How to Spot AI‑Generated Phishing Emails Before They Hit Your Inbox
— News — By Gethyn Jones
We walk you through the exact steps we take on the bench to identify AI‑crafted phishing mails and keep your devices safe.
You're at the kitchen table, coffee in hand, when the laptop chimes – an email from "Your Bank" asking you to confirm a "suspicious login" by clicking a button that looks exactly like the bank’s logo. Is the sender really who they claim to be? – check the address first We start by hovering over the sender name. If the address reads something like security@bank‑alerts.co.uk instead of the official security@yourbank.co.uk , that’s a red flag. On the bench we open the full header (right‑click → "View Message Source" in Outlook or "Show original" in Gmail) and look for the From: and Return‑Path: fields. Mismatched domains, extra sub‑domains or a misspelt bank name are classic AI‑generated tricks. Does the email contain weird phrasing or odd grammar? AI‑generated text can sound fluent but often slips on idiom or context. We read the body aloud – does "your account has been temporarily disabled" sit naturally, or does it feel like a literal translation? Look for: Unusual capitalisation – e.g. "Your Account" in the middle of a sentence. Mixed UK/US spelling – "colour" alongside "realize". Generic greetings – "Dear Customer" instead of your name. If any of those pop up, we flag it. Are the links really pointing where they say? We never click. Instead we hover and copy‑paste the URL into VirusTotal (or a local URL scanner). On the bench we also use the nslookup command to see where the domain resolves. If the link shows bank‑alerts.co.uk/login but the actual URL resolves to 192.168.1.
For expert IT support, contact CefniTech — friendly, local IT support for homes and businesses across the UK.