How to spot a fake Microsoft or Amazon email before it costs you

Fake emails impersonating Microsoft and Amazon are among the most effective phishing attacks. They work because people expect emails from these companies, the logos look right, and the messages feel urgent. But most of them have tells, and knowing what to look for stops them cold.
Check the sender's actual email address
This is the single most reliable catch. Attackers can make the display name say anything, but the actual email address is harder to spoof. A real Microsoft email comes from a domain that ends in @microsoft.com or a closely related Microsoft domain. A real Amazon email comes from @amazon.com or Amazon's approved domains.
Here's how to check: hover over the sender's name without clicking. Your email client will show you the actual email address behind the display name. If it says "Microsoft Support" but the address is support@microsft-help.com or noreply@service-alerts.net, it's fake. Misspellings and unfamiliar domains are the biggest red flag.
Real Microsoft domains include microsoft.com, onmicrosoft.com, and a few others, but not random variations. Real Amazon domains are amazon.com or amazonses.com. If the address doesn't match, delete it.
Look for urgent language and requests to verify information
Phishing emails create panic to make you act fast. They'll say your account is locked, your password has been compromised, or your payment method failed. Then they ask you to click a link to verify your identity, confirm your password, or update your payment information.
Real Microsoft and Amazon emails rarely ask you to verify sensitive information by email. If they do, they'll ask you to go directly to the website yourself (by typing the address in your browser, not clicking a link) and log in from there. They won't ask for your password in an email, ever.
If an email creates urgency and asks you to click a link to confirm personal details, assume it's fake. Legitimate companies know better than to put sensitive actions behind email links.
Test the links without clicking them
Phishing emails work because they look like they come from the real company and the link looks legitimate at first glance. But the actual destination is fake.
Before you click any link, hover over it (don't click). Your email client will show you the actual URL it goes to. A real Microsoft link goes to a domain under microsoft.com or onmicrosoft.com. A real Amazon link goes to amazon.com or a verified Amazon domain. If the link goes to anything else, it's a phishing attempt.
Look closely at the domain. Attackers use tricks like microsft.com (missing the second 'i'), am4zon.com (replacing letters with numbers), or completely unrelated domains. When in doubt, go to the website directly: open a new browser tab, type the address yourself, and log in from there instead of using the email link.
Watch for generic greetings and poor formatting
Real companies personalize their emails. If the email says "Dear Customer" or "Dear User" instead of your actual name, that's a sign it came from a bulk phishing campaign, not a company that has your account details.
Also look at the quality of the message. Spelling mistakes, awkward grammar, and misaligned images are common in phishing emails. Real companies have QA processes and professional templates. If something looks off or rushed, trust that instinct.
Real Microsoft and Amazon emails are also specific. They mention the specific service (your Microsoft 365 account, your AWS account, your Amazon order number). Vague threats about "your account" without details are usually fake.
When in doubt, contact the company directly
If an email makes you nervous and you can't tell whether it's real, don't use the contact information in the email. Open a new browser, go to the official website, and contact them directly from there. You can ask whether they sent the email and what it was about.
Most phishing attacks succeed because one person clicks one link. A moment of caution saves the cost of a breach. If you've already clicked a suspicious link, change your password immediately and watch your account for unauthorized activity. If your cybersecurity defenses are in place, your email security should catch most phishing before it reaches you anyway, but a human check is always the last line of defense.
