as the first thing to check. CISA says so plainly: “A common sign used to be poor grammar or misspellings although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”
This matters more than it sounds. Somebody trained on the old sign does not merely miss the new messages — they actively conclude that a well-written message is safe, which is worse than having no rule at all. The signs that survive are the ones on the list above, and the strongest of them is the request rather than the prose.
CISA marks that page as archived content, which its own banner says may not reflect current policy or programs. The observation is quoted here because it is a statement about how these messages read rather than a statement of policy, and because nothing on the first page of results for this question mentions it at all.
Recognise, resist, delete
CISA reduces the whole of it to three words, and the middle one is the one people skip.
Recognise. Its list of signs: “Urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately”; “Requests to send personal and financial information”; “Untrusted shortened URLs”; and the lookalike addresses above.
Resist. In CISA’s words: “If you suspect phishing, resist the temptation to click on links or attachments that seem too good to be true and may be trying to access your personal information. Instead, report the phish to protect yourself and others.”
Delete. And this one has a detail worth having: “Delete the message. Don’t reply or click on any attachment or link, including any ‘unsubscribe’ link. Just delete.” The unsubscribe link is the trap inside the trap, because using it feels like the responsible thing to do and confirms the address is read by a person.
If you are unsure whether a message might be genuine, CISA gives the same exit the FTC does, with the extra case for a message that appears to come from somebody you know: “Use another way to reach the person to confirm whether they contacted you.”
How to report a phishing email, in three places
The three destinations are not alternatives to one another — they do different jobs, and most advice on this subject names one and stops.
An email goes to the Anti-Phishing Working Group. The FTC’s instruction: “If you got a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org.” That is an industry body that pools reports across providers, so a message reported there can be blocked for people who do not use your mail provider.
A text message goes to 7726. “If you got a phishing text message, forward it to SPAM (7726).” Those four digits spell the word on a keypad, and the report goes to your own mobile network.
Either of them also goes to the FTC. “Report the phishing attempt to the FTC at ReportFraud.ftc.gov.” That is the one that feeds enforcement rather than filtering.
And reporting inside your mail program is a fourth, separate thing. It is worth doing and it is not a substitute. In Gmail the route Google publishes is four steps: open the message, click More next to Reply, and click Report phishing. Google notes what that does with the message: “When you manually move an email into your Spam folder, Google receives a copy of the email and any attachments”, which it may analyse “to help protect our users from spam and abuse”. It trains that provider’s filter. It does not reach the APWG, your mobile network or the FTC.
If the message arrived in Outlook, the clicks are different and they have their own page, which also explains why reporting does not block the sender.
If you already clicked, or already replied
The FTC splits this into two cases, and they need different things.
If you gave up information. “If you think a scammer has your information, like your Social Security, credit card, or bank account number, go to IdentityTheft.gov. There you’ll see the specific steps to take based on the information that you lost.” That site is run by the FTC and it costs nothing; what it does and the deadlines that start now are set out separately.
If you clicked or opened something. “If you think you clicked on a link or opened an attachment that downloaded harmful software, update your computer’s security software. Then run a scan and remove anything it identifies as a problem.” If the scan finds something, or if the machine has started behaving differently, removing it is a separate job.
And in both cases, if a password was typed into the page the link led to, that password is gone — not just for that site but for every site it was reused on. Changing it there and everywhere else is the actual repair, and how to stop reusing them is the thing that makes the next one of these harmless.
The FTC’s own preventive list is four items and the third is the one that survives a successful phish: “Protect your accounts by using multi-factor authentication… Multi-factor authentication makes it harder for scammers to log in to your accounts if they do get your username and password.” Which is exactly why the next message asks for the code instead — and why a code you did not request is worth understanding before somebody asks you for one.
The check, in the order that works
Read the message backwards. Everything above the request is decoration.
Where this sits. An email is one of the doors in phishing and scam calls, and the same script arrives through the others. When it arrives as a phone call with a trusted number on the screen, the screen is the part that proves nothing. When it arrives as a text, reducing the volume is a different job from judging one message. And the endpoint of a great many of these is somebody asking you to read out a verification code, which is the one request that is always a scam.
The words for the other doors. The same attack delivered by text is called smishing and by telephone vishing, and the distinction earns its keep in one place only — what you can do afterwards differs by channel. The single most impersonated name in the text version is a delivery service, and the rule that circulates about it is the wrong one: the post office does send texts. And when the message carries no name at all, only digits, who can say who leases them, and who cannot.
Where to start
Four ways into this page.
- “Show me a real one.”
- The FTC’s worked example — the example
- “What do I check first?”
- Read it backwards — what to look at
- “Where do I report it?”
- Three places, three jobs — reporting
- “I already clicked.”
- The two cases, and what each needs — if you clicked
Reporting, by where it arrived
The clicks differ by program, and none of them reaches the industry bodies on their own.
If one of them worked
A message that succeeded leads to one of these, and they are in the order the damage happens.
Questions people also ask
What is a phishing email example?
The FTC publishes one: an email carrying a real company logo, saying the account is on hold because of a billing problem, and inviting you to click a link to update your payment details. The three signs it lists are the generic greeting, the billing story and that link.
What are the warning signs that an email is a phishing attack?
CISA lists urgent or emotionally appealing language claiming dire consequences, requests to send personal and financial information, untrusted shortened URLs, and lookalike addresses. The strongest single one is the FTC’s rule that legitimate companies do not email a link to update payment information.
Is bad grammar still a sign of phishing?
No longer reliably. CISA: “A common sign used to be poor grammar or misspellings although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”
How to report a phishing email?
Three places, doing three different jobs. The FTC: forward a phishing email to the Anti-Phishing Working Group at reportphishing@apwg.org; forward a phishing text to SPAM (7726); and report the attempt to the FTC at ReportFraud.ftc.gov. Reporting inside your mail program is separate and trains only that provider’s filter.
What happens if you open a phishing email?
Opening one is not the dangerous act; clicking a link, opening an attachment or typing something in is. The FTC’s instruction if you did: update your security software, run a scan, and remove anything it identifies. If information was given up, go to IdentityTheft.gov.
Should I click unsubscribe to stop them?
No. CISA is specific about this one: delete the message and do not reply or click on any attachment or link, “including any ‘unsubscribe’ link”. Using it confirms that a person reads the address.
Not covered here. It does not reproduce a usable phishing message. The example is described in the FTC’s words rather than reprinted, and no link, address or attachment from a real one appears anywhere on the page.
It does not name a security product, a training course or a simulation service. Several of the most prominent pages on this subject are selling one, which is worth knowing while reading them.
And it does not promise you will be able to spot the next one. The signs below are the ones that still work today; the rule about what a message asks you to do is the one that will survive the ones written next year. What holds instead is simple: the example and its three signs are quoted from the FTC with the date read, the point about grammar is quoted from CISA together with the fact that CISA marks that page as archived, the reporting routes are given in full with what each one actually reaches, and no product is named or sold.
Sources
- Federal Trade Commission — How To Recognize and Avoid Phishing Scams: the list of stories these messages tell with the correction attached to each, the published worked example and its three signs, the rule that legitimate companies will not email or text a link to update payment information, the four protective measures including multi-factor authentication, the instruction to contact a company on a number or website you know is real, the three reporting destinations, and what to do if you clicked or gave up information — consumer.ftc.gov, read 10 September 2026.
- CISA — Recognize and Report Phishing: the three-step Recognize, Resist and Delete framing; the list of common signs including urgent or emotionally appealing language and lookalike addresses; the instruction not to click any link including an unsubscribe link; and the statement that poor grammar and misspellings are no longer a reliable sign because in the era of AI some messages will have perfect grammar and spelling. CISA marks this page as archived content which may not reflect current policy or programs — www.cisa.gov, read 10 September 2026.
- Google — Avoid & report phishing emails (Gmail Help): the definition of phishing as an attempt to steal personal information or break into accounts using deceptive messages and sites, the list of what such messages do including impersonating an organisation or somebody you know and looking exactly like a message from a trusted source, the four steps to report a message as phishing, and the note that Google receives a copy of a reported message and its attachments and may analyse them — support.google.com, read 10 September 2026.
- Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): that anyone asking for an account verification code is a scammer, which is the request a successful phishing email usually leads to next — consumer.ftc.gov, read 10 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 10 September 2026 · last checked 11 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.