12 phishing indicators to check before you click

    Most phishing pages fail at least three of these twelve checks. Blackwall analysts run this list on every intake before the AI Triage score is finalised: you can use the same steps to decide whether to click, click-and-report, or hard-block.

    7 min readUpdated July 6, 2026

    Why a manual pass still matters

    Automated blocklists (Google Safe Browsing, Microsoft SmartScreen, PhishTank) are usually 6-48 hours behind a fresh kit. In that window the attacker collects credentials from anyone who trusts the browser warning alone. A 60-second manual pass closes most of that gap.

    The twelve indicators below are grouped by where the signal lives: sender, domain, transport, content. Any single hit is suspicious. Three or more is almost always a kit.

    Sender signals (1-3)

    1. Display name spoofing. The friendly name says "PayPal Security", the actual address is service@pay-verify-42.tk. Every serious mail client shows both: expand the header before reacting.
    2. Reply-To divergence. The message comes from a plausible domain but Reply-To points to a free-mail box (gmail, gmx, proton). Legitimate brands never do this.
    3. SPF/DKIM/DMARC failure. View the full source; a dmarc=fail or spf=softfail on a brand that publishes strict DMARC is a hard indicator.

    Domain signals (4-7)

    1. Look-alike TLD or hyphenation. micros0ft-login.com, appleid-secure.support, paypal.com.verify-account.io. The brand only owns the last two labels: everything before is attacker-controlled.
    2. Very young domain. WHOIS registration less than 30 days old on a brand that has existed for decades is a red flag. whois, rdap.org or Blackwall's Website Scam Check surface this in one lookup.
    3. Free / abused TLD. .tk, .ml, .gq, .top, .rest, .zip host disproportionate volumes of phishing. Not an automatic verdict, but weigh accordingly.
    4. Suspicious subdomain nesting. login.microsoftonline.com.attacker.io: anything to the left of the registered domain is under attacker control.

    Transport signals (8-9)

    1. Certificate age and issuer. A brand-new Let's Encrypt cert issued yesterday to a supposed enterprise brand is suspicious. Legitimate corporates renew months in advance and often use DigiCert / Sectigo EV.
    2. Redirect chain. Hover the link, then paste into a URL expander (urlex.org, unshorten.it) or fetch with curl -IL. Multi-hop redirects through unrelated domains are a phishing hallmark.

    Content signals (10-12)

    1. Credential-capture form on HTTP POST to an unrelated host. View source and inspect the <form action="…">. If it posts to a different origin than the brand you're seeing, it's a kit.
    2. Urgency + threat language. "Your account will be closed in 24 hours", "unusual sign-in from Nigeria". Standard social-engineering pattern: banks and platforms communicate account issues in-app, not by pushy email.
    3. Broken pixel-perfect clone. Logos slightly off, footer year wrong, links go to #. Kits are copied from screenshots; small inconsistencies always leak.

    You've decided it's phishing: what next?

    Do not delete the message. It's evidence. In order:

    1. Preserve the raw source (.eml) and a full-page screenshot of the landing site: with the URL bar visible.
    2. File with Google Safe Browsing and Microsoft SmartScreen so browser warnings appear within hours.
    3. File with APWG (reportphishing@apwg.org) so brand-side takedown teams are notified.
    4. Submit to Blackwall: the case is opened with the hosting provider and, if unresponsive, escalated to the upstream ASN so the page is actually removed, not just blocked.

    The detailed reporting workflow lives on the Report phishing page.

    Have a URL to report right now?

    Blackwall triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report a phishing site

    Frequently asked questions

    How can I tell if a website is phishing?

    Check the sender address, the registered domain (only the last two labels are owned by the brand), WHOIS age, TLS certificate age, and whether the form action posts to a different origin. Three or more red flags almost always means it is a phishing kit.

    Is a padlock in the browser enough to trust a site?

    No. A padlock only means the connection is encrypted, not that the site is legitimate. Most phishing pages today use free Let's Encrypt certificates and show the padlock.

    Where should I report a phishing URL?

    File with Google Safe Browsing, Microsoft SmartScreen, and APWG (reportphishing@apwg.org), then submit to Blackwall so the hosting provider takes the page offline: not just blocklists it.

    How long does it take to take a phishing page offline?

    Browser blocklists usually activate within hours. A hoster-level takedown via Blackwall typically resolves within 4-48 hours depending on the provider and ASN.

    Should I click a suspicious link to check it?

    No. Never click. Use a URL expander (urlex.org), a sandbox (urlscan.io, Blackwall's Website Scam Check), or curl -IL from a safe environment to inspect the redirect chain and target.

    Cookie Notice

    We use cookies to ensure the functionality of our website. Necessary cookies are required for operation. Optional cookies help us improve our services. For more information, see our Privacy Policy.