An AI-written phishing email rarely gives itself away through spelling or grammar anymore. The tells that survive good writing are structural: a request that skips your organization’s normal approval channel, and a sender identity that doesn’t match where the message actually came from.
Takeaways
- AI-written phishing emails rarely contain grammar mistakes anymore, so the writing quality of a message is no longer proof that it’s legitimate.
- Manufactured urgency, like a deadline of a few minutes or an instruction to skip your company’s normal approval process, is a more reliable warning sign than anything about how the email is written.
- Verifying a request through a channel the email itself did not provide, such as a saved phone number or a manually typed web address, catches attempts that slip past every other check.
- Checking the sending domain character by character catches lookalike addresses that a display name alone will never reveal.
- Reporting a phishing email to your employer’s security team or the FBI’s Internet Crime Complaint Center helps defenders block the same message from reaching other people, while deleting it protects only you.
| Old tell | Typos, broken grammar |
|---|---|
| New signal | Manufactured urgency |
| Best defense | Out-of-band verification |
| Where to report | FBI IC3, employer security team |
Is perfect grammar still a giveaway?
No. For years, security awareness training told people to look for typos and broken grammar as proof an email was fake, which worked because most phishing came from templates written by non-native English speakers. Large language models removed that tell entirely. A 2023 study led by researcher Julian Hazell, published on arXiv, found AI-generated spear-phishing messages persuaded recipients to click at rates matching messages written by trained human red-teamers, at a fraction of the time cost. The Federal Trade Commission’s phishing guidance still lists spelling and grammar among its warning signs, which is incomplete advice for anything drafted by a language model. Verizon’s 2024 Data Breach Investigations Report found 68% of breaches involved a non-malicious human element such as clicking a link, a number grammar checks were never going to move on their own.
What tone tells give it away?
AI-written phishing tends to be too smooth in one specific way: it stays evenly polished from the first line to the last, without the natural variation in energy a genuine, rushed colleague writes with. A legitimate request from your manager usually has some friction in it, a half-finished sentence or a specific detail only they would know. A model-generated message reads as if it was proofread by someone with infinite patience, because it was. OpenAI documented state-linked groups using its models to draft and refine phishing content in a February 2024 report on disrupting malicious use of its tools. The UK’s National Cyber Security Centre concluded in a January 2024 assessment that AI would almost certainly increase the volume and believability of phishing over the following two years. I’ve written before about how these models generate fluent, context-aware text in the first place, and that same fluency is what strips away the old tells.
Why urgency is the strongest tell
Urgency is the tell that survives every generation of phishing, AI included, because urgency is what makes a scam work regardless of how well it’s written. A message pushing you to act within minutes, skip a normal approval step, or keep a request from a colleague is doing the actual manipulation, and no amount of polished sentence-level writing changes that structure. CISA’s phishing guidance lists pressure to bypass procedure as a consistent marker across campaigns, regardless of how they’re written. I’ve argued before that click rate is the wrong way to measure how ready people are for these attempts, because it rewards spotting bad grammar rather than manufactured urgency. Train yourself to notice the ask, not the writing quality. If a message is telling you not to double check, that instruction is the scam.
Six checks, ranked by what works
These six checks are ranked by how often each one catches an AI-written phishing attempt, from the check that works almost every time to the one that only helps occasionally.
- Hover before you click. Check where a link points, not what the text claims it points to; Google’s phishing guidance walks through how, and it applies to any email client.
- Check the sending domain character by character. A lookalike domain, like an rn swapped for an m, is still the most common way a legitimate-looking sender turns out fake.
- Call the person back on a number you already had. Never use a number or reply address the email itself supplies.
- Ask whether the request matches how this person or company normally operates. A vendor asking you to change payment details by email alone is a pattern Microsoft’s Digital Defense Report flags as a recurring business email compromise tactic.
- Check if your email already shows up in a known breach. Have I Been Pwned shows whether attackers already have genuine details about you to personalize a message with.
- Look for a request with no verifiable specifics. Legitimate correspondence usually references a specific order number or a prior conversation; AI-written lures often stay generic because the model has nothing genuine to reference, a gap SANS security awareness training teaches people to notice.
Does the sender address ever lie?
Yes, constantly, and it’s a more reliable indicator than anything about the writing itself. Display names are trivial to fake, so a message can show your CEO’s name while originating from a domain registered days earlier. Check the sending address itself, not just the name attached to it, and check whether the reply-to address matches the from address at all. Google Safe Browsing maintains a list of known malicious domains that most browsers check against automatically, which is one reason a warning banner is worth taking seriously rather than dismissing as overcautious. IBM’s X-Force Threat Intelligence Index has tracked criminals increasingly using generative tools to scale up lookalike domains alongside lure text, meaning the domain check counts for more now, not less, even as the prose gets harder to flag on its own.
What should you do before you click?
Before you click anything, separate the request from the writing and verify it through a channel the email itself did not provide. That means opening a new browser tab and typing the company’s known address yourself instead of clicking the one supplied, or calling a number saved from a previous legitimate interaction. Proofpoint’s State of the Phish report has tracked organizations for years and consistently finds that people who verify out-of-band catch attempts that slip past every other filter. This counts for more as AI agents start reading and drafting replies inside your inbox for you. I’ve written about why cheaper AI agents haven’t made the systems around them safer, and an agent that clicks through or replies on your behalf removes the one human pause that catches most of these attempts.
Where do you report it?
Report it instead of deleting it, because your report is what lets defenders spot the same pattern across other targets. In the US, forward it to your employer’s security team and to the FBI’s Internet Crime Complaint Center. The Anti-Phishing Working Group collects reports globally and feeds them into shared blocklists used across the industry, documented in its ongoing phishing trends reports. In the UK, Action Fraud is the equivalent reporting channel. Deleting a phishing email protects only you; reporting it protects everyone else it was also sent to.
Prompts you can use
Paste these straight in. Change the parts in square brackets and nothing else.
You are a cautious, security-aware colleague, not a cybersecurity expert giving me a technical verdict. I'm going to paste the full text and headers of an email I received, with any passwords, account numbers, or personal identifiers replaced by placeholders first. Based only on what I paste, walk me through: 1) which details in the wording feel generic or templated versus specific to a genuine relationship I'd have with this sender, 2) whether the urgency or the request to bypass a normal process stands out, 3) what the sending domain and any links suggest, if I include them, and 4) what out-of-band step I should take to verify this before acting on it. Do not tell me definitively that it is or isn't phishing; give me the evidence and let me decide, and ask me clarifying questions if you need more context about who the sender claims to be.
Replace any actual passwords, account numbers, or personal details with placeholders before pasting an email into an AI tool, even one you trust.
Help me write a short, calm script I can use to verify an unusual request I received by email, in case I need to call the person or company back to confirm it's genuine. Context: [describe the request, e.g. 'a vendor asking me to update the bank account we send payments to']. The script should be four to six sentences, sound natural rather than accusatory, and end with me asking them to confirm the detail in question through the phone call itself rather than by replying to the email. Assume I'll be calling a number I already had on file, not one provided in the email.
Fill in the actual context in the brackets before using it; a generic script won’t reference the specific request convincingly.
I want to report a phishing email I received to my company's security team. Turn the following raw details into a short, clear writeup: sender address, subject line, what the email asked me to do, and why it seemed suspicious to me. [Paste your notes here]. Keep it under 150 words, use plain language, and structure it so a security analyst can act on it immediately without needing to ask me follow-up questions first.
Attach the original email as a file or forward it separately if your company’s process requires that; this prompt only turns your notes into the writeup.
Questions people actually ask
Can AI detection tools tell me if an email was written by AI?
Not reliably. AI text detectors have high error rates on short, edited text like an email, and attackers can easily paraphrase output to dodge them. Treat detection tools as a weak extra indicator at best, and rely on verifying the request itself rather than trying to prove who or what wrote the sentences.
Why do phishing emails look so professional now?
Because large language models write fluent, well-structured text by default, removing the grammar mistakes that used to flag scams written off templates by non-native speakers. A 2023 study on arXiv found AI-written phishing performed as well as messages written by trained humans.
Is it safe to click a link if the email looks like it’s from someone I know?
No. Display names are easy to fake, and a message can show a colleague’s name while coming from a different domain entirely. Check the sending address and verify unusual requests by calling or messaging the person through a channel the email did not provide.
What should I do if I already clicked a phishing link?
Disconnect from the network and change any passwords you entered. Then check a service like Have I Been Pwned for exposed credentials, and report the incident to your employer’s security team immediately, since catching it fast limits damage more than catching it perfectly.
Does reporting a phishing email do anything?
Yes. Reports feed shared blocklists run by groups like the Anti-Phishing Working Group and national agencies such as the FBI’s Internet Crime Complaint Center, which get flagged domains blocked for other potential targets faster. A single report can protect people well outside your own inbox.
Sources
- arXivarxiv.org
- Federal Trade Commission’s phishing guidanceconsumer.ftc.gov
- 2024 Data Breach Investigations Reportverizon.com
- February 2024 reportopenai.com
- January 2024 assessmentncsc.gov.uk
- phishing guidancecisa.gov
- Google’s phishing guidancesupport.google.com
- Microsoft’s Digital Defense Reportmicrosoft.com
- Have I Been Pwnedhaveibeenpwned.com
- SANS security awareness trainingsans.org
- Google Safe Browsingsafebrowsing.google.com
- X-Force Threat Intelligence Indexibm.com
- State of the Phish reportproofpoint.com
- FBI’s Internet Crime Complaint Centeric3.gov
- Anti-Phishing Working Groupapwg.org
- phishing trends reportsapwg.org
- Action Fraudactionfraud.police.uk
What happens next
Expect phishing detection tools to lean harder on behavioral and domain indicators rather than language patterns, since AI has closed the writing-quality gap for good. Watch how email providers like Google and Microsoft update their built-in warnings as AI-generated lures keep improving. Also watch whether AI agents that read and act on your inbox get default safeguards before they get default access.
Take this further
Act as a blunt hiring manager who has read ten thousand resumes, not a career coach. I will paste my full resume and the job description I want. Rewrite the whole resume for that role, section by section, in this order: summary, experience, skills, education. Rules: every experience line leads with impact, not duty. Use bracketed placeholders like [8 percent] for any number I did not give you, and list at the end every placeholder I need to replace with a real figure. Keep it to one page of text. Plain formatting only, no tables or columns, so screening software can parse it. After the rewrite, tell me the three weakest claims that need evidence before I send this anywhere. My resume: [paste resume]. The role: [paste job description].

