Summary: Scammers use AI to write their phishing emails now, so the spelling and grammar mistakes that used to give them away are gone. The UK’s National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal, and harder to catch. If you want to know how to spot a scam email today, stop reading how it’s written and start reading what it’s asking you to do.
For years, learning how to spot a scam email came down to one rule: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it worked.
It doesn’t anymore. Attackers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know.
The good news: the tells didn’t disappear. They moved, and how to spot a scam email is still a teachable skill. Below is what still works, what to teach your team this week, and what to do if someone has already clicked.

How to spot a scam email: why the old advice stopped working
The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed. AI took that away.
The UK’s National Cyber Security Centre says generative AI can now create convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake, so it reads as believable.
That means the one thing most people were trained to look for no longer tells you much. If your security awareness training still leads with “watch for typos,” it’s teaching your team to trust a signal that stopped working.
Why AI phishing emails are so convincing now
- The writing is clean. A scam email reads like a normal business email, because a machine wrote it in seconds, in whatever tone the attacker asked for.
- It’s personal. Attackers can feed public details about your company into an AI tool — pulled from your website, your team’s LinkedIn profiles, or a press release — and get a message tailored to you: the right names, the right job titles, and a believable reason to be in touch.
- There’s more of it. AI makes each message faster to produce, so attackers send far more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses.
- It arrives at the right moment. A message referencing a project that’s genuinely in flight, or a renewal that’s genuinely due, doesn’t feel like a cold approach. It feels like Tuesday.
These days, the scam email isn’t the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in your finance team gets a message that looks like it’s from a supplier they really deal with, mentions a real project, and asks to update the bank details for the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.
Your spam filter won’t catch every AI phishing email
It’s tempting to assume your email security will handle this. It catches a lot, and you should keep it switched on and properly tuned.
But a well-written, personalized email that asks a normal-sounding question doesn’t always look dangerous to a filter — especially when it carries no obvious bad link or attachment. There’s nothing technically wrong with a plain-text message asking a colleague to confirm an account number. It also helps to make your own domain harder to impersonate — that’s what SPF, DKIM and DMARC records are for. Both the NCSC and the FBI expect AI to push more of these messages through.
Which is why the last line of defense is a person who knows what to check. Filtering reduces the volume; judgment catches what gets through. You need both, and most businesses have only invested in the first. If you’d like a second opinion on how your email security is configured, that’s the kind of thing our managed IT and cybersecurity services are built to review.
How to spot a scam email: 7 warning signs that still work
If you can’t trust how an email is written, look at what it’s asking you to do. That’s where the real phishing email warning signs are, and AI hasn’t changed them:
- It asks for money — a payment, a gift card, or a transfer to a new account.
- It asks for a login, a verification code, or personal details.
- It creates pressure — a deadline, a threat, or a “do this now before the end of day.”
- It asks you to change bank details for an invoice or a supplier.
- It arrives with a link or attachment you weren’t expecting, even from a familiar name.
- The display name looks right, but the actual email address doesn’t match it.
- It steers you off your normal process — “don’t loop in accounts payable,” “just handle this one directly,” “I’m in meetings all day, email only.”
Every one of these is about what the email is asking for, not how it reads. So the rule to teach your team is simple: when a message is about money, logins, or how you pay someone, slow down before you act.
The 60-second check anyone can run
Knowing how to spot a scam email doesn’t take technical skill. Give your team four questions and a minute:
- What is this asking me to do? Money, credentials, or a process change puts it in the “verify” pile automatically.
- Was I expecting it? An unprompted invoice, password reset, or document share deserves a pause.
- Who is it really from? Expand the sender field and read the full address, not the display name. Check for a lookalike domain — a swapped letter, an extra hyphen, a .co instead of .com.
- Can I confirm it another way? Call a number you already have. Not the number in the email.
Sixty seconds of verification costs nothing. A wire sent to the wrong account is rarely recoverable.
Phishing email warning signs now show up outside your inbox
AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip — enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment.

The same technology that makes AI phishing emails convincing makes AI phone scams convincing too. A text message asking you to approve a login, a call from “your bank’s fraud team,” a voicemail from a director who never left one — all of it is cheaper and more believable than it was two years ago.
The defense doesn’t change: if a call, text, or voicemail asks for money or logins, hang up and call the person back on a number you already have. Teach the channel-switch as a habit, not an exception.
How to protect your team from AI phishing emails
- Verify money and login requests another way. If an email asks you to pay a new account or change a supplier’s bank details, call the person on a number you already have. Don’t reply to the email or use a number it gives you.
- Stop telling staff to watch for bad spelling. Tell them to look at what the email is asking for, and to slow down when it’s about money or logins.
- Make one rule for payment changes: confirm every change to bank details by phone, every time, even when it’s urgent. Especially when it’s urgent.
- Turn on phishing-resistant MFA or passkeys, so a stolen password is harder to use even if someone gets tricked. This is the single highest-value change most small businesses haven’t made yet.
- Set a dollar threshold that requires two people. Above a number you choose, no payment or banking change goes out on one person’s approval.
- Make it easy to report a suspicious email — one button, one address — and make sure nobody feels silly for checking. A team that reports freely catches things a filter never will.
- Remind the team now and then that scam emails look perfect these days. A quick five-minute chat beats a poster nobody reads.
None of this requires a big security budget. Teaching people how to spot a scam email takes a policy, a phone call, and a team that knows the policy exists.

What to do if someone already clicked
Assume it will happen eventually. Speed matters more than blame:
- Change the password immediately and sign out all active sessions for that account.
- Check for mailbox rules you didn’t create. Attackers commonly add a forwarding or auto-delete rule to hide their tracks — this is one of the first things to look for.
- If money moved, call the bank now. Fraudulent transfers are sometimes recoverable in the first hours and almost never after that.
- Tell your IT provider so they can check whether anything else was accessed and whether other accounts are exposed.
- Report it. In the US, file with the FBI’s IC3. Reporting is also how these patterns get tracked.
- Warn the rest of the team. The same message is almost certainly in other inboxes.
Take the next step
If you’re not sure whether your email security, MFA setup, or payment-approval process would hold up against a well-written AI phishing email, that’s a short conversation — not a project. We’ll walk through what you have, what’s exposed, and what’s worth fixing first — the same ground we cover in a security posture review.
Frequently asked questions about how to spot a scam email
Can you still spot a scam email by bad spelling and grammar?
Not reliably. If you learned how to spot a scam email by hunting for typos, that method is done. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it asks you to do.
What phishing email warning signs still work?
The request itself: paying money, changing bank details, sharing a login or code, or being pushed to act urgently. Those signs don’t depend on how the email reads, which is exactly why they’ve survived.
Are AI phishing emails really more effective?
Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal, and the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions in reported losses. Cleaner, tailored messages get opened and clicked more often.
Will my spam filter stop AI phishing emails?
It will catch a lot, and you should keep it on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone. A trained person is the backstop.
What should staff do if they aren’t sure about a message?
Slow down and check through a channel they trust — calling a known number or asking the person directly. And report it, even if it turns out to be genuine. A team that over-reports is far cheaper than one that stays quiet.
How often should we train the team on how to spot a scam email?
Short and frequent beats long and annual. A five-minute reminder each quarter, plus a note whenever something real lands in the inbox, keeps it current far better than a once-a-year session everyone forgets by February.
Sources and further reading
- NCSC: The near-term impact of AI on the cyber threat — the UK cyber agency on AI producing phishing lures without the usual spelling and grammar mistakes.
- FBI IC3: Criminals Use Generative AI to Facilitate Financial Fraud — how criminals use AI-generated text and cloned voices, and how it removes the usual signs of fraud.
- CISA: Recognize and Report Phishing — plain-language guidance you can hand straight to your team.
—
This Article has been Republished with Permission from The Technology Press.
