Phishing red flags: what actually deserves attention
The phishing warning signs that genuinely matter, what each one means in practice, and why no single red flag should decide whether an email is safe on its own.
Choose the explanation that suits you. Both versions cover the same topic.
1. Credential and account-access lures
Unexpected sign-in, password-expiry, MFA, device-code or OAuth-consent requests deserve verification, especially when the destination is unfamiliar or the message claims immediate account consequences.
2. Payment diversion and business email compromise
Invoice changes, new bank details, gift-card requests, payroll changes and executive-style urgency can cause immediate financial loss. Verify them through an existing trusted channel before acting.
3. Extortion and blackmail
Sextortion and blackmail emails often claim to possess private video, browsing history or compromising material, then demand cryptocurrency under a deadline. The claims are commonly fabricated, but the demand itself is high-risk malicious behaviour.
4. Malicious or multi-stage attachments
PDF, Office, archive, HTML, calendar and nested-email files can be used to move the victim to the next stage. Password protection, executable content, extension mismatch, macros and embedded links all change the investigation.
5. Deceptive destinations and redirect chains
A visible link can hide another host, a legitimate cloud service can be abused as an intermediate step, and shortened or wrapped URLs can obscure the eventual destination. Domain structure and context both matter.
6. Identity incoherence
Recognisable display names paired with unrelated or randomly generated sender, Reply-To or Return-Path domains are useful warning signs, particularly when the message also has missing authentication, high spam classification or risky calls to action.
7. QR, CAPTCHA and ClickFix-style lures
Modern campaigns may move the interaction away from an obvious link using QR codes, fake CAPTCHA steps or instructions to copy/run commands. Static email analysis can identify setup clues, while the final landing page may require isolated visual investigation.
8. Why context matters
Legitimate marketing can contain urgency, tracking links, bulk-mail headers and third-party sending infrastructure. Jatzo therefore combines signals instead of declaring one keyword, one provider or one authentication result to be proof.
Modern access and execution lures
Device-code phishing and OAuth-consent abuse can use legitimate service domains. Look at the requested permission or code workflow. ClickFix-style instructions ask a user to execute commands; the trusted appearance of the page is not sufficient.
Static inspection has boundaries
QR decoding currently covers supported attached or inline raster images. It does not fetch remote images or render every document page. Encrypted archives, nested content and resource limits should appear as inspection limitations. Live reputation for extracted QR URLs is part of the paid plans.
