A sender address that doesn’t match the real company.
Urgent threats (“your account will be closed”).
Generic greetings like “Dear customer.”
Links whose real address differs from the text (hover to check).
Unexpected attachments.
Requests for passwords or payment details.
Spelling and design mistakes.
Don’t click. Go to the company’s site directly, or report the email as phishing. If you already clicked, change your password and enable two-factor authentication.