You cannot rely on typos to spot phishing emails

On this page
  1. The quality filter
  2. A new standard

A typical phishing email from fifteen years ago often looked like a disaster. It might have started with a greeting such as Dear Customer and contained words that were almost, but not quite, spelled correctly. Phishing is the practice of sending fraudulent emails to trick people into revealing sensitive data or installing malware, which is malicious software designed to damage or disable computers. For years, the standard advice for spotting these messages was simple: look for the typos.

The quality filter#

This advice was reasonable. Many early attackers operated from regions where English was not the primary language. They relied on primitive translation tools that produced clunky phrasing and obvious spelling errors. A person who noticed a misspelled word in a supposedly official bank email could feel confident that the message was a fake. It seemed logical that a multi-billion pound financial institution would employ someone capable of using a spellchecker.

There is another reason for the poor grammar. Some attackers used bad spelling as a filter. The goal of a phishing campaign is not to trick everyone, but to find the most vulnerable targets. Someone who ignores several blatant typos is more likely to follow a suspicious link or provide a password without questioning the request. A person who stops to analyse the grammar is already too alert to be an easy target. By leaving errors in the text, the attacker avoids wasting time on sceptical people and focuses on those most likely to comply. It is a cold form of efficiency; the typos act as a sieve to remove anyone with a critical eye.

A new standard#

The situation has changed because the tools available to attackers have improved. The arrival of Large Language Models has removed the language barrier. These are computer programs trained on vast amounts of text that can generate human-like prose with perfect grammar and a professional tone. An attacker no longer needs to be a native speaker to write a convincing email. They simply tell the software to write a formal notice from a bank, and the result is linguistically flawless.

Many modern attacks do not even involve writing new text from scratch. Attackers often copy real emails from corporate organisations. They find a genuine internal memo about a policy change or a payroll update and mirror the style exactly. This includes using specific corporate jargon and following the expected layout of a professional business message. The result is an email that looks identical to a legitimate communication because it was based on one.

Relying on spelling as a defence creates a dangerous blind spot. A person who believes that bad grammar equals a scam may assume that a perfectly written email is safe. This overconfidence is exactly what the attacker wants. When the red flags in the text disappear, the reader stops questioning the source of the message and begins to trust the content.

The focus must shift from how a message is written to what it is asking for. The context is more important than the grammar. A request for a password or an urgent wire transfer is suspicious regardless of whether the spelling is flawless. One should consider if the sender normally makes such requests and why the urgency exists. If a request seems unusual, the safest path is to verify it through a separate channel.

If an email asks for sensitive information or a sudden payment, ignore the quality of the prose. Contact the alleged sender using a known phone number or a fresh email thread. Do not click links in the original message to do this. Check the official company portal directly rather than following a provided link.

Frequently asked questions#

How do I spot a phishing email if there are no typos?

Look for unusual requests, suspicious sender addresses, or urgent demands for sensitive data. Even if the grammar is perfect, attackers often create a false sense of urgency to pressure recipients into acting quickly without thinking. Verifying the request through a separate, trusted communication channel is the safest way to confirm legitimacy.

Why do some phishing emails have bad spelling?

Some attackers use poor grammar as a filter to find vulnerable targets. People who overlook obvious mistakes are more likely to follow malicious links or provide passwords. By leaving errors in the text, criminals avoid wasting time on sceptical individuals and focus their efforts on those most likely to comply with fraudulent requests.

Can AI make phishing emails look real?

Large Language Models allow attackers to generate professional prose with perfect grammar regardless of their native language. These tools can mimic the tone of a bank or corporate entity, removing the traditional red flags. This means that linguistic flaws are no longer a reliable way to identify whether an email is fraudulent or genuine.

Sources & further reading