Phishing email examples: 12 real-world lures, explained
Every example below is a reconstruction of a lure that lands in real inboxes every day. Read the message, then read what an analyst sees in it. Notice how the same three ingredients repeat: urgency, a process you are asked to bypass, and a sender address that does not belong to the brand it borrows.
The gallery
From: Microsoft Support <support@ms-verify-alerts.top>
Subject: Action required: your password expires in 24 hours
Dear user,
Your password will expire today. Failure to update it will result in the permanent loss of access to your mailbox and all associated files.
Keep the same password by confirming your identity below.
Link shows: https://login.microsoftonline.com
Link goes to: http://ms-verify-alerts.top/owa/signin
What gives it away
- The sender domain (ms-verify-alerts.top) has nothing to do with Microsoft.
- Microsoft never emails password-expiry deadlines; expiry is set by your own organization.
- The link text shows a real Microsoft address, but the actual destination is an unrelated .top domain.
- Manufactured 24-hour urgency exists to stop you from checking.
From: Accounts Payable <billing@your-supplier-uk.co>
Subject: OVERDUE: Invoice #INV-2041 final reminder
Hello,
Our records show invoice #INV-2041 remains unpaid despite previous reminders. Please note our banking details changed this month following an internal restructure.
Settle the balance to the updated account to avoid service interruption and late fees.
What gives it away
- A supplier announcing new bank details is the classic business email compromise setup; verify by phone on the number you already have.
- Threatening service interruption over an invoice you may never have received.
- The domain (your-supplier-uk.co) closely mimics but does not match the real supplier.
From: Security Team <no-reply@account-security-alert.net>
Subject: Enter your verification code to cancel the sign-in
We detected a sign-in attempt from Moscow, Russia. If this was you, no action is needed.
If this was NOT you, enter the code we just sent to your phone below to immediately block the attacker.
What gives it away
- This is the reverse-attack trick: the attacker is already logging in and needs the code the real service sent you.
- No legitimate service asks you to type a one-time code back into an emailed page.
- Unverifiable fear framing (Moscow sign-in) with an instant action path.
From: Daniel Reeves - CEO <d.reeves.ceo0ffice@gmail.com>
Subject: Are you at your desk? Quick confidential task
I'm heading into a board meeting and can't take calls. I need you to purchase 8 x $100 Apple gift cards for our client appreciation event and send me the codes by photo.
This is confidential until announced, so please don't loop anyone else in.
What gives it away
- A Gmail or lookalike address standing in for the executive's real company address.
- Gift cards are a fraudster favourite: fast, untraceable and irreversible.
- Secrecy pressure (don't tell anyone) is designed to bypass the one check that would catch it.
From: Royal Mail <tracking@royalmail-parcel.redelivery.info>
Subject: Your parcel is held: pay £2.99 redelivery fee
We attempted delivery today but nobody was home. Your parcel is being held at our depot for 48 hours.
Pay the small redelivery fee now to reschedule and avoid the parcel being returned to sender.
Link shows: Track your parcel
Link goes to: http://royalmail-parcel.redelivery.info/pay/card.php
What gives it away
- A small fee is the point: it tests a stolen card and harvests your full card details.
- Real carriers link redelivery from their own site, not from a chain of extra domains.
- 48-hour holding deadlines recur across every carrier-impersonation scam.
From: OneDrive <shared-files@drive-notifications.xyz>
Subject: Sarah shared 'Q4-Bonus-Plan.pdf' with you
Sarah Miller (sarah.miller@yourcompany.com) has shared a document with you.
Click View document to review it. You'll need to sign in with the email the document was shared with.
Link shows: View document
Link goes to: http://drive-notifications.xyz/login?email=victim
What gives it away
- The lure is a colleague's name and an intriguing file title; the sign-in page behind it is fake.
- The actual notification comes from a .xyz domain, not the genuine Microsoft sharing domain.
- Sensitive file names (bonuses, payroll, layoffs) exploit curiosity and urgency.
From: HM Revenue & Customs <refunds@gov-claims-processing.org>
Subject: You are eligible for a tax refund of £486.20
After recalculation of your fiscal activity, we have determined that you are eligible to receive a tax refund of £486.20.
Submit your refund claim within 3 days. Claims submitted after this period will be discarded.
What gives it away
- Governments never email unsolicited refund offers and never ask for bank details by link.
- "Recalculation of your fiscal activity" is stilted, machine-translated phrasing common to mass phishing.
- A refund you never claimed is the oldest lure on the internet; it works because it feels like free money.
From: HR Portal <hr@company-benefits-update.com>
Subject: Payroll self-service: confirm your bank details
As part of our annual compliance audit, all employees must re-verify their salary account before the next pay run.
Employees who do not confirm within 5 business days will be moved to paper cheques.
What gives it away
- Payroll diversion is one of the highest-loss categories: redirecting one salary is worth months of credit-card phishing.
- The annual audit framing recurs every year, which is the tell: real HR processes are announced on the intranet.
- Check the domain against the one your payslips actually come from.
From: Voicemail System <vm@pbx-messages.net>
Subject: Missed call: 1 new voicemail message
You have 1 new voicemail message received at 09:42 from an unknown number.
The message could not be played inline. Download the audio attachment or click below to listen.
What gives it away
- The attachment is typically an HTML file that renders a fake login page locally, hiding the URL from mail filters.
- Unknown-number framing exploits universal curiosity.
- Check who your real voicemail emails come from; they rarely come from pbx-messages.net.
From: Recruitment <careers@linkedin-jobs-portal.com>
Subject: Interview invitation: we reviewed your profile
Congratulations! Based on your CV on LinkedIn, you have been shortlisted for a remote position paying $4,500/week.
No interview required. Confirm your acceptance and provide your banking details for the first onboarding payment.
What gives it away
- High pay, no interview, remote-only: the three markers of every fake-job money-mule recruitment.
- Banking details requested before any human contact means the job's purpose is your account.
- Real recruiters message from LinkedIn itself or the company's own domain.
From: Portfolio Advisor <vip@elite-trading-signals.io>
Subject: Last chance: 3 spots left in today's managed pool
Our AI trading pool returned 41% last month. Membership closes at midnight and we are limiting this cohort to 3 new investors.
Deposit in BTC or USDT to lock in your allocation. Withdrawals open after the 30-day cycle.
What gives it away
- Crypto payments are irreversible by design; that is why scams demand them.
- Artificial scarcity (3 spots, midnight close) plus impossible returns (41%/month) is the whole pitch.
- Withdrawals gated behind a cycle means your deposit was never meant to come back.
From: DocuSign <notifications@dse-signnow.net>
Subject: Completed: Please review the Non-Disclosure Agreement
Your document has been completed and is ready for review. All parties have signed.
Review the document to protect your account security. Do not share this email with others.
Link shows: Review Document
Link goes to: http://dse-signnow.net/view/login.php
What gives it away
- "Completed" but you must log in to see it: the login page is the product of this lure.
- The brand is copied but the domain (dse-signnow.net) is a mash-up of two real brands.
- Do-not-share instructions suppress the colleague who would spot it.
The pattern behind every example
Twelve lures, one recipe. The attacker needs you to (1) act before you think, (2) trust the display name instead of the real sender address, and (3) click instead of verifying out of band. Every example above fails the same two-second check: expand the header, read the actual domain, and hover the primary link. When those still look right, the email headers have the final word, because a forged message cannot fake SPF, DKIM and DMARC results from the real brand.
For a deeper walkthrough, read our 10 red flags for spotting a phishing email.
Check the real thing, not the template
Templates only go so far: targeted phishing copies your supplier's tone and your CEO's name. PhishingSonar parses the full email source, checks SPF, DKIM and DMARC, compares display links against their real destinations, flags lookalike domains and extracts indicators you can hand to your SOC. Email content is never stored, and the built-in redaction tool scrubs personal details in your browser before anything is sent.
Frequently asked questions
- What are the most common phishing email examples?
- The most common lures are fake password-expiry notices, invoice and bank-detail fraud, delivery-fee scams, fake document shares, gift-card requests from executives, and tax or refund notifications. All of them combine urgency with a link or attachment that routes you to an attacker-controlled page.
- What do all these phishing examples have in common?
- Three things: pressure to act quickly, a request that bypasses a normal process, and a sender domain or link destination that does not match the brand being impersonated. If you check only the real sender address and the link destination, you will catch most of them.
- Are these real phishing emails?
- The examples are reconstructions of widely reported, real-world lure types, rewritten so no live links or working payloads are included. The tactics, sender patterns and wording mirror what lands in real inboxes.
- How can I check if the email I received is one of these?
- Compare the display name with the real sender address, hover the links to read their true destination, and look at the SPF, DKIM and DMARC results in the headers. A header analyzer like PhishingSonar checks all of this automatically in seconds.