HomeSecurity › How to spot phishing

Padlock over a keyboard, digital security concept

How to tell if a message or link is a scam (phishing)

Updated in 2026 · 5 min read

An SMS from your "bank", an email from the "postal service", or a warning that your account is about to be blocked: scam messages designed to trick you arrive every day. Here are the signs to recognize phishing before clicking, and the steps to follow if you think you've already fallen into the trap.

In this article:

  1. What phishing is, explained simply
  2. Typical signs of a fraudulent SMS or email
  3. How to check a link without clicking it
  4. Why you shouldn't trust an SMS about packages or bank issues
  5. What to do if you've already clicked the link or given your details
  6. How to report a phishing attempt

1. What phishing is, explained simply

Phishing is a scam attempt where someone poses as a company, a bank or an official body to get you to hand over your personal details, your passwords or your card numbers. It usually arrives as a message (email, SMS or WhatsApp) that includes a link: when you click it, it takes you to a website that mimics the real one, where you're asked to "log in" or "verify your details". In reality, everything you type there goes straight to whoever set up the scam.

The name comes from "fishing": the same message is sent to thousands of people at once, knowing some will "bite". You don't need to be a computer expert to fall for it, because these messages are increasingly well made and play on urgency and fear.

2. Typical signs of a fraudulent SMS or email

Although every scam is different, almost all of them share a few traits that, once you learn to spot them, will put you on alert right away:

Important: if a message makes you feel like "I have to do this right now", that's precisely the sign that you should stop and be suspicious. Serious companies don't rush you like that.

3. How to check a link without clicking it

You don't need to click a link to know if it's suspicious. On your phone, press and hold your finger on the link for a few seconds without releasing: you'll see the destination URL appear without opening it. On a computer, just hover your mouse over the link (without clicking) and look at the address shown in the bottom corner of the window.

Once you see the full URL, look at the main domain, meaning the name right before the first slash ("/"). For example, in www.correos.es/seguimiento, the real domain is "correos.es". If instead you see something like "correos-envios-verificacion.com" or a combination of letters and numbers you don't recognize, it's a fake website that's only copying the design of the original.

4. Why you shouldn't trust an SMS about packages or bank issues

Two of the most used hooks are the "package pending delivery" notice and the "problem with your bank account" one. They work because almost everyone has some order on the way or an account at a bank, so the message fits anyone's life.

The golden rule is simple: never click the link in one of these messages without checking it first through another channel you control yourself. If you're worried about a supposed package, go directly to the courier's official website or app by typing the address yourself, or check the tracking number you were given when you bought it. If you're worried about your bank, call the number you have saved for your branch or open the official app from the icon you already have installed, never from the link in the message.

5. What to do if you've already clicked the link or given your details

If you've clicked a suspicious link, or worse, entered your username and password on a website that now raises doubts, don't freeze up: act as soon as possible with these steps.

6. How to report a phishing attempt

Reporting these messages helps get them blocked and stops other people from falling into the same trap. If the phishing arrived by email, most email providers have a "mark as phishing" or "report spam" option directly in the message's menu. If it arrived by SMS, in Spain you can forward it for free to 7726, a number set up so mobile carriers can identify and shut down these scam campaigns.

If you've also suffered a financial loss or had your data stolen, it's a good idea to file a report with the Policía Nacional or the Guardia Civil, who have units specialized in cybercrime, and also notify Spain's National Cybersecurity Institute (INCIBE) through its helpline.

✔ By learning to recognize these signs and always checking the link before clicking, you'll avoid the vast majority of phishing attempts, and if you ever do fall for one, acting quickly limits the damage a lot.
Advertising space (Google AdSense)

Frequently asked questions

How can I check a suspicious link without clicking it?

Press and hold your finger on the link (or hover your mouse over it on a computer) without releasing or clicking: the real destination URL will appear. Look at the main domain, right before the first slash, and check that it exactly matches the company claiming to be the sender.

What should I do if I've already entered my details on a phishing website?

Change that password immediately from a secure device, and also on any other service where you use the same one. If you gave banking details, notify your bank as soon as possible to block the card or account if necessary. Turn on two-step verification everywhere you can.

Do phishing messages only arrive by email?

No, it's just as common to receive them by SMS (known as smishing), through WhatsApp, by phone call or even on social media. The goal is always the same: to get you to click a link or rush you into revealing personal or banking details.

You might also like

Have questions about this article?

Write them in the comments and we'll help you out. To comment you need to register (with email, Google or Facebook). Comments only load if you accept cookies.