MALWARE AND PHISHING CyberArtical Editorial Team

Perfect spelling is no longer a sign that an email is genuine

Hands resting on a laptop keyboard in front of a red screen reading that the user's personal files have been encrypted

For twenty years the standard consumer phishing tip was to look for bad English. Misspellings, odd capitals, a stray comma where a full stop belonged. That tip is now retired, and not by a security vendor with something to sell: CISA’s own phishing page says that in the era of artificial intelligence some emails will have perfect grammar and spelling, and tells readers to look out for the other signs instead.

What changed and what didn’t

  • CISA: “in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”
  • The signs CISA still lists: urgent or emotionally appealing language claiming dire consequences, requests for personal and financial information, untrusted shortened URLs, and incorrect addresses or links such as amazan.com.
  • CISA’s verification rule: “Look up another way to contact the company or person directly” — never the number or link in the message.
  • CISA’s action sequence is resist, report, delete. Do not reply.
  • Phishing and spoofing was the most-reported crime type in the 2025 IC3 report at 191,561 complaints.

The tell you were taught, and why it worked

The grammar tip worked because it was a proxy for effort. Writing fluent, idiomatic English at scale used to be expensive, so a message that read badly was cheap, and cheap correlated with fraudulent. Readers were effectively grading the attacker’s budget.

The proxy has broken. Fluent text is no longer expensive, and CISA has updated its consumer guidance to say so directly. That single sentence retires the most-repeated phishing tip in circulation.

The signs CISA still lists

The FTC’s list of pretexts sits alongside this and is worth reading as a set, because it describes the story rather than the typography: claims of suspicious activity or log-in attempts that never happened, a problem with your account or payment information that does not exist, a request to confirm personal or financial information you never needed to confirm, an invoice you do not recognise, a payment link where the link has malware, an offer of a government refund, and a coupon for free stuff.

  • Urgent or emotionally appealing language, especially anything claiming dire consequences if you do not act.
  • Requests to send personal or financial information.
  • Untrusted shortened URLs.
  • Incorrect email addresses or links — CISA’s worked example is a link to amazan.com rather than the real domain.

Verification you can do without the sender’s help

The reason the grammar tip mattered so much is that it was the only check most people had that did not involve trusting the message. There is a better one, and it has been in CISA’s guidance all along: look up another way to contact the company or person directly.

That means the number on the back of your card, the app you already have installed, a URL you type yourself. Not the number in the email, not the reply button, not the helpful link at the bottom. This check does not care how well the message is written, which is exactly why it survived the change that killed the grammar tip.

The same logic applies to visual polish. A convincing logo, a valid-looking sender name and a padlock in the address bar are all now cheap. The FBI’s public service announcement on that last point is unusually direct: do not trust a website just because it has a lock icon or “https” in the browser address bar.

Resist, report, delete

If you already gave something away, the route changes. The FTC’s instruction is that if you think a scammer has your information — Social Security number, credit card or bank account number — go to IdentityTheft.gov. If you think you downloaded something, update your security software and run a scan.

  1. Resist the temptation to click links or attachments.
  2. Report it — use your mail client’s report option or the “report spam” button, forward phishing email to reportphishing@apwg.org, forward phishing texts to SPAM (7726), and file the report at ReportFraud.ftc.gov.
  3. Delete the message. Do not reply and do not click any attachment or link.

Why the grammar advice is taking so long to die

It is memorable, it is free to give, and it flatters the reader. Telling someone they can spot a criminal by their punctuation is a more appealing message than telling them to phone the bank on a number they looked up themselves.

It is also the kind of tip that survives copying. Consumer security articles are frequently written from other consumer security articles, so a line that entered circulation in the 2000s can still be repeated in 2026 without anyone checking whether the source that originated it has since changed its mind. In this case the source has, and said so on the page.

If you want one sentence to put in its place, use CISA’s own: some emails will now have perfect grammar and spelling, so look out for the other signs. Then teach the other signs — urgency, requests for personal or financial data, untrusted shortened URLs, near-miss domains — and the habit of ringing back on a number you looked up yourself.

Sources: CISA — Recognize and report phishing · FTC — How to recognize and avoid phishing scams · FBI IC3 — PSA on the HTTPS padlock (I-061019-PSA) · FBI IC3 — 2025 Internet Crime Report

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories