Live trends from phishing emails reported by the LureSight community. Every submission is scrubbed of personal information and carries no identifier linking it to the reporter — what you see here is the attackers, not the reporters.
The tricks behind the numbers above — every one of these has been seen in real reported mail, and every one is something LureSight checks for.
Domains built to pass a glance: paypa1-secure.com, rnicrosoft-login.top —
swapped letters, brand-plus-extra-words, risky endings like .top.
The words say paypal.com; the link opens somewhere else entirely — sometimes hidden
behind redirectors, security-gateway wrappers, or base64 encoding.
A fake charge — "$486.77 renewed" — and a phone number to call to cancel. No links at all; the scam happens on the phone, where no filter can follow.
Tell: real companies let you manage charges in your account. Never call numbers from the email.The link is hidden inside a QR code image, so email security can't read it — and scanning moves you onto your phone, away from protection.
Tell: a legitimate sender has no reason to make you scan a code from an email on the same device.The entire "invoice" is one big picture — amounts, threats, and phone numbers rendered as pixels that text filters can't see.
Tell: if you can't select the text with your cursor, someone chose to hide it from scanners.Real logos (often hotlinked from Wikipedia), copied email templates, and display names one letter off — "DocSign" — from mailboxes with no connection to the brand.
Tell: check the actual sending address and where links point, not the pictures.A real colleague or vendor's hacked mailbox mails their whole contact list a fake "attachment" —
a link dressed as Document.pdf that opens a file-sharing site.
"Personalized" to random-character names ("Hello Uvpixhuymn"), pushing government-benefit or prize lures with fine print admitting it's a "non-government site."
Tell: agencies mail from .gov, and real senders know your actual name.The message presents itself as being from a company — in the signature, the footer, or the display name — but the address it was actually sent from is an unrelated domain. Works for any organization, not just famous brands.
Tell: read the actual email address, not the display name. "Meridian Bank" from a gmail.com or asecure-pay-portal.top address is not Meridian Bank."You've been selected" for an airdrop, token eligibility, or fee rebate — enter a code or
claim link to unlock rewards. Often invokes a real crypto or prediction-market brand
(Polymarket, Coinbase) from an unrelated sender.
"Within 24 hours," "account suspended," "verify immediately," secrecy and "quick favor" asks — urgency exists to make you act before you think.
Tell: manufactured deadlines are the oldest trick there is. Slow down; verify independently.SPF, DKIM, and DMARC are how mail proves who sent it. Failures — or "passing" only because the scammer used a real free-mail account — are hidden in the headers.
Tell: you can't see headers easily, which is exactly why LureSight reads them for you.