Navigation
Type to search pages, tools, and sections…
Phishing is the #1 way attackers steal money and accounts. The good news: every phishing message gives itself away if you know what to look for. Here are the seven signals that work in 2026 — plus what to do if you already clicked.
Phishing emails fake the display name ("PayPal Support") but the actual address is always something off (paypa1-help@gmail.com, support@paypal-billing.net). Hover or tap-and-hold to see the real address before doing anything.
"Your account will be closed in 24 hours", "Suspicious login from Russia", "Last chance to claim your refund". Real companies do not threaten you. Urgency exists to stop you from thinking.
A link can say www.netflix.com but point anywhere. Hover (or long-press on mobile) and check the URL bar that appears. If it does not exactly match the brand's real domain — including the suffix — do not click. When in doubt, paste the URL into the GACS website checker.
No legitimate company — bank, exchange, wallet, government, or support team — will ever ask for your password, seed phrase, or 2FA code. If an email or chat asks for any of these, it is a scam, full stop.
Invoice you did not request, shipping label for a package you did not order, "contract" from a recruiter you never spoke to. PDF and .doc attachments can carry malware. Open in a preview tool, not your normal application.
If the email says your bank, exchange, or service has a problem, do not click the email's link. Open a new tab, type the URL yourself, and log in. Any real notice will be waiting in your account dashboard.
Even after all the above, paste the link into the free GACS website checker. It cross-references 12,000+ confirmed scam sites and live community reports — catching freshly-spun-up phishing pages that browser warnings have not seen yet.
Phishing is when an attacker pretends to be a trusted person or company — your bank, your boss, a delivery service, a friend — to trick you into giving up a password, seed phrase, credit card, or money. It usually arrives by email or SMS but increasingly by chat (WhatsApp, Telegram, LinkedIn DM) and even phone call.
Look at the actual sender address (not the display name) and hover over every link to see where it really points. If either looks even slightly off — a misspelled domain, a sub-domain you don't recognize, a .net instead of .com — assume it is phishing and delete it.
If you only clicked but did not enter anything, close the tab and clear your browser cookies. If you entered a password, change it immediately on the real site and on every other site where you reused it. If you entered crypto credentials or signed a wallet transaction, follow the GACS panic guide at /panic-guide — speed matters in the first 15 minutes.
Yes — phishing over SMS ("smishing") is now more common than email phishing in the US. Same rules apply: do not click the link, do not call the number. If a delivery, bank, or government text feels off, open the company's real app instead.
Crypto phishing often skips the email step entirely — the attacker DMs you on Discord, X, or Telegram with a link to a fake "airdrop", "support form", or "wallet recovery" page. The page asks you to connect a wallet or paste your seed phrase. Treat any wallet-connect prompt from a link in a DM as a scam by default.
Partially. Browser anti-phishing lists (Google Safe Browsing, Microsoft SmartScreen) catch known bad URLs, but the average phishing page lives less than 24 hours — too short for those lists to react. Community-driven checkers like GACS catch fresh sites much faster.
When in doubt, paste the URL into the free GACS website checker before you click.
Open website checkerPhishing isn't limited to emails and texts. Learn how scammers use QR codes to bypass corporate link scanners and what to check before you scan.
Quishing Scams: How to Spot and Avoid QR Code PhishingJournalists, researchers and educators are welcome to cite this page. Use the permalink below or copy a ready-made citation.
https://gacs.app/how-to-spot-phishingGACS. (2026). How to Spot a Phishing Email (and Website) in 2026. GACS — Global Anti-Crime & Safety. Retrieved July 22, 2026, from https://gacs.app/how-to-spot-phishing
"How to Spot a Phishing Email (and Website) in 2026." GACS — Global Anti-Crime & Safety, GACS, 2026, https://gacs.app/how-to-spot-phishing. Accessed July 22, 2026.
GACS. "How to Spot a Phishing Email (and Website) in 2026." GACS — Global Anti-Crime & Safety. Accessed July 22, 2026. https://gacs.app/how-to-spot-phishing.
@misc{gacs_how_to_spot_phishing,
author = {GACS},
title = {How to Spot a Phishing Email (and Website) in 2026},
howpublished = {GACS — Global Anti-Crime & Safety},
year = {2026},
note = {Accessed: July 22, 2026},
url = {https://gacs.app/how-to-spot-phishing}
}Press / media enquiries: About GACS · Editorial policy · Methodology
The 7-point deep-domain check.
Updated checklist for AI-generated storefronts.
One printable checklist for every channel.
Parking meters, restaurant menus, delivery slips.
Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated July 22, 2026
Cite this page: GACS (2026). How To Spot Phishing — GACS. https://gacs.app/how-to-spot-phishing · Record ID GACS-how-to-spot-phishing
Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.