You're reading this because a phishing email landed right in your inbox
I know that sinking feeling. You check your email, and there it is — a message from "PayPal" or "Microsoft" that looks real. But something's off. The grammar is weird, the link feels wrong. It slipped past Gmail's spam filter (or Outlook's, or Yahoo's). Don't panic. Here's the fix, from easy to thorough.
The 30-second fix: Delete and report
First, do not click anything. Not the link, not the attachment, not even "unsubscribe." Just delete it. But do it the right way.
- Open the email.
- Click the three dots (More) next to Reply.
- Select Report phishing. In Gmail, this trains Google's filter to catch similar junk next time. In Outlook, it's Report > Report phishing.
- Then hit the trash icon.
That's it. The email is gone. Google's filter learns. You move on. But if you already clicked something, keep reading.
The 5-minute fix: If you clicked a link or opened an attachment
Okay, so you tapped a link. Maybe you even typed your password into a fake login page. I've done it too — it happens. Here's the damage control.
- Change your password immediately. Go directly to the real website (type the URL yourself), not from the email. Use a strong password you haven't used anywhere else.
- Turn on two-factor authentication (2FA). Go to your account security settings. If it's not on, turn it on now. Use an authenticator app (Google Authenticator, Microsoft Authenticator) — not SMS if you can help it.
- Check for forwarding rules. Attackers sometimes set up email forwarding to steal more messages. In Gmail: Settings > See all settings > Forwarding and POP/IMAP. Look for any forwarding address you didn't set. Delete it.
- Sign out of all sessions. In Gmail, scroll to the bottom of your inbox, click Details next to "Last account activity." Then click Sign out all other web sessions. This boots any bad guys still inside.
This takes maybe 5 minutes. Once done, the immediate danger is gone. But if you want to be sure, go to the next step.
The 15-minute fix: Full security audit
You clicked the link, entered credentials, and now you want to be extra sure. Or maybe this happened at work and your IT guy is breathing down your neck. Here's the full cleanup.
- Run a malware scan. Even if you didn't download anything, some phishing sites can slip a keylogger or trojan onto your machine. Use Windows Defender (built-in, free, good enough) or Malwarebytes. Full scan. Takes 15-20 minutes.
- Check account recovery options. Attackers often change your recovery email or phone number to lock you out. In Gmail: Settings > Security > Recovery email and phone. Make sure they're yours.
- Review app permissions. Go to your Google Account > Security > Third-party apps with account access. Revoke anything you don't recognize. I once found a fake "Calendar Sync" app that was stealing contacts.
- Reset app passwords. If you use Gmail with Outlook or a phone mail app, generate new app-specific passwords. In Gmail: Settings > Security > App passwords. Delete old ones, create fresh ones.
- Monitor your accounts for a week. Watch for strange logins, password reset emails, or purchases you didn't make. Set up Google's Security Checkup (myaccount.google.com/security-checkup) to run every month.
That's it. The phishing email is gone, your account is locked down, and your anxiety should drop. You're good.
Why did this phishing email get through?
Spam filters aren't perfect. They miss things. A new phishing domain, a cleverly disguised link, or a hacked legitimate account can slip past. Google blocks 99.9% of spam, but that 0.1% still hits. This is why reporting helps — you're training the filter for next time.
If this keeps happening, consider switching to an email service with stronger phishing detection. Google Workspace (paid Gmail) has better AI for this. Outlook's built-in Defender also catches more. But for most people, the free version is fine if you stay watchful.
Quick tips to avoid future phishing
- Hover over links before clicking. On desktop, mouse over the link. Does it match the sender's domain? If the email says "PayPal" but the link says "paypa1-login.com," it's fake.
- Don't trust urgency. "Your account will be closed in 24 hours" is a classic trick. Real companies give you weeks, not hours.
- Use a password manager. It won't auto-fill on a fake site because the domain doesn't match. That's a dead giveaway.
- Enable 2FA everywhere. Even if they steal your password, they can't get in without the second factor.
I still get phishing emails on my personal Gmail. I delete, report, and move on. It's part of using the internet. But now you know how to handle it — fast, clean, and without drama.