Phishing email examples: seven fakes, and what gives each one away
Seven phishing emails of the kinds the FTC warns about: the sign-in alert, the payment problem, the "confirm your details" request, the fake invoice, the delivery fee, the government refund and the free reward. Each one is marked with what gives it away.
Seven stories, told over and over
Phishing emails change their logos and their wording, but they keep telling the same few stories. The FTC lists seven of them. Below is one example of each, written by us for this page.
Everything in these examples is made up. Every address ends in .example, a name set aside for examples by the internet's standards (RFC 2606), so it can't belong to any real company or person. The links in the boxes can't be clicked; each one shows where it would go instead.
One thing before you start: don't count on spelling mistakes. CISA points out that phishing written with AI tools can have perfect spelling and grammar. The signs below are about what an email wants you to do, not how well it is written.
If you have a real email in front of you right now, the checklist in is this email a scam? is the faster read.
1. "We noticed a sign-in attempt"
- From
- Account Security <[email protected]>
- To
- you
- Subject
- Unusual sign-in attempt blocked
Dear user,
We blocked a sign-in to your account from a new device (Windows, Chrome).
If this wasn't you, secure your account now or it may be suspended.
Secure my account → https://account-verify.example/login
Account Security Team
What gives it away
- The story itself. The FTC's words: scammers "say they've noticed some suspicious activity or log-in attempts — they haven't."
- "Dear user." A generic greeting is one of the signs the FTC marks on its own phishing example.
- The sender.
account-verify.exampleis not the address of the company whose account it is talking about. - The button leads to a sign-in page. Don't type a password on a page an email sent you to.
To check, open the app or type the company's address yourself, and look at its security or recent-activity page. That is the FTC's advice for any message that might be real: contact the company "using a phone number or website you know is real — not the information in the email."
2. "There's a problem with your payment"
- From
- Billing Department <[email protected]>
- To
- you
- Subject
- Your membership is on hold
Hi,
We couldn't process your last payment, so your membership is on hold.
Update your payment details within 24 hours to keep watching.
Update payment → https://stream-account.example/billing
What gives it away
- The story. Scammers "claim there's a problem with your account or your payment information — there isn't" (FTC).
- A link to update your card. The FTC's rule for this one: "legitimate companies won't email or text with a link to update your payment information."
- The deadline. CISA lists urgent language as a sign, "especially messages that claim dire consequences for not responding immediately."
The FTC's own real-world example of this email even carried the real company's logo. Swap in any subscription you pay for; the pattern is the same.
3. "Please confirm your details"
- From
- Customer Verification <[email protected]>
- To
- you
- Subject
- Action required: confirm your information
Dear customer,
As part of a routine security review, we need you to confirm your identity.
Please reply with your full name, date of birth, card number and the last four digits of your Social Security number.
Accounts that are not verified within 48 hours will be closed.
What gives it away
- What it asks for. CISA names "requests to send personal and financial information" as a sign. The FTC: scammers "say you need to confirm some personal or financial information — you don't."
- Reply with your details. A card number and part of your Social Security number, sent by email, to an address you've never written to.
- The threat. Closed in 48 hours, which is the "dire consequences" CISA describes.
4. An invoice you don't recognize
- From
- Renewal Center <[email protected]>
- To
- you
- Subject
- Invoice #PP-40718: your plan has been renewed
Thank you for your purchase.
Product: Total Device Protection, 3 years
Amount charged: $399.99
If you did not authorize this charge, call our refund team within 24 hours:
1-800-555-0137
What gives it away
- You never bought it. The FTC: scammers "include an invoice you don't recognize — it's fake."
- The only way out is their phone number. The email wants you to call, so the conversation happens on their terms.
- The deadline, again.
Don't call the number in the email. CISA's advice for a message that might be real: "don't click on any link or call any number in the message." To check a charge, look at your bank or card statement, and reach the company through contact details you looked up yourself. There's a longer walk-through of this one in the Geek Squad scam email.
5. "Click here to pay"
- From
- Parcel Delivery <[email protected]>
- To
- you
- Subject
- Your package could not be delivered
We attempted to deliver your package today but no one was available.
To schedule a new delivery, pay the $1.99 redelivery fee.
Schedule delivery → https://sh.example/p7Qx2
What gives it away
- A link to pay. Scammers "want you to click on a link to make a payment — but the link has malware" (FTC).
- A shortened link. CISA lists "untrusted shortened URLs" as a sign:
sh.example/p7Qx2tells you nothing about where it leads. - A package you weren't expecting, and no tracking number you could check yourself.
6. "You're eligible for a government refund"
- From
- IRS Refund Office <[email protected]>
- To
- you
- Subject
- You are eligible for a tax refund of $1,284.50
Our records show you overpaid your taxes.
Submit your bank details within 48 hours to receive your refund.
Claim my refund → https://irs-gov-refund.example/claim
What gives it away
- The story. Scammers "say you're eligible to register for a government refund — it's a scam" (FTC).
- It came by email at all. The IRS says: "We never email without your permission."
- A deadline on money you're owed. 48 hours to claim a refund is the same pressure as every other example here.
Forward fake IRS emails to [email protected], the address the IRS gives for them.
7. "A reward for you"
- From
- Rewards Team <[email protected]>
- To
- you
- Subject
- Congratulations! Your $100 reward is waiting
You've been selected for a $100 store reward.
Answer 3 quick questions, then pay $4.95 shipping to receive your card.
Claim reward → https://loyal-shopper.example/survey
What gives it away
- Free stuff. Scammers "offer a coupon for free stuff — it's not real" (FTC).
- You never entered anything. No contest, no sign-up, and yet you were "selected".
- "Just pay shipping." A $4.95 fee still means typing your card number into their page.
What all seven have in common
Put them side by side and the same three things show up every time:
- A story that wants you to act now: a block, a hold, a deadline, a prize that expires.
- A way to act that the email gives you: its link, its button, its phone number, a reply.
- A request for something only you should have: a password, a card number, your bank details, your Social Security number.
The fix is the same for all of them: don't use anything in the email to check the email. Open the app, type the company's address yourself, or call a number you found on your own. The FTC and CISA both give that same advice.
Check a link without opening it
If you want to know where a link in an email really goes, paste it into our checker instead of clicking it. We open it in a browser that isn't yours and tell you where it really goes, how old the site is, and whether it asks for a login or a payment. How to read any address yourself is in is this link safe?
If you already clicked, replied or paid
- You typed a password on a page from the email: change it straight away, anywhere you used it. The FTC's advice is a new, strong password and two-step verification.
- You sent personal information: go to IdentityTheft.gov, the FTC's site for exactly this, for steps that fit what you gave away.
- You downloaded or opened something: the FTC's advice is to update your security software and run a scan.
- You paid: contact your bank or card company straight away. The FTC's full list of next steps, by how you paid, is at What To Do if You Were Scammed.
Report it, then delete it
- forward the email to [email protected] (the FTC's address for phishing emails), and a fake IRS email to [email protected]
- report it to the FTC at ReportFraud.ftc.gov
- use your mail app's own report button: how to report a phishing email shows where it is in Outlook, Gmail and Apple Mail
Then, as CISA puts it, delete it without replying or clicking any links, including the unsubscribe link.
Sources: FTC: How To Recognize and Avoid Phishing Scams (September 2022) · CISA: Recognize and Report Phishing · IRS: Report phishing · FTC: What To Do if You Were Scammed · RFC 2606: Reserved Top Level DNS Names
Check a link before you click it
Paste the link or scan the QR code. We open it for you and show the real destination, the redirects on the way, and whether anyone has reported the seller behind it.
Check a linkMore articles
- QR codes Quishing: how QR code scams work, and how to check a code before you scan it Quishing is phishing through a QR code: on a parking meter, in an email, on a flyer or a package you never ordered. How each version works, what the FTC and FBI advise, and how to see where a code goes first.
- Scams Geek Squad scam emails: the fake renewal invoice, and how to check it An email says you will be charged hundreds of dollars to renew Geek Squad and gives a number to call. Here is what happens if you call, how to check the charge safely with Best Buy, the same trick dressed as McAfee or Norton, and what to do if you already called.
- Scams How to report a phishing email in Outlook, Gmail and iPhone Mail The exact buttons to report a phishing email in Outlook, Gmail and Apple Mail, where else to forward it (APWG, the company being faked, the FTC), and what reporting does and does not do.