Phishing no longer has to look sloppy. FTC and CISA both warn that realistic messages can still be fake.

Good phishing may include:

  • correct logos
  • convincing layout
  • urgent but believable wording
  • a link that almost matches the real one
  • a phone number that reaches the scammer

That is why the safer habit is not “spot the typo.” It is “do not use the link or number they sent.”

A quick example: you get a clean email saying your account is under review and you must sign in now. The safest move is not to click and inspect it more closely. The safest move is to open the site or app yourself.

What to do:

  • Ignore the link and go to the official app or typed address yourself.
  • Be extra suspicious of urgent account warnings.
  • Let the password manager help you notice mismatched sites.

This lesson is part of Email & Online Accounts from Lumoset Foundation, Fort Wayne, Indiana – free, always, with no account and no catch.