Bay Geeks logoTampa Bay IT Support · Since 2004
Bay Geeks Guide · Scams Read This First

How to Spot a Phishing Email or Text

Most of the compromised accounts we clean up started with one message that looked normal enough. Here's how to spot one in the ten seconds you actually have, which scams are making the rounds locally, and what to do if you already clicked.

Nobody breaks in through the front door anymore. They get let in, by a person who was busy, and by an email that was well made. That is not a character flaw; it is the whole business model. The fix is a habit, not a gadget: knowing what to look at, and having a way to check that doesn't involve the message itself.

The Short Version

Pressure, plus a link or attachment, plus a request to act, is the entire pattern. Real organizations rarely need you to do something this minute. When a message makes you feel rushed, stop and check through a route you already trust: the app on your phone, the number on the back of your card, the website you type in yourself. Never the link in the message.

The Five Tells

01

The address behind the name

The display name says Microsoft or your bank. The actual address is a random Gmail or a lookalike domain: micros0ft-support.com, chase-secure.net. On a phone, tap the sender's name to see the real address. On a computer, hover over it.

02

Urgency with a consequence

Account suspended in 24 hours. Unpaid toll. Package on hold. Payroll problem. The deadline exists so you skip the part where you think.

03

The link goes somewhere else

Hover on a computer or press and hold on a phone, and read the address before you tap. Shortened links, QR codes and “View document” buttons hide the destination on purpose.

04

An attachment you weren't expecting

Invoices you didn't order, voicemails as attachments, HTML files, ZIPs and disc images. A vendor you have never emailed with does not open the relationship with a file.

05

It asks for a code, a password, or a gift card

No legitimate company asks you to read back a sign-in code, confirm a password, or pay in gift cards. That request alone ends the conversation.

What's Hitting Tampa Bay Right Now

The messageWhat's really going on
“SunPass: unpaid toll, pay now to avoid a penalty”The toll text that has flooded Florida phones. SunPass does not text payment links. Check your balance in the SunPass app or by typing the address yourself.
“USPS: your package could not be delivered, confirm your address”The post office doesn't text you first. Track a package by typing the tracking number at usps.com.
“Your Norton, McAfee or Geek Squad renewal of $399 has been charged”A refund scam. The phone number leads to a fake support desk that asks for remote access to “process the refund.” See our fake popup guide.
“Duke Energy or TECO: disconnection today, call to pay”Utilities don't disconnect by text on the same day. Call the number printed on your bill.
A text from “your boss” asking for gift cards or a quick favorBusiness email compromise in miniature. Call them on the number you already have. Our wire fraud guide covers the expensive version.
A DocuSign, SharePoint or Dropbox file you weren't expectingThe link opens a fake Microsoft sign-in that captures your password. Ask the sender through a separate channel first.
A flood of sign-in approval prompts on your phoneSomeone already has your password and is hoping you tap Approve to make it stop. Deny every one, then change the password.

How to Check Without Clicking

If You Already Clicked

This happens to careful people. What matters is the next fifteen minutes, not the last one.

What you didDo this now
Clicked the link, then closed itUsually fine. Run a scan and watch for follow-up messages.
Typed your password on the pageTreat the account as taken. Change the password from a different device, add a passkey or authenticator app, sign out everywhere, and check for new forwarding rules. Full order of operations in our breach guide.
Read a code back, or approved a promptSame as above, faster. The attacker is inside right now.
Opened an attachment or ran a fileDisconnect from Wi-Fi, don't sign into anything, and get the machine checked. See virus symptoms.
Paid, or gave card detailsCall the card issuer now. Banks can block a card in minutes and reverse a fresh charge.
Gave remote accessUnplug it, and don't use that machine for banking until it's checked. Assume anything saved in the browser was copied.

Where the Filters and the SOC Come In

Good email filtering stops most of this before it lands, and DMARC on your own domain stops crooks from sending mail as you (see SPF, DKIM and DMARC). No filter catches everything, though, which is why the layer that matters for a business is the one that notices the successful login: an employee's password used from a country they've never been to, or a new inbox rule that hides replies. That is what identity threat detection inside Bay Geeks SOC watches for around the clock, and it is the difference between a phished password and a breach.

Quick Self-Check

QuestionIf “no” or “not sure”...
Do you know how to see the real sender address on your phone?Two-minute lesson, ask us
Does your email have a passkey or authenticator app, so a phished password alone isn't enough?Do this today
At work: would anyone notice a sign-in from overseas at 2 a.m.?Worth a call
FIXED ✓

Catch the Login, Not Just the Email

Filtering stops most phishing. Bay Geeks SOC catches the one that got through, at the moment the stolen password is actually used.

Frequently Asked Questions

Is it dangerous just to open a phishing email?

No. Reading a message is safe in any modern mail app. Clicking links, opening attachments and typing a password are the risks. If you want to hide that you read it, turn off automatic image loading in your mail settings.

Why does the phishing email know my name and where I work?

That comes from old breaches and public sources like LinkedIn and your company website. Personalization is cheap and automated; it is not a sign that someone is targeting you personally. Our three layers guide explains the difference.

Should I reply STOP to scam texts?

No. Any reply confirms a live number and gets you more of them. Forward the text to 7726, block the sender, and delete it.

Are phishing links more dangerous on a phone?

Yes. Phones hide the address bar and the real sender, and a fake login page is harder to tell apart on a small screen. Most stolen passwords are now typed on a phone.

Does Bay Geeks train staff to spot this?

Talk to us. The training that works is short and repeated, not a two-hour course, and it pairs with filtering and passkeys so the day someone slips isn't the day the business gets breached.

Your Password Was in a Breach

The first hour after a breach notice: what to change, in what order, and what to check.

Passkeys, Explained

The sign-in method a fake login page can't steal, and how to set one up.

Fake Virus Popup Scam

Getting the fake Microsoft alert off your screen without calling the number.

Wire Fraud and Fake Invoice Emails

How business email compromise moves real money, and the callback rule that stops it.

Identity Threats 101

Why a stolen password is now the most common way in, and how it's stopped.

Am I Being Hacked?

The three layers of cyber threats, and which one is actually your problem.

📞 727-579-4335  ·  ✉️ support@baygeeks.com  ·  Privacy Policy  ·  Terms of Service

Call Now Schedule