Campoverde Repair
Security

How to Spot a Phishing Email Before It's Too Late

📅 September 4, 2026 🔧 Security

The Threat Sitting in Your Inbox Right Now

A phishing email is a fraudulent message designed to trick you into handing over passwords, banking details, or personal information — by pretending to be someone you trust. Over 3.4 billion phishing emails are sent every single day, and one wrong click is all it takes to lose your savings, your business data, or your identity.

By the end of this article, you'll be able to identify a phishing email faster than the scammer wants you to — every time.

email inbox hacker threat

Why Phishing Is a Bigger Problem Than Ever on the Costa Blanca

Expats are prime targets. Full stop. You're navigating an unfamiliar banking system, dealing with Spanish bureaucracy in a second language, and you're slightly more likely to panic when an email arrives claiming your NIE application has failed, your Banco Sabadell account is frozen, or Correos has a parcel waiting. Scammers know this. They craft their lures accordingly.

Phishing attacks increased by 61% in 2023 compared to the previous year, according to the Anti-Phishing Working Group. And AI tools now let criminals generate flawless English — or Spanish — in seconds. The days of spotting a scam because it was full of typos? Those days are fading fast. You need a sharper eye now.

suspicious link browser warning

The Anatomy of a Phishing Email — How It Actually Works

Phishing isn't random. It follows a formula. Once you know that formula, you'll see the fingerprints on every fake email you receive. Here's how the attack is structured:

The Spoofed Sender Address

The "From" name in your email client can say absolutely anything. Scammers set it to "PayPal Security Team" or "Correos España" — but the actual email address behind that name tells a different story. Click or tap on the sender name to reveal the full address. If it reads something like support@paypa1-secure.net or noreply@correos.delivery.xyz, it's fake. Legitimate companies send from their own verified domains, always.

Watch especially for:

The Urgency Trap

Phishing emails are engineered to stop you thinking clearly. They create a manufactured emergency — "Your account will be closed in 24 hours," "Unauthorised login detected — act now," "Your parcel will be returned if you don't pay €1.99 shipping today." That artificial time pressure is the mechanism. The moment you feel rushed by an email, slow down. That feeling is the attack working.

The Poisoned Link

The link in a phishing email looks legitimate on the surface. The text might read www.bbva.es/security, but the actual URL it points to is something completely different. On a desktop, hover your mouse over any link before clicking — look at the bottom-left of your browser to see where it actually leads. On a phone, press and hold the link to preview the destination URL. If the real destination doesn't match the displayed text, don't touch it.

Red flags in URLs include:

The Fake Login Page

If you do click, the destination is usually a cloned version of a real website — your bank, Hacienda, Amazon, Microsoft. It looks pixel-perfect in many cases. But check the browser address bar, not the page design. The URL will be wrong. Also look for a padlock icon — a padlock means the connection is encrypted, not that the site is legitimate. Scammers can get SSL certificates too. The padlock is necessary but nowhere near sufficient.

The Malicious Attachment

Not every phishing email wants your password. Some want to install malware. The delivery vehicle is usually an attachment: a PDF claiming to be an invoice, a Word document asking you to "Enable macros to view content," or a ZIP file containing an executable. Never open an attachment you weren't expecting — even if it appears to come from someone you know. Accounts get compromised, and attackers then use them to target that person's contacts. The sender being real doesn't make the attachment safe.

The Mistakes That Get People Caught

Even technically aware people fall for phishing. Here's what trips them up:

Trusting the Logo

Copying a logo takes about 30 seconds. A convincing logo in an email proves nothing. Scammers use official brand colours, correct fonts, and realistic email footers. Visual design is not evidence of legitimacy — it's decoration.

Assuming HTTPS Means Safe

As mentioned above, the padlock icon means the connection between your browser and the server is encrypted. It does not mean the server belongs to who you think it does. This misconception is one of the most dangerous in cybersecurity. Roughly 84% of phishing sites now use HTTPS. Don't let a padlock lower your guard.

Forgetting That Spam Filters Aren't Perfect

Your spam folder catches a lot. Your inbox catches the rest — and so does it. Sophisticated phishing campaigns are specifically designed to evade spam filters: clean sending infrastructure, properly authenticated domains, and carefully crafted content. If it landed in your inbox, that doesn't mean it's been vetted. It just means it passed an automated filter.

Thinking "I'd Never Fall for That"

Overconfidence is a phisher's best friend. The most successful attacks don't target naive users — they target busy, distracted, stressed ones. A phishing email that arrives on a Monday morning when you're already overwhelmed, referencing your actual bank and using your correct name, lands differently than a cartoon scam does. Complacency is a vulnerability.

A Real-World Example: The "Gestoría" Email Attack

One of our clients — a British expat running a small rental business near Torrevieja — received an email that appeared to come from her Spanish gestoría (accountant). Same email format, similar signature, correct logo. The email said the Hacienda had flagged an underpayment and she needed to log in via a link to review the notice before a fine was issued.

She nearly clicked. What stopped her: the email arrived on a Saturday afternoon. Her gestoría never contacts clients on weekends. That one small detail — the timing — made her pause. She forwarded it to us instead of clicking through.

When we examined it: the sending domain was gestoria-asesoria24.net — not her gestoría's actual domain. The link led to a cloned Agencia Tributaria page on a server hosted in Eastern Europe. Had she entered her credentials, those would have been harvested within seconds and likely used to access her Spanish bank account via linked services.

The lesson here isn't that she was nearly fooled — it's that the email was genuinely convincing. And it would have fooled most people. What saved her was a single moment of "this feels slightly off." That instinct is trainable. You can develop it deliberately.

Key Takeaways

What to Do If Something Lands in Your Inbox

If an email gives you even a 5% uneasy feeling — forward it to us before you click anything. We'll check the headers, trace the actual sending server, and tell you in plain English whether it's legitimate or a trap. If you've already clicked and entered credentials somewhere, that's a different emergency — contact us immediately and we'll start the damage-limitation process: changing passwords, checking for malware, and reviewing account access logs. Don't sit on it hoping for the best. In phishing, the clock runs against you from the moment you click.

Frequently asked questions

How can I tell if an email is a phishing scam?

Check the actual sender email address (not just the display name), look for urgency or threats, and hover over any links before clicking to see where they really lead. Legitimate companies never pressure you to act within hours or ask for passwords via email. If something feels off, trust that instinct and verify directly with the company by phone or their official website.

Does a padlock (HTTPS) mean a website is safe to log into?

No — HTTPS only means the connection between your browser and the server is encrypted, not that the site is legitimate. Around 84% of phishing sites now use HTTPS. Always check the full URL in your browser's address bar, not just the presence of a padlock.

Can phishing emails come from people I know?

Yes. If a contact's email account has been hacked, attackers can use it to send malware-laden attachments or phishing links to everyone in their address book. Never open an unexpected attachment — even from a trusted contact — without verifying with them directly via a separate channel like a phone call or WhatsApp.

What should I do immediately after clicking a phishing link?

Don't enter any information on the page that opens, close the browser, and change the passwords for any accounts the email was pretending to be from — especially if you use the same password elsewhere. Run a malware scan on your device and contact a local tech professional immediately to assess whether anything was installed.

Are expats on the Costa Blanca more at risk from phishing attacks?

Expats are disproportionately targeted because scammers exploit unfamiliarity with Spanish banking, bureaucracy, and official communications. Emails impersonating Correos, Hacienda, Banco Sabadell, or immigration services are especially common in the region. Staying alert and knowing the warning signs is your best defence.

Computer trouble on the Costa Blanca?

30+ years of repair experience — on-site within 30 km and remote worldwide. Tell me what's wrong and I'll sort it.

Get help now →

Photos via Pexels