All resources

// Security

How to Protect Yourself From Phishing Emails

March 15, 2026 · The Computer Doctors

Phishing attacks are more sophisticated than ever. Criminals are impersonating banks, government agencies, and people you actually know. Here is how to spot one before it costs you something.

01

Urgency and fear tactics

"Your account will be suspended in 24 hours." Urgency is the oldest tool in the box, because a person in a hurry does not check the sender address.

Real organisations do not threaten you into clicking something within the hour. If a message is engineered to make you panic, that is the tell.

02

Mismatched sender addresses

The display name says one thing; the actual address says another. Expand it and read the full domain, not the name in bold.

Hover over any link before clicking. The URL shown at the bottom of your browser should match the company's real domain exactly — not a lookalike with an extra word or a different ending.

03

Unexpected attachments

Never open attachments you were not expecting, even from people you know. Their account may have been compromised and is being used to spread malware to everyone in their address book — which is precisely why it works.

04

Bad grammar and spelling

Professional companies proofread their emails. Errors in a message claiming to be from Microsoft, your bank, or the IRS are a strong warning sign.

Worth knowing: some of this is deliberate. Obvious errors filter out cautious readers early, leaving the sender with the people most likely to fall for the rest of it.

If you think you received one

  • Do NOT click any links or open attachments.
  • Do NOT call any phone numbers listed in the email — the number is part of the scam.
  • Report it to your IT department or email provider as spam/phishing.
  • If you think your account was compromised, change your password immediately and enable multi-factor authentication.
  • Contact The Computer Doctors if you need help securing your device: (904) 823-9669.

05

What actually prevents this

  • Use a password manager (Bitwarden, 1Password) to generate and store strong, unique passwords.
  • Turn on multi-factor authentication everywhere it is offered — especially email, because email is how every other password gets reset.
  • Verify unexpected requests through a channel you chose. If your bank emails you, call the number on your card, not the one in the message.
  • Keep software updated. Many phishing payloads rely on holes that were patched months ago.

The short version

Urgency, a mismatched sender, and a link you were not expecting. Any two of those together means stop and verify through a channel you picked yourself. If you are not sure, call us — we would far rather answer a question about a suspicious email than recover an account after the fact.

Want us to take a look?

Describe what it is doing. We will tell you honestly whether it needs work and what that work is worth.