Skip to content
Email Tools

guide · Security

How to Identify a Phishing Email in Gmail

Identify a phishing email in Gmail fast: read Gmail's warning banners, check the real sender, hover links, and act on a suspected attack. Sourced, step by step.

Alexis Dollé By Alexis Dollé · ·
How to Identify a Phishing Email in Gmail

Gmail now blocks more than 99.9% of spam, phishing, and malware before it reaches you — roughly 10 million spam emails every minute, by Google’s own count. The trouble is the fraction that gets through: those are the messages crafted well enough to beat an automated filter, which means they are crafted well enough to fool a hurried human too. I get a convincing fake every few weeks, and the ones that land are never the clumsy ones. Here is exactly how to identify a phishing email in Gmail — reading the warning banners, checking the real sender, testing links safely, and knowing what to do the moment something asks for your password.


What Phishing Looks Like in Gmail

Phishing is a message that impersonates someone you trust to trick you into handing over a password, a payment, or personal data. In Gmail it usually arrives as a brand or contact you recognize, a reason to act now, and a link or attachment that does the actual stealing.

The UK’s National Cyber Security Centre defines phishing plainly: “criminals use scam emails, text messages or phone calls to trick their victims”. The goal is always the same — get you to do something you would not do if you stopped to think. In Gmail that “something” is almost always one of three moves: click a link to a fake login page, download an attachment that installs malware, or reply with details you should never send by email.

What makes modern phishing hard is polish. The amateur versions — broken English, a stranger’s address, an obvious scam — Gmail filters out by the millions. The ones that reach your inbox borrow real logos, copy a company’s exact tone, and spoof a sender name you know. So the question is never “does this look professional?” It is “can I verify, independently, that this is real?” The rest of this guide is how you answer that in under a minute, without taking the bait.


Read Gmail’s Warning Banners

Gmail flags risky mail with a colored banner before you read it. A red banner means Gmail strongly suspects phishing and tells you not to click or reply; a yellow banner means it could not verify the sender. A message that still carries a warning has already failed an automated check — trust the banner.

Gmail does a lot of the work for you, and people skip the most obvious signal: the banner across the top of the message. According to Google’s Gmail Help, Gmail shows these warnings when it detects risk:

  • Red banner — likely phishing. Gmail suspects the message is an attempt to steal your information and advises you not to click links, download attachments, or reply. This is the strongest warning Gmail gives. Do not argue with it.
  • Yellow banner — unverified sender. Gmail could not confirm the sender is who they claim to be, often because the address was spoofed or the domain failed authentication. The message might be legitimate, but treat it as guilty until you have verified it another way.
  • Spoofing and unconfirmed-sender notes. Gmail also flags addresses that look similar to ones you know and senders whose identity it cannot confirm — both classic phishing setups.

These banners are not Gmail being cautious for show. Google states that Gmail blocks more than 99.9% of spam, phishing attempts, and malware. A message that made it past that and still earned a warning is, statistically, the dangerous kind. The banner is the cheapest signal you will ever get — read it first, every time, before you read the email itself.


Check the Real Sender

The display name is decoration; the address after the @ sign is the truth. Click or tap the sender name to expand the real address, then look for lookalike domains, public webmail pretending to be a company, and any mismatch between the brand and the domain.

“PayPal Security Team” is a label anyone can type. Underneath it can sit security@paypa1-alerts.com — and that is the part that tells you whether to trust the message. In Gmail, click the sender’s name on desktop (or tap the arrow on mobile) to expand the full address. Then read it like a detective:

  • Lookalike domains. paypa1.com with a number one, microsoft-support.co, amaz0n-billing.net. Attackers register domains a glance mistakes for the real thing.
  • Public webmail wearing a uniform. A bank, courier, or government body emailing you from @gmail.com or @outlook.com is a near-certain fake. Real organizations send from their own domain.
  • Brand-domain mismatch. The email claims to be from your bank, but the domain after the @ has nothing to do with the bank. That gap is the whole scam.

When an address looks plausible but you are unsure, find the company through a channel you already trust — type their URL yourself or use a number from your card, never one from the email. If you need to confirm what else a known-good sender has written you, search Gmail by sender to compare this message against their real history; a sudden change in tone, domain, or formatting is a tell. The address is where most phishing falls apart — it is just easy to skip past the display name and never look.

The fewer bulk senders crowding your inbox, the easier real threats are to spot — a phishing email hidden among forty newsletters is far more likely to get a careless click than one sitting alone. A tool like Leave Me Alone mass-unsubscribes from the lists you never read, shrinking the noise attackers rely on to slip past you and leaving an inbox where the suspicious message actually stands out.

Never trust link text — trust the destination. On desktop, hover over a link and read the real URL in the bottom-left corner; on mobile, long-press to preview it. If the visible text and the actual address disagree, or the domain is misspelled or unfamiliar, do not click.

The link is where a phish does its work, and it is also where it gives itself away. A button that says “Verify your account” can point anywhere. Before you click, make the real destination show itself:

  • On desktop, rest your cursor on the link without clicking. Gmail shows the true URL in the bottom-left corner of the window. Compare it to the visible text.
  • On mobile, press and hold the link until a preview appears, then read the domain before you decide.

What you are checking is simple: does the destination match the sender’s real domain, and is it spelled correctly? Google’s phishing guidance and consumer-protection bodies alike advise verifying where a link goes before following it, because legitimate companies have no reason to disguise it. Two extra rules: shortened links (bit.ly and the like) hide their destination, so treat them with suspicion in unexpected mail, and a login page reached from an email link should never be where you type your password — open the site yourself instead. The same instinct applies to attachments: an unexpected invoice, “shipping label,” or “voicemail” file is a common malware delivery, so confirm with the sender through another channel before opening anything.


The Language of a Phish

Phishing manipulates emotion to short-circuit judgment. The tells are urgency (“act within 24 hours”), threat (“your account will be suspended”), and requests for things no legitimate company asks by email — your password, full card number, or a payment in gift cards.

Beyond the technical signals, phishing has a voice, and once you hear it you cannot unhear it. The script is engineered to make you act before you think:

  • Manufactured urgency. “Your account will be closed in 24 hours.” “Suspicious login — confirm now.” Pressure is the point; it stops you from checking.
  • Threat or fear. Suspension, a fine, a fraud alert, a package held at customs. Fear makes people click.
  • Requests no real company makes. Per Google, Gmail “won’t ever ask you for personal information, like your password, over email” — and neither will your bank. A request for your password, PIN, full card number, or a one-time code is phishing, full stop.
  • Too-good-to-be-true. A refund you are owed, a prize, an inheritance, a crypto windfall. If you did not enter, you did not win.
  • Off-key details. A generic “Dear Customer,” small grammar slips, a logo that is slightly wrong, a reply-to address that differs from the sender.

No single tell is proof — a real company can sound urgent. But urgency plus a request for credentials plus a link to an unfamiliar domain is not a coincidence; it is the recipe. When the emotional pressure and the technical mismatch line up, you are looking at a phish. Trusting that instinct also means not over-reporting normal mail: if a real newsletter keeps annoying you, mark it as not spam and unsubscribe rather than treating every unwanted email as an attack.


Report and Delete

Reporting beats deleting. Open the message, click More (the three dots) next to Reply, and choose Report phishing — Gmail removes it and uses it to protect everyone. Then delete it. Never reply, even to “unsubscribe,” because a reply confirms your address is live.

Deleting a phish protects you; reporting it protects everyone, including future-you. Per Google’s Gmail Help, the steps are:

  1. Open the suspicious message.
  2. Click More (the three-dot menu) next to Reply.
  3. Select Report phishing.

Gmail then removes the message and feeds it back into the filter, sharpening detection of that attack pattern. If Gmail wrongly flagged a genuine email, the same menu offers Report not phishing to correct it. The thing not to do is reply — not to argue, not to ask “is this real?”, not even to use the “unsubscribe” link inside a suspected phish, because any response tells the attacker the address is monitored and worth more attacks. If your inbox is drowning in spam that makes the real threats hard to see, knowing how to report spam consistently and cleaning out your spam folder keeps the signal-to-noise ratio high enough that a genuine phish stands out instead of blending in.


If You Already Clicked

Move fast and contain it. If you entered a password, change it now and turn on two-step verification; change it anywhere you reused it. Scan for malware, watch your accounts for fraud, tell IT if it was a work account, then report the original message.

Falling for a phish is not the disaster — failing to react is. If you clicked a link or, worse, typed something into a fake page, work through this in order:

  • Changed-password first. If you entered a password, change it immediately on the real site, and change it anywhere you reused that password. Reuse is how one phish becomes five compromised accounts.
  • Turn on two-step verification. It blocks an attacker who already has your password. If the account was your Google one, walking through your account-recovery options and securing them is the priority.
  • Scan your device. If you downloaded or opened an attachment, run a malware scan before doing anything else sensitive.
  • Watch for fraud. Check bank statements and your Google account’s recent activity for anything you did not do. If your Gmail itself feels off — strange sent mail, settings you did not change — work through the account-compromised steps right away.
  • Escalate at work. A work account means an organizational risk. Tell your IT or security team immediately; speed limits the blast radius.
  • Report it. Finally, report the original message in Gmail so the attack is logged and others are protected.

The window between clicking and the attacker acting is your advantage. Use it.


Verdict

Identifying a phishing email in Gmail comes down to four habits: read the warning banner, expand the real sender address, hover links before clicking, and treat any request for a password or payment as hostile. Gmail catches 99.9%; these checks cover the rest.

Best for: anyone who wants a repeatable, under-a-minute routine instead of a vague sense of caution. Banner, sender, links, language — run those four checks on anything that asks you to act, and the polished fakes that slip past Gmail’s filters stop being a gamble.

Watch out if: you rely on the absence of a warning as an all-clear. Gmail’s 99.9% is excellent, not perfect, and the most dangerous phishing is precisely the kind built to arrive without a banner. The manual checks are not redundant with the filter — they are what covers the gap the filter leaves.

Read the banner first, trust the address over the display name, never click a link you have not inspected, and report rather than reply. Pair those habits with a quieter inbox, and the rare phish that reaches you meets a reader who is looking for it instead of one who is rushing past.

Alexis Dollé, founder of Email Tools
Alexis Dollé
Founder & Editor

Alexis Dollé, email expert for 10+ years. Founder of Email Tools. I test every email client and utility myself, then write about them the way I’d explain them to a friend — no marketing fluff, no sponsored rankings, every claim sourced.

LinkedIn

Sources & references
  1. Google Gmail Help, “Avoid and report phishing emails” — phishing tactics, “Gmail won’t ever ask you for personal information, like your password, over email,” and the Report phishing steps. Accessed 2026-06-19. support.google.com/mail/answer/8253
  2. Google Gmail Help, “Spot suspicious account activity and phishing warnings” — red/yellow warning banners, spoofed addresses, and unconfirmed senders. Accessed 2026-06-19. support.google.com/mail/answer/1366858
  3. Google Safety, “Gmail keeps your inbox safe” — “Gmail blocks more than 99.9% of spam, phishing attempts, and malware” and “block nearly 10 million spam emails every minute.” Accessed 2026-06-19. safety.google/intl/en_us/gmail
  4. UK National Cyber Security Centre, “Phishing: spot and report scam emails” — “criminals use scam emails, text messages or phone calls to trick their victims.” Accessed 2026-06-19. ncsc.gov.uk/collection/phishing-scams

Frequently Asked Questions

How do I know if an email is phishing in Gmail?

Start with Gmail’s banner: a red warning means it suspects phishing, a yellow one means it could not verify the sender. Then check three things yourself — expand the sender to see the real address (not the display name), hover over links to read where they actually go, and ask whether the message creates urgency or asks for a password or payment. Any one of those is a red flag; two or more is almost certainly phishing.

What does the Gmail phishing warning mean?

Gmail shows a colored banner when it detects risk. A red banner means Gmail strongly suspects the message is a phishing attempt and advises you not to click links, download attachments, or reply. A yellow banner means Gmail could not confirm the sender is who they claim to be, often because the address was spoofed or unverified. Both are signals to slow down and verify before acting.

Can a phishing email get past Gmail’s filters?

Yes, occasionally. Google says Gmail blocks more than 99.9% of spam, phishing, and malware, but 99.9% is not 100% — new and highly targeted attacks can slip through before the filters catch up. That is why the manual checks matter: a clean inbox is not proof a single message is safe, so verify the sender and links on anything that asks for money, credentials, or personal data.

What should I do if I clicked a phishing link in Gmail?

Act fast. If you entered your password, change it immediately and turn on two-step verification. If it was a different account’s password, change that one too and anywhere you reused it. Scan your device for malware, watch your bank and Google account for unfamiliar activity, and if it was a work account, tell your IT or security team right away. Then report the original message in Gmail so others are protected.

How do I report a phishing email in Gmail?

Open the message, click More (the three dots) next to Reply, and choose Report phishing. Gmail removes the message and uses it to improve detection for everyone. If Gmail wrongly flagged a real email, open it and choose Report not phishing through the same menu. Reporting is better than simply deleting, because it trains the filter against that attack.

Why am I getting so many phishing emails in Gmail?

Usually because your address has been exposed in a data breach or scraped from a public page, putting it on lists that attackers buy and reuse. Reporting phishing trains Gmail to catch more of it, and cutting your overall inbox noise helps the real threats stand out — unsubscribing from bulk senders and cleaning your spam folder both shrink the surface attackers hide in.


Related: Steps to take if your Gmail account is compromised — what to do after a successful attack. How to report spam in Gmail — keep the filter sharp and the inbox quiet. Check your Gmail spam folder — where flagged phishing lands.