Email security

Phishing

Mail built to trick you into giving something away: a password, a payment, or a click that installs something harmful.

Last reviewed · July 2026

Overview

Phishing is mail designed to extract something from you: a password, a payment, a signature on a document, or a click that installs something harmful. It is the attack the other pages in this section orbit around, because spoofed senders and impersonated brands exist mostly to make a phishing ask land.

How attackers abuse it

A phishing message usually borrows trust first: a spoofed sender, a copied logo, an urgent tone. Then comes the ask. “Verify your account.” “Your invoice is overdue.” “Sign in to view this file.” The links behind those buttons often lead to look-alike sign-in pages dressed up as the real thing.

The tell is the combination, not either half alone. Plenty of honest mail asks you to sign in; plenty of honest mail comes from brands. A borrowed identity plus a request that would hand over access or money is the phishing signature.

In short:

Phishing combines a borrowed identity with a request for access or money. Look for both together, not just one.

What Sieve shows you

When Sieve files a phishing attempt as Malicious, your dashboard shows the reasons in this section's vocabulary: an unsafe link, a claimed brand the sender cannot back up, an authentication failure. The message is filed under a label in your Gmail, never deleted.

If a flag is wrong, drag the message back to your inbox or restore it from the dashboard. One correction restores the message and teaches your own filter about that sender.

Further reading: Avoid and report phishing (Google)