Phishing used to be easier to spot because it often looked obviously wrong — awkward phrasing, strange formatting, a sender address that was clearly fake. AI has largely erased that tell; phishing emails written with AI assistance now read as naturally as ones written by a real colleague, and click-through rates on AI-generated phishing have caught up to human-written scams. The old advice needs an update.
What to actually check
- Sender address, not display name. A display name can say "Microsoft Support" while the actual email address is something unrelated. Always check the real address, not just what's shown by default.
- Urgency and pressure. "Act now," "your account will be suspended," "urgent wire transfer needed" — pressure to act immediately, without time to verify, is one of the most consistent phishing signals regardless of how well-written the email is.
- Requests that skip a normal process. If a request bypasses a step your organization normally requires — an approval, a second signature, a verification call — that's worth questioning even if everything else about the email looks legitimate.
- Hover before you click. On desktop, hovering over a link (without clicking) usually shows the actual destination URL. If it doesn't match what the link claims to be, don't click it.
- Unexpected attachments, especially ones that require you to "enable content" or macros to view — a very common malware delivery method.
What's changed with AI-generated phishing specifically
AI removes the grammatical and stylistic inconsistencies that used to be a reliable tell, and it can personalize an email convincingly using publicly available information — a target's job title, recent company news, even writing style scraped from public posts. This means the content itself is a much less reliable signal than it used to be. The behavioral red flags above — urgency, unusual requests, skipped process steps — hold up regardless of how polished the writing is, which is exactly why they matter more now.
What to do when you spot one
Report it through your organization's official channel rather than just deleting it. A single reported phishing email can help IT or security block the sender for everyone else, and it helps build a picture of what campaigns are actively targeting your organization. If you're not sure whether something is phishing, asking is always the right move — nobody in IT will be annoyed by a "is this legitimate?" question, and every security team would much rather answer ten of those than clean up after one successful click.
Red flag quick-check
Before clicking anything or replying with sensitive information, ask: does this create urgency? Does it ask me to skip a normal step? Does the sender address actually match who it claims to be? If any answer is yes, or you're unsure, verify through a separate channel — call the person directly, or check with IT — before acting.