Skip to main content
Security & Privacy

The 7-second check that catches most phishing before you click

A seven-question checklist for the moment before you click, plus why the smartest people you know are still exactly the right target for it.

Barbara Corcoran, the investor from Shark Tank, lost nearly $400,000 to a phishing scam in 2020. The email appeared to come from her assistant, referenced a real renovation project, and came from an address one letter off from the real one. Her team caught it before the money was gone for good, but the scam worked well enough to get that far against someone whose entire career runs on evaluating risk for a living.

That's the detail worth sitting with: phishing doesn't succeed because targets are careless. It succeeds because it's built to arrive at the exact moment you're primed to respond fast: the invoice on the day you were already chasing an invoice, the "urgent" login request during a week you're genuinely stressed. Your rational brain isn't the one making the decision when you're rushed, and phishers know that better than most marketers know their own funnel.

Knowing the psychology helps, but it doesn't stop a click by itself. What stops a click is a fixed sequence you run automatically, before you act on anything that asks you to log in, pay, or hurry, regardless of how legitimate it feels in the moment.

The seven questions that take seven seconds

Phishing Exposed condenses its entire technical-detection chapter into what it calls the 7-Second Checklist, meant to run in your head before clicking anything in a message that feels even slightly off:

  1. Was I expecting this specific message from this sender?
  2. Does the sender's display name match their actual email address?
  3. Does the tone or urgency feel manipulative?
  4. Are there spelling or grammar errors a professional organization would catch?
  5. Does the message ask me to download something or enter credentials?
  6. Does hovering over links (without clicking) reveal suspicious URLs?
  7. Would this sender typically contact me through this channel?

A single "yes" warrants caution. Multiple "yes" answers are close to a guarantee. The book is explicit that this isn't a completeness test: you don't need all seven to line up, because a well-crafted attack won't trip most of them. It's a pattern-interrupt: the act of consciously running through the list, rather than reacting on instinct, is what buys you the moment of critical thinking the whole checklist exists to force.

Question two deserves particular attention, because it's the one modern attacks are built to survive a glance at. Display-name spoofing shows "PayPal Service" or "Amazon Customer Service" in the field you actually read, while the real sending address is something unrelated: the book's example is "[email protected]." Most email clients show the display name prominently and bury the actual address, so the checklist only works if you actually open it and look, not if you register that a familiar name flashed past.

Question six is the other one worth practicing deliberately, because the underlying trick has gotten harder to spot on sight. Attackers now register domains using visually identical Unicode characters (replacing the Latin "a" in "amazon.com" with a Cyrillic look-alike, for instance), so the URL your eye reads as correct isn't the one your browser will actually load. Hovering to preview the real destination catches this even when the domain looks perfect at a glance. On mobile, a long press does the same job.

Where people go wrong

The single most common mistake is the overconfidence trap the book names directly: "I'm too savvy to fall for this." It's the exact belief that made the Corcoran case and the 2020 Twitter account takeover work: both involved people and companies with above-average security awareness, caught not because they were careless but because the attack was timed and personalized well enough to slip past a moment of genuine distraction.

The second is trusting visual cues that no longer mean anything. The padlock icon in the address bar used to be shorthand for "safe," but free SSL certificates are trivial to obtain now, and a convincing fake site will have one too. The padlock confirms the connection is encrypted. It says nothing about who's on the other end.

The third is treating detection as a one-time skill rather than a habit that decays. Tactics shift: AI-generated phishing text has eliminated most of the spelling errors that used to be an easy tell, and voice-cloning scams didn't exist in a practical form five years ago. The full digital safety guide covers the account-hardening side of this (password managers and two-factor authentication), which matters precisely because detection has a failure rate no checklist gets to zero, and a second factor is what limits the damage when a well-timed attack gets through anyway.

What's in the kit

Inside Phishing Exposed

Going deeper

  • AudioDon't Take the Bait
  • BookPhishing Exposed
  • ChecklistFull Device Protection
  • ChecklistPost-Phishing Incident Response
  • GuideThe 7-Second Phishing Detection Protocol
  • Listicle12 Quick Checks to Expose a Phishing Scam
  • Mini-Course7-Day to Outsmart Every Phishing Scam
See the full kit: $9

Phishing Exposed is one of 5 bundles in The Digital Safety Pack, or take the whole pack for $29.