Activation Hub Online Blog
Internet Security

How phishing emails get past your spam filter

The convincing ones don't break any rules a filter checks for. They come from real accounts, link to real services and ask for something ordinary — which is why the checks that work are ones you do yourself.

A hand holding a smartphone with an email app open

Spam filters are good at what they were built for: bulk mail, forged addresses, suspicious attachments and links to domains already reported as malicious. Most of the rubbish aimed at your inbox never reaches it.

The phishing emails that do get through tend to be the careful ones. They pass every technical check because, technically, nothing is wrong with them. The problem is what they ask you to do, and a filter can't judge that. You can.

Why a filter lets them through

Email providers check whether a message really came from the domain it claims, using standards called SPF, DKIM and DMARC. That stops crude forgery, but not an attacker sending from a genuine account.

Compromised real accounts. Messages from a taken-over mailbox are authentic in every way a filter can measure, and sometimes arrive as a reply inside an existing thread.

Lookalike domains. A domain one letter off the real one can be registered in minutes with valid authentication. It passes because it genuinely is that domain.

Links to real services. Many campaigns link to a document on a legitimate file-sharing or form service. The link is clean; the fake login page is one click further on.

No attachment, no malware. A message that just asks you to reply, call a number or approve a payment contains nothing to scan.

What the convincing ones look like

Spelling mistakes are no longer a useful tell; fluent text is easy to generate. The patterns that matter are about the request:

  • An invoice, delivery or account notice you weren't expecting, with a link to "view" or "confirm" it.
  • A shared document from someone you know, where opening it leads to a sign-in page.
  • A supplier or colleague saying their bank details have changed.
  • A QR code in the email or an attached PDF, which moves the link to your phone where it's harder to inspect.
  • Gentle urgency: today, before the end of the week, or your access will be paused.

None of these is proof on its own. They are the moments to slow down.

Checks you can do in under a minute

Read the full sender address. On a phone, tap the sender name to reveal it. The part just before .com or .co.uk is the domain that matters.

Check where a link really goes. On a computer, hover over it and read the address shown at the bottom of the window. On a phone, press and hold to preview it without opening. If it doesn't go where the email says, stop.

Go the long way round. Open the app or type the website address yourself. If the invoice or warning is real, it will be waiting in your account.

Confirm by another channel. For any change of bank details or unusual payment request, call the person on a number you already have, not one in the email. This single habit defeats most invoice fraud.

Notice when your password manager stays quiet. A password manager fills your details only on the exact site it saved them for. If it offers nothing on a login page you've used before, the page is probably not the site you think it is. There's more on this in setting up a password manager.

Settings that reduce the damage

  • Turn on two-step verification for email first, since your inbox is the reset route for everything else. App-based prompts and passkeys resist phishing far better than text codes; the methods compared explains why.
  • Use passkeys where offered. They are tied to the real website, so they simply won't work on a copy.
  • Show full sender details in your mail app if it has the option, so display names can't hide the address.
  • Keep your browser's built-in phishing protection on. In most browsers it's in the privacy or security settings and is on by default. It won't catch brand-new pages, but it catches many.

If you've already clicked or replied

  1. If you entered a password, change it now from the real site, and anywhere else you used the same one.
  2. Sign out of other sessions. Most email and social accounts have an option to sign out everywhere, in the security section.
  3. Check your mail rules and forwarding. Attackers often add a rule that forwards or hides messages. Remove anything you didn't set up.
  4. If you shared card or bank details, call your bank using the number on the back of your card.
  5. Report it. Use your mail app's report phishing option.

Being caught out isn't a sign of carelessness. These emails are designed to look ordinary, and acting quickly afterwards limits most of the harm.