Let's think about this for a second
Phishing emails and messages share a lot of common warning signs — a sender address that's slightly off from the official domain (paypal-support.com vs. paypal.com), manufactured urgency ('act within 24 hours or your account will be closed'), grammar and spelling errors, a link whose visible text doesn't match its actual URL when you hover over it, and pressure to click an attachment or link. Banks and government agencies will never ask for your password or card number over email or SMS.
Let's connect this to a real scenario
Before clicking a link, hover your mouse over it and check the actual URL in the status bar (long-press on mobile). Read the sender's email address carefully — the display name might say 'Microsoft Support,' but would you trust it if the actual address is microsoft-support@random-domain.com? If you're unsure, don't click the link in the email — type the official website's URL into your browser yourself instead.
Let's walk through it together
Phishing red flags
-------------------
Sender: support@paypa1.com (domain မှားနေ)
Subject: URGENT — verify within 24 hours
Link text shown: paypal.com
Actual URL: paypal-secure-verify.xyzYou'll be able to analyze an email using three phishing warning signs.Try it in 5 minutes
Pick a promotional or suspicious-looking email from your inbox and hover over the sender address and link URL to check them (don't click).
A quick word of caution
If you accidentally click a phishing link, change your password immediately and check your account activity — don't panic, but act right away.