Mental ShieldMental Shield

Digital

How to recognise phishing

Author: Rustam Mirzabayev · Updated 2026-08-23 · 6 min read

Short answer

Phishing is recognised by the combination of “an unexpected message + a demand for immediate action + a link that asks for your data”. What you check is not the design of the email but the domain — and whether you asked for this action at all. The rule is simple: you enter a service the way you always do, not through a link in a message.

Why it matters

Fake pages stopped looking clumsy long ago: the logo, the fonts and the address look convincing, and even a fraudulent site has a certificate. Only one difference remains — you arrived there through someone else's link. That is the step to remove from your habits.

A real scenario

How it looks from the inside

An email “from the bank”: a suspicious login, please confirm your identity. The link leads to a page indistinguishable from the real one. After the login a field for the SMS code appears — and at that very moment the attacker enters the same data on the real site. The person notices only when a transfer notification arrives.

Signs

  • The message arrived unexpectedly and demands action right now.
  • The domain resembles the real one but has an extra word or a different zone.
  • You are asked to enter a password or code on a page from the link.
  • The email contains a threat: blocking, a fine, loss of access.
  • The greeting is impersonal or details are subtly wrong.

What to do

  1. Do not follow the link — open the service the way you normally do.
  2. Check the whole domain, not just the beginning of the address.
  3. Enable two-factor authentication wherever money and email live.
  4. If you have already entered your details, change the password and end other sessions.
  5. Tell the bank or the support team: it speeds up blocking.

Expert view

Phishing remains the most widespread tool precisely because it requires no hacking: the person enters the data themselves. That is why our training drills not the recognition of emails but the habit of entering a service by your own route.

Rustam Mirzabayev, the project translates professional security experience into the language of everyday decisions

Frequently asked questions

Is the padlock in the address bar a guarantee?

No. It only shows that the connection is encrypted, not that the site is honest.

Is it dangerous just to open an email?

The risk usually comes from links and attachments. Still, it is safer not to open attachments from unknown senders.

What if I entered my password on a fake page?

Change the password on the real site immediately, end active sessions and check the linked email and phone.

Take the free test

Find out which threat scenarios you may be missing — and get a personal learning route.