// Anatomy of a phishing email

This email wants to trick you. Find the 7 tells.

A real phishing email leaves clues everywhere. Click on whatever feels off — each hit explains why it is a red flag. Learn to read them like an analyst.

Inbox · 1 new message
🔒
From:PayPal Support <>
Reply-To:
To:you

,

We have detected unusual activity in your account. For your security, we have temporarily limited it. If you do not verify your identity within the next 24 hours, your account will be permanently deleted.

We attach your latest invoice for review:

📎 · 84 KB

© 2024 PayPal. Automated message; do not reply (it would go straight to the attacker).

Red flags

0 / 7
1Urgency and threatUndiscovered…
"24 hours", "suspended", "deleted": fear and a countdown push you to act without thinking. Legitimate messages don't threaten you with a deadline.
2Lookalike domain (typosquatting)Undiscovered…
The display name says "PayPal", but the real domain is paypa1-alerts.com — with a 1 instead of the "l" and not paypal.com. The display name lies; the domain doesn't.
3Different Reply-ToUndiscovered…
The "Reply-To" points to secure-mail-ru.info, another domain (and another country). Your replies would go straight to the attacker's inbox.
4Generic greetingUndiscovered…
"Dear customer": a company that knows you uses your name. A generic greeting gives away a mass mailing to thousands of addresses.
5The link doesn't go where it saysUndiscovered…
The button says "Verify", but the real link is http://paypa1-alerts.com.verify-login[.]ru/secure — the actual domain is verify-login.ru, everything before it is smoke. Hover before you click, always.
6Double-extension attachmentUndiscovered…
Invoice_2024.pdf.exe: it looks like a PDF, but it is an executable. Windows hides the real extension by default, so you see ".pdf" and run malware.
7Typos and misspelled brandUndiscovered…
"Reg{a}rds", "PayePal": typos and a misspelled brand. Legitimate messages are proofread; mass phishing rarely is.
All 7! You now read a phishing email like an analyst. The automated version of this is the Email Triage (.eml): upload a message and it extracts the real route, SPF/DKIM/DMARC and IOCs.

Example email, harmless. No link is real.