Try this thought experiment: read the last suspicious-looking email you got and ask whether you could have spotted it purely from the writing. A few years ago, that test worked reasonably well, since scam emails were riddled with typos and stilted phrasing that gave them away instantly. That test barely works anymore. Roughly 82.6% of phishing emails now contain AI-generated content, according to KnowBe4’s 2025 Phishing Threat Trends Report, and that content reads as fluently as anything a real colleague or bank would send.

This isn’t a small shift, it’s a fundamental one. APWG recorded 3.8 million phishing attacks globally in 2025, and the businesses tracking this space closely describe AI-generated phishing as now outperforming human-written phishing in direct testing, a complete reversal from just two years earlier. If the old advice to “watch for bad grammar” is officially obsolete, the good news is that better, more durable ways to spot a scam still exist. This guide walks through what actually still works.

Why the Old Advice Stopped Working

For most of the internet’s history, phishing detection boiled down to a fairly simple checklist: look for spelling mistakes, awkward sentence structure, and generic greetings like “Dear Customer” instead of your actual name. Generative AI has quietly dismantled almost every item on that list. A scammer no longer needs any particular skill with language to produce a flawless, professionally worded message, they just need access to a chatbot, which means the barrier to running a convincing scam has collapsed for a huge population of low-skill attackers.

The economics behind this shift matter as much as the technology itself. AI has driven the cost of writing and translating a convincing scam message close to zero, which changes who becomes a worthwhile target. A small business or an individual that used to be “too small to bother with” for a scammer weighing time against payoff is now well within reach of a campaign that costs almost nothing to run. This is a big part of why phishing volume has grown so dramatically since AI writing tools became widely available.

What Still Gives a Scam Away

The Request Itself, Not the Writing Quality

Since polished writing no longer signals legitimacy, the most reliable red flag has shifted to the nature of the request itself. Genuine institutions rarely create artificial urgency, demanding you click a link within the hour, verify your account details immediately, or risk some dramatic consequence. Scammers rely on that manufactured pressure specifically because it short-circuits the moment of hesitation where most people would otherwise stop and think. Any message engineered to make you act before you can consider it carefully deserves extra scrutiny, regardless of how professional it looks.

Mismatched Sender Details

Even a flawlessly written message often has a small inconsistency somewhere in the technical details, a sender address that’s close to but not quite the real domain, a reply-to address that doesn’t match the supposed sender, or a link that, when hovered over rather than clicked, points somewhere entirely unrelated to the claimed destination. These details take a few extra seconds to check and remain one of the most reliable technical tells even as the written content itself becomes indistinguishable from something genuine.

Requests That Bypass Normal Channels

A message asking you to handle something unusual through an unusual channel, wiring money based solely on an email, resetting a password through a link in a text rather than the app itself, or approving a purchase through a chat message instead of your company’s normal procurement system, is worth treating with suspicion regardless of how convincing the message sounds. Legitimate requests almost always have a normal, established path, and a scam frequently tries to route around that path specifically because the normal process would catch the fraud.

The New Attack Formats Worth Knowing About

Deepfake Voice Scams

One of the more unsettling developments is the rise of cloned voice scams, where an attacker uses AI to replicate a real person’s voice convincingly enough to call an employee and request an urgent wire transfer. The finance team member on the other end genuinely believes they’re hearing their CEO, because in every audible way, they are. Establishing a verification protocol for any unusual financial request, a callback to a known number or a code phrase confirmed through a separate channel, closes this gap regardless of how convincing the voice sounds.

QR Code Phishing

QR codes embedded in emails and PDFs have become a popular way to move an attack from a closely monitored work laptop to a personal phone that typically has far less security oversight. Microsoft has reported QR code phishing climbing by as much as 146% in a single quarter, reflecting how quickly attackers pivoted once they recognized this blind spot. Treating a QR code inside an unexpected email with the same suspicion you’d apply to a suspicious link, since that’s functionally what it is, closes off this particular avenue.

Smishing and Voice Phishing

Text-message-based phishing, often called smishing, continues growing at a striking pace, with some trackers reporting quarter-over-quarter increases of 30 to 40%. Phone screens make it considerably harder to inspect a suspicious link carefully compared to a desktop browser, which is exactly why attackers have leaned into this channel so heavily. The same core discipline applies here as with email: unexpected urgency, a request to click a link and verify something, or pressure to act immediately are red flags whether they arrive by email, text, or voice call.

Watching for Brand Impersonation

Attackers consistently borrow the built-in trust people already have in familiar brands rather than trying to build credibility from scratch. Microsoft has remained the single most impersonated brand in phishing attacks for several years running, appearing in a significant share of all recorded scams worldwide, with major delivery services and retail brands also rotating through the top rankings depending on the season. Recognizing this pattern is useful precisely because it means an unexpected message claiming to be from one of these familiar names deserves a second look rather than automatic trust, simply because it’s exactly the kind of message attackers know people are primed to open without much scrutiny.

Why Verifying Through a Separate Channel Beats Everything Else

If there’s a single habit that outperforms every detection technique covered so far, it’s verifying any request involving money, credentials, or sensitive data through a channel completely separate from the one the request arrived on. A suspicious email claiming to be from your bank gets checked by calling the number printed on your physical card, not any number or link included in the message itself. A surprising request from a colleague or executive gets a quick internal message or call to confirm, rather than an immediate reply to the original email thread. This single habit sidesteps the entire manipulation regardless of how convincing the original message is, since it removes the attacker’s ability to control every side of the conversation.

What to Do After Spotting a Scam

Recognizing a phishing attempt is only useful if it leads to the right follow-up action. Reporting the message to your email provider or IT team helps flag the sender for others who might receive the same campaign, and most major platforms make this a one-click action built directly into the inbox. If any information was entered before the scam was recognized, a login credential typed into a fake page, for instance, changing that password immediately and enabling multi-factor authentication on the affected account limits how much damage the exposure can cause. Given that the FBI’s Internet Crime Complaint Center reported $2.8 billion in business email compromise losses in the U.S. alone in 2024, treating a near-miss seriously rather than shrugging it off is a reasonable response to how much money is genuinely moving through these scams.

Final Thoughts

The rules for spotting a scam have genuinely changed, and clinging to outdated advice about typos and awkward phrasing leaves people exposed to exactly the kind of polished, AI-generated fraud that’s now the norm rather than the exception. What still works is scrutinizing the request itself rather than the writing quality, checking sender details and links carefully, treating unfamiliar formats like QR codes and cloned voices with the same suspicion as a suspicious email, and verifying anything involving money or credentials through a completely separate channel before acting.

If this guide helped sharpen your sense of what to watch for, share it with someone in your life or your team who could use the update, especially anyone still relying on the old “check for bad grammar” advice. And if you want more practical, well-researched security guidance as scam tactics keep evolving, subscribe so the next warning reaches you before the next scam does.