The typos are gone. The broken grammar, the oddly formal "Dear Valued Customer," the logo that looked slightly off — the tells that security-awareness training spent a decade teaching people to spot have mostly disappeared, because the emails are no longer written by someone working in a second language under time pressure. They're generated. And they're good.
That doesn't mean phishing has become undetectable. It means the tells have moved from the writing to the structure of the message itself — and those are actually easier to check, once you know where to look.
The pressure is the product
Every phishing email is selling you one thing: a reason to act before you think. That hasn't changed and can't change, because it's the entire mechanism. A message that gives you time to verify it is a message you'll verify. So look past the wording and ask what the email wants you to feel in the next thirty seconds — locked out, in trouble, or about to miss something free.
Check the part that's hard to fake
A convincing subject line and body are cheap to generate. A domain that has existed for years, is properly configured, and matches the organization exactly is not. So the highest-value check is also the simplest one:
- Hover before you click. On desktop, hovering over a link shows the real destination in the corner of the browser. On mobile, press and hold. Compare it letter by letter to the organization's real domain — not just the part that looks familiar.
- Read the sender address, not the display name. "Amazon Support" is just text someone chose. The address after the @ symbol is what matters, and it's the part scammers can't fully control.
- Distrust perfect familiarity. A message that references a real recent order, a real coworker's name, or a real event you attended feels more trustworthy — but that context is often scraped from a data breach or a public profile, not proof of legitimacy.
Three checks, in order
You don't need to run a full investigation on every email. Most phishing attempts fall apart at the first or second check:
If you've already clicked
Clicking a link usually isn't the point of no return — entering credentials or downloading a file is. If you've clicked but stopped there, close the tab and move on. If you entered a password, change it immediately on the real site, and change it anywhere else you reused it. If you downloaded and opened a file, disconnect the device from the internet and run a full scan before doing anything else on it.
The takeaway
Better-written phishing doesn't mean cleverer phishing — it means the tells shifted from the sentence level to the structural level. The domain, the urgency-plus-consequence pattern, and the habit of navigating to sites yourself will keep working long after this particular wave of AI-written scam emails is replaced by the next one.