Gini's AI analyzes multiple elements of every email to detect phishing scams. Here's what we look for - knowing these can help you spot scams even without Gini.
Sender Address Red Flags
Mismatched Domains
Red Flag: The email claims to be from a company but the email address doesn't match.
Examples:
- Email claims to be Amazon but comes from: amazon-support@mail-secure.com
- Email claims to be your bank but comes from: alerts@chase-verify.net
What to look for: Check the part after the @ symbol. It should exactly match the company's real domain (amazon.com, chase.com, etc.)
Slight Misspellings
Red Flag: The email domain is almost right, but with small changes.
Examples:
- amaz0n.com (zero instead of 'o')
- app1e.com (number 1 instead of 'l')
- paypa1.com (number 1 instead of 'l')
- microsft.com (missing 'o')
What to look for: Read the domain character by character.
Free Email Services
Red Flag: A "company" using Gmail, Yahoo, or other free email.
Example: Your bank would never email from: chase.customer.service@gmail.com
What to look for: Real businesses use their own email domains.
Link Red Flags
Hidden Destinations
Red Flag: The link text says one thing but goes somewhere else.
Example: Link says "www.yourbank.com" but actually goes to "scammer-site.ru/fake-login"
What Gini does: We check where links actually lead, not just what they say.
Shortened URLs
Red Flag: Links use URL shorteners to hide the real destination.
Examples: bit.ly, tinyurl.com, t.co links in emails claiming to be from banks or services
What to look for: Legitimate companies rarely use shortened links in official emails.
Mismatched URLs
Red Flag: The URL almost looks right but isn't.
Examples:
- signin-paypal.com (not paypal.com)
- amazon.com.verify-order.net (the real domain is verify-order.net)
What to look for: The actual domain is right before the first single slash.
Content Red Flags
Urgent Language
Red Flag: The email creates panic to make you act without thinking.
Examples:
- "Your account will be suspended in 24 hours!"
- "Unauthorized access detected - verify immediately!"
- "Final warning - action required today!"
What to look for: Real companies give you reasonable time to respond.
Threats
Red Flag: The email threatens consequences.
Examples:
- "Your account has been compromised"
- "Legal action will be taken"
- "You will be arrested if you don't respond"
What to look for: Real organizations don't threaten you in emails.
Requests for Sensitive Information
Red Flag: Asking for information no legitimate email would request.
Examples:
- Passwords
- Complete Social Security number
- Full credit card number with CVV
- Bank account and routing numbers
- PINs
What to look for: No real company asks for these via email.
Grammar and Formatting
Poor Grammar and Spelling
Red Flag: Multiple errors that a professional company wouldn't make.
Examples:
- "Dear Customer valued,"
- "Plese verify your informations"
- "Your account have been suspend"
What to look for: While not all phishing has errors, many do.
Generic Greetings
Red Flag: Not using your name when a real company would.
Examples:
- "Dear Customer"
- "Dear User"
- "Hello Sir/Madam"
What to look for: Your bank knows your name and usually uses it.
Unprofessional Formatting
Red Flag: Poor design that doesn't match the company's usual style.
Examples:
- Blurry logos
- Misaligned text
- Inconsistent fonts
- Colors that don't match the brand
What to look for: Compare to real emails you've received from that company.
Attachment Red Flags
Unexpected Attachments
Red Flag: Files you didn't request, especially:
- .exe, .zip, .scr files
- "Invoices" you didn't expect
- "Important documents" from unknown senders
Pressure to Open
Red Flag: Urgency around attachments.
Example: "Open the attached form immediately to avoid account closure"
What Gini Does With This Information
When Gini scans your email, it:
- Checks the sender against known patterns
- Analyzes all links for suspicious destinations
- Scans content for urgency, threats, and data requests
- Looks at formatting and language quality
- Combines findings into a risk score
The more red flags found, the higher the risk level assigned.
Protect Yourself
Even with Gini protecting you:
- Never click links in suspicious emails - Go to websites directly
- Verify unexpected requests - Call the company using a known number
- Don't download unexpected attachments
- Trust your instincts - If something feels wrong, it probably is