Cybersecurity

How to Spot a Phishing Email — 7 Warning Signs

QuickFixIT Pro · Edmonton · September 2026 · 6 min read

Phishing emails are the single most common way that hackers steal passwords, install malware, and break into business accounts. The Canadian Anti-Fraud Centre received over 58,000 phishing reports in 2024 — and that's only the ones people actually reported. The real number is much higher.

The good news: once you know what to look for, phishing emails are usually easy to spot. Here are the 7 warning signs we tell every Edmonton client to watch for.

1. The Sender's Email Address Doesn't Match the Company

This is the most reliable sign. The display name might say "Microsoft Support" or "Canada Revenue Agency," but look at the actual email address. A legitimate email from Microsoft will come from a @microsoft.com domain — not support-microsoft@gmail.com, microsoft-helpdesk@outlook.com, or any other variation.

Always click on the sender name to reveal the full email address before trusting any message.

Quick check: Hover over any links in the email before clicking. The real destination URL appears in the bottom-left of your browser or mail client. If the URL looks suspicious or doesn't match the company, don't click.

2. There's a Sense of Urgency or Threat

Phishing emails almost always try to pressure you into acting fast. Common tactics include:

Legitimate companies rarely send emails demanding instant action under threat of losing access. If you feel rushed, that's a red flag. Go directly to the company's website in a new browser tab instead of clicking the email link.

3. The Email Asks for Personal Information

No legitimate bank, government agency, or tech company will ever ask you to confirm your password, SIN, credit card number, or banking details by email. Ever. If an email asks for this information — or directs you to a page that asks for it — treat it as a phishing attempt.

CRA scam alert: The Canada Revenue Agency will never email you asking for personal information, payment by gift card, or wire transfer. If you receive an email claiming to be from the CRA asking for any of this, it's a scam.

4. Poor Spelling and Grammar

Many phishing emails originate from outside Canada and contain obvious spelling mistakes, awkward phrasing, or sentences that don't quite make sense. Phrases like "Dear Valued Customer" instead of your actual name are also common. Professional companies proofread their communications — sloppy writing is a warning sign.

Note: AI has made some phishing emails much more polished. Don't rely on bad spelling alone to decide whether an email is safe.

5. The Link Destination Doesn't Match the Brand

Phishing emails often link to websites that look identical to the real thing — same logo, same layout, same colours — but the URL is different. Common tricks include:

The real domain is the part immediately before the first single slash. In paypal.com.verify-account.net/login, the real domain is verify-account.net — not PayPal.

6. There's an Unexpected Attachment

If you weren't expecting a file, be very careful before opening any attachment — especially .zip, .exe, .docm, or .xlsm files. These can execute code as soon as they're opened. Even a PDF from an unknown sender can contain malicious scripts.

If a colleague or client sends you an unexpected attachment, call or text them to confirm before opening it. Email accounts get compromised, and the message may not actually be from them.

7. Something Just Feels Off

Trust your instincts. If an email makes you feel uneasy — even if you can't pinpoint exactly why — don't click anything. Go directly to the website in question by typing the URL yourself, or call the company using a number from their official website (not the number in the suspicious email).

If you already clicked: Disconnect from the internet immediately, change the password for any account you entered credentials into (from a different device if possible), and enable multi-factor authentication. If you think malware was installed, contact a professional before using the device for anything sensitive.

How to Report Phishing in Canada

You can report phishing emails to the Canadian Anti-Fraud Centre at antifraudcentre.ca or by calling 1-888-495-8501. If the email impersonates the CRA, report it to canada.ca/cra-security.

If you're a business, you should also report it to your IT team or provider so they can block the sender and alert other staff.

Think you may have clicked a phishing link?

We offer professional virus and malware removal in Edmonton. We'll scan your device, remove any threats, and make sure your accounts are secure. No fix, no fee.

Book a Free Diagnostic

Les courriels d'hameçonnage (phishing) sont de loin la méthode la plus courante utilisée par les pirates pour voler des mots de passe, installer des logiciels malveillants et accéder à des comptes d'entreprise. Le Centre antifraude du Canada a reçu plus de 58 000 signalements d'hameçonnage en 2024 — et ce ne sont que les cas signalés.

La bonne nouvelle : une fois que vous savez quoi chercher, ces courriels sont généralement faciles à détecter. Voici les 7 signes que nous enseignons à tous nos clients d'Edmonton.

1. L'adresse courriel de l'expéditeur ne correspond pas à l'entreprise

C'est le signe le plus fiable. Le nom affiché peut dire « Support Microsoft » ou « Agence du revenu du Canada », mais regardez l'adresse réelle. Un vrai courriel de Microsoft viendra d'un domaine @microsoft.com — pas de support-microsoft@gmail.com ou autre variante.

Cliquez toujours sur le nom de l'expéditeur pour voir l'adresse complète avant de faire confiance à un message.

Vérification rapide : Survolez les liens avec votre souris avant de cliquer. L'URL de destination s'affiche en bas à gauche de votre navigateur. Si elle semble douteuse, ne cliquez pas.

2. Il y a un sentiment d'urgence ou une menace

Les courriels d'hameçonnage tentent presque toujours de vous pousser à agir rapidement. Exemples courants :

Les entreprises légitimes envoient rarement des courriels menaçant de fermer votre compte si vous n'agissez pas immédiatement. Si vous vous sentez pressé, c'est un signal d'alarme.

3. On vous demande des informations personnelles

Aucune banque, agence gouvernementale ou entreprise technologique légitime ne vous demandera jamais de confirmer votre mot de passe, votre NAS, votre numéro de carte de crédit ou vos informations bancaires par courriel.

Alerte arnaque ARC : L'Agence du revenu du Canada ne vous enverra jamais de courriel demandant des renseignements personnels, un paiement par carte-cadeau ou un virement bancaire. Si vous recevez un tel courriel, c'est une arnaque.

4. Fautes d'orthographe et formulations maladroites

Beaucoup de courriels d'hameçonnage contiennent des fautes évidentes, des tournures de phrases étranges, ou une salutation générique comme « Cher client » au lieu de votre nom. Les entreprises professionnelles relisent leurs communications.

Note : l'intelligence artificielle a rendu certains courriels d'hameçonnage beaucoup plus soignés. Ne vous fiez pas uniquement aux fautes d'orthographe.

5. Le lien ne mène pas au vrai site

Les courriels d'hameçonnage renvoient souvent vers des sites identiques à l'original — même logo, même mise en page — mais l'URL est différente. Exemples :

Dans paypal.com.verifier-compte.net/login, le vrai domaine est verifier-compte.net — pas PayPal.

6. Une pièce jointe inattendue

Si vous n'attendiez pas de fichier, soyez très prudent avant d'ouvrir toute pièce jointe — surtout les fichiers .zip, .exe, .docm ou .xlsm. Si un collègue vous envoie une pièce jointe inattendue, confirmez par téléphone avant d'ouvrir.

7. Quelque chose cloche

Faites confiance à votre instinct. Si un courriel vous met mal à l'aise, ne cliquez sur rien. Allez directement sur le site en tapant l'URL vous-même, ou appelez l'entreprise en utilisant un numéro tiré de leur site officiel.

Si vous avez déjà cliqué : Déconnectez-vous d'Internet immédiatement, changez le mot de passe de tout compte pour lequel vous avez entré des identifiants (depuis un autre appareil si possible), et activez l'authentification à deux facteurs. Si vous pensez qu'un logiciel malveillant a été installé, contactez un professionnel.

Comment signaler un hameçonnage au Canada

Signalez les courriels d'hameçonnage au Centre antifraude du Canada sur antifraudcentre.ca ou au 1-888-495-8501.

Vous pensez avoir cliqué sur un lien malveillant ?

Nous offrons la suppression de virus et logiciels malveillants à Edmonton. Aucun frais si on ne peut pas réparer.

Réserver un diagnostic gratuit