← AI & securityai phishing is flawless now, judge the request not the writing

ai phishing is flawless now, judge the request not the writing

the typo is dead, and that's a problem for old habits

for years the advice was "check for bad grammar" and "look for weird spelling." that advice is basically retired now. ai writes phishing emails that are grammatically perfect, tonally on point, and personalized with details scraped from linkedin, company websites, and old data breaches. the writing quality signal is gone. so we need new signals, and they're not about how the email sounds, they're about what the email is asking you to do.

check the sender's real domain, not the display name

email clients show you a friendly display name like "microsoft support" or "your ceo," but that name is just text, anyone can type anything there. what matters is the actual domain the email came from. on desktop, click or hover on the sender name to reveal the full address. on mobile, tap the sender's name to expand it.

look for lookalike domains. these rely on you skimming fast:

paypa1.com
micros0ft-support.com
yourcompany-hr.com (instead of yourcompany.com)
account-security-appleid.com

if the domain isn't the exact one your bank, employer, or vendor actually uses, that's your answer. don't trust "close enough."

hover every link before you click anything

ai can write a flawless call to action, but it can't disguise where a link actually goes, at least not without you being able to check. on desktop, hover your mouse over any link and look at the bottom left corner of your browser or email client, it shows the real destination url. on mobile, press and hold the link to preview it without opening it.

what you're looking for:

does the domain match who supposedly sent this?
is it a shortened link (bit.ly, tinyurl) hiding the real destination?
does the url have extra subdomains trying to look legit?
example: login.microsoft.com.secure-verify.net
that last part before the first single slash is the real domain, and it's not microsoft.

if you can't verify the link, don't click it. type the website address in yourself instead.

urgency is the tell, not the tone

this is the big one. ai phishing doesn't sound rushed or sloppy anymore, so attackers lean harder on manufactured urgency to get you to skip your own checks. "your account will be suspended in 24 hours." "wire this today or we lose the vendor contract." "the ceo needs this gift card purchase confirmed right now, i'm in a meeting."

urgency is a pressure tactic, full stop. legitimate requests involving money, credentials, or sensitive data almost never require you to bypass normal verification "just this once." when you feel that little spike of panic or pressure to act immediately, that's not a coincidence, that's the design. slow down on purpose.

verify money and credential requests through a second channel

this is the single most effective habit against ai phishing, because it doesn't rely on you spotting anything in the email at all. if a message asks you to send money, change payment details, share a password, or approve access, don't reply to that email or click anything in it. instead, contact the person or company through a channel you already know is real:

call the phone number on file, not one from the email
message your coworker on slack or teams directly
log into the actual website by typing the url yourself
walk over and ask in person if you can

if your ceo emails asking for an urgent wire transfer, a 30 second phone call confirms it instantly. attackers are betting you won't take that extra step. take it anyway.

the takeaway

the writing used to give phishing away. now it won't, so stop grading emails on grammar and start grading them on behavior. check the real sending domain, hover before you click, treat urgency as a red flag instead of a reason to hurry, and confirm anything involving money or credentials through a totally separate channel. judge the request, not the writing, and build that into a reflex, not a one time check.

watch the reel ↗
the weekly drop

one command a week that makes you harder to hack.

a single tool, explained in plain english, every week. straight to your inbox.

no spam. one email a week. unsubscribe anytime.