What Gini Looks for in Phishing Emails

Gini's AI analyzes multiple elements of every email to detect phishing scams. Here's what we look for - knowing these can help you spot scams even without Gini.

Sender Address Red Flags

Mismatched Domains

Red Flag: The email claims to be from a company but the email address doesn't match.

Examples:

What to look for: Check the part after the @ symbol. It should exactly match the company's real domain (amazon.com, chase.com, etc.)

Slight Misspellings

Red Flag: The email domain is almost right, but with small changes.

Examples:

  • amaz0n.com (zero instead of 'o')
  • app1e.com (number 1 instead of 'l')
  • paypa1.com (number 1 instead of 'l')
  • microsft.com (missing 'o')

What to look for: Read the domain character by character.

Free Email Services

Red Flag: A "company" using Gmail, Yahoo, or other free email.

Example: Your bank would never email from: chase.customer.service@gmail.com

What to look for: Real businesses use their own email domains.

Link Red Flags

Hidden Destinations

Red Flag: The link text says one thing but goes somewhere else.

Example: Link says "www.yourbank.com" but actually goes to "scammer-site.ru/fake-login"

What Gini does: We check where links actually lead, not just what they say.

Shortened URLs

Red Flag: Links use URL shorteners to hide the real destination.

Examples: bit.ly, tinyurl.com, t.co links in emails claiming to be from banks or services

What to look for: Legitimate companies rarely use shortened links in official emails.

Mismatched URLs

Red Flag: The URL almost looks right but isn't.

Examples:

  • signin-paypal.com (not paypal.com)
  • amazon.com.verify-order.net (the real domain is verify-order.net)

What to look for: The actual domain is right before the first single slash.

Content Red Flags

Urgent Language

Red Flag: The email creates panic to make you act without thinking.

Examples:

  • "Your account will be suspended in 24 hours!"
  • "Unauthorized access detected - verify immediately!"
  • "Final warning - action required today!"

What to look for: Real companies give you reasonable time to respond.

Threats

Red Flag: The email threatens consequences.

Examples:

  • "Your account has been compromised"
  • "Legal action will be taken"
  • "You will be arrested if you don't respond"

What to look for: Real organizations don't threaten you in emails.

Requests for Sensitive Information

Red Flag: Asking for information no legitimate email would request.

Examples:

  • Passwords
  • Complete Social Security number
  • Full credit card number with CVV
  • Bank account and routing numbers
  • PINs

What to look for: No real company asks for these via email.

Grammar and Formatting

Poor Grammar and Spelling

Red Flag: Multiple errors that a professional company wouldn't make.

Examples:

  • "Dear Customer valued,"
  • "Plese verify your informations"
  • "Your account have been suspend"

What to look for: While not all phishing has errors, many do.

Generic Greetings

Red Flag: Not using your name when a real company would.

Examples:

  • "Dear Customer"
  • "Dear User"
  • "Hello Sir/Madam"

What to look for: Your bank knows your name and usually uses it.

Unprofessional Formatting

Red Flag: Poor design that doesn't match the company's usual style.

Examples:

  • Blurry logos
  • Misaligned text
  • Inconsistent fonts
  • Colors that don't match the brand

What to look for: Compare to real emails you've received from that company.

Attachment Red Flags

Unexpected Attachments

Red Flag: Files you didn't request, especially:

  • .exe, .zip, .scr files
  • "Invoices" you didn't expect
  • "Important documents" from unknown senders

Pressure to Open

Red Flag: Urgency around attachments.

Example: "Open the attached form immediately to avoid account closure"

What Gini Does With This Information

When Gini scans your email, it:

  1. Checks the sender against known patterns
  2. Analyzes all links for suspicious destinations
  3. Scans content for urgency, threats, and data requests
  4. Looks at formatting and language quality
  5. Combines findings into a risk score

The more red flags found, the higher the risk level assigned.

Protect Yourself

Even with Gini protecting you:

  1. Never click links in suspicious emails - Go to websites directly
  2. Verify unexpected requests - Call the company using a known number
  3. Don't download unexpected attachments
  4. Trust your instincts - If something feels wrong, it probably is