AI phishing emails are scam messages written or polished with AI, and they no longer give themselves away with clumsy grammar. They can be fluent, personal and written in your own language. The good news is that the reliable warning signs were never really about spelling: they are about the sender, the request and the pressure, and you can learn to check those in a minute.
This guide explains what has changed with AI phishing emails, the signs that still work, a step-by-step way to check a suspicious message, how an AI assistant can help with that check safely, and what a small business should put in place.
What AI changed about phishing emails
Phishing is an attempt to trick someone into revealing passwords, payment details or other sensitive information, or into paying money or installing malware, by pretending to be a trusted sender. It is as old as e-mail. What AI changes is the cost of doing it well.
Better language, in every language
For years, poor grammar and odd phrasing were the easiest tells, especially in smaller languages such as Lithuanian, Latvian or Estonian. Language models write natural text in many languages, so a scam aimed at a Vilnius accountant can now read like it was written by a colleague.
Personalisation at scale
Attackers can feed public information, a company website, a LinkedIn profile or a press release, into an AI and get a message that mentions your real role, your supplier’s name or a project you announced. What used to be expensive targeted “spear phishing” becomes cheap.
Faster variations
Spam filters learn to recognise repeated text. AI can produce thousands of slightly different versions of the same lure, which makes simple pattern matching less effective.
What did not change
The attacker still needs you to do something: click, log in, pay, open an attachment or reply with information. That request, and the way it is pushed, is still where most scams can be caught.
Common AI phishing emails to expect
Most AI phishing emails follow a handful of well-worn scripts. Knowing them makes the next one easier to recognise, even when the wording is new.
The supplier with new bank details
A message that appears to come from a real supplier, often replying in an existing thread, says their bank has changed and the next invoice should be paid to a new account. AI makes the tone and terminology match the real supplier closely. The defence is procedural: never change payment details on the strength of an e-mail.
The urgent request from the boss
“Are you at your desk? I need you to handle a payment quietly before the board meeting.” The sender name is your managing director; the address is not. AI can imitate a manager’s style from public interviews or posts.
The account or delivery problem
Your mailbox is full, your parcel is held at customs, your subscription failed. A link leads to a perfect copy of a login or payment page. These messages rely on the fact that such notices are routine.
The recruiter or business opportunity
A tailored job offer or partnership proposal with an attachment or a “document portal” link. Personalisation from your public profile makes it feel genuine.
The fake AI tool or invoice for one
Increasingly common: an invoice or renewal notice for an AI subscription you do not use, or an invitation to try a new “AI assistant” that asks you to sign in with your work account. If a message names a tool your company pays for, check the subscription in the tool itself, never through the link. The same applies to Ask Mio or any other assistant: type the address yourself, sign in, and look at your account there, rather than following a billing link from an unexpected e-mail.
Warning signs that still work
Forget spelling mistakes as your main test. These signs remain reliable even when the writing is perfect.
- Urgency or fear. “Your account will be closed today”, “final notice”, “the CEO needs this before the meeting”.
- A change of routine. New bank details for a known supplier, a request to use a different payment method, a password reset you did not ask for.
- Requests to bypass process. “Keep this confidential”, “do not call, I am in a meeting”, “skip the usual approval”.
- Sender address mismatches. The display name says your bank; the actual address is a free mailbox or a look-alike domain with one letter changed.
- Links that do not go where they say. Hovering or long-pressing shows a different domain from the one in the text.
- Unexpected attachments. Invoices you were not expecting, especially archives or documents that ask you to “enable content”.
- Login pages reached from an e-mail. Any message that leads straight to a login form deserves suspicion.
The United Kingdom’s National Cyber Security Centre keeps a clear, practical collection on recognising and reporting phishing scams that is worth sharing with a team.
Old tells vs signs that still work
| Sign | Reliable before AI? | Reliable now? | Why |
|---|---|---|---|
| Spelling and grammar errors | Often | No | AI writes fluent text in many languages |
| Generic greeting (“Dear customer”) | Sometimes | Weak | AI personalises from public information |
| Sender domain mismatch | Yes | Yes | Attackers still cannot send from your bank’s real domain if it is protected |
| Urgency and pressure | Yes | Yes | The scam still needs a fast, unchecked action |
| Change of payment details | Yes | Yes | Classic invoice fraud pattern |
| Link domain differs from text | Yes | Yes | The landing page is controlled by the attacker |
| Request to bypass normal process | Yes | Yes | Process is what stops fraud |
How to check a suspicious email step by step
1. Stop and do not act from the message
Do not click links, open attachments, reply or call numbers printed in the message. Nothing legitimate is harmed by waiting ten minutes.
2. Look at the real sender address
Open the full sender details, not just the display name. Check the domain letter by letter: rnicrosoft instead of microsoft, an extra hyphen, a different country ending.
3. Check the links without clicking
Hover on a computer or long-press on a phone to see the real address. If the domain is not exactly the organisation’s own, treat it as hostile.
4. Verify through a separate channel
Call the supplier, colleague or bank using a number you already have, or log in by typing the address yourself. This one step defeats most invoice and CEO fraud, however convincing the e-mail.
5. Look at authentication results if you can
Many mail programs show whether a message passed SPF, DKIM and DMARC checks, often under “show original” or “message details”. A failed check on a message claiming to be from a large company is a strong warning sign. A pass only proves the message came from that domain, not that the domain is the one you think.
6. Report it
Forward it to your IT contact or use your mail program’s “report phishing” button, then delete it. If you already clicked or entered a password, change that password from a clean device straight away and tell whoever manages your accounts.
Using an AI assistant to check a message safely
An assistant can be a useful second opinion, as long as you use it carefully. It is not a security product, and its verdict is advice, not proof.
What works well
- Explaining the red flags. Paste the text of the message, with personal details removed, and ask: “List any signs this could be phishing and explain each one.”
- Reading headers. Raw e-mail headers are hard to read. An assistant can explain what the authentication lines and “Received” entries mean.
- Checking a domain. Ask whether a sender domain has proper mail records. Ask Mio includes a Domain & DNS check tool that looks up A, AAAA, MX, TXT and NS records and whether the site responds. Our AI domain DNS checker guide explains what those records mean.
- Training your team. Ask for realistic examples of phishing aimed at your industry to use in a short internal training session.
What to avoid
- Do not paste passwords, full account numbers or customer data into any chat. Our guide on what not to share with AI lists the categories.
- Do not ask an AI to open a suspicious link for you “to see what is there”. Check the domain instead.
- Do not treat “looks safe” as permission. If money or credentials are involved, still verify through a separate channel.
Phishing text can also try to manipulate an AI that reads your mail, for example by hiding instructions in the message. That is a form of prompt injection, and it is one reason why tools that act on your behalf should ask for confirmation. In Ask Mio, the Gmail and Microsoft 365 connectors are read-only, and e-mails to anyone other than yourself always wait for your confirmation.
What a small business should put in place
Individual vigilance helps, but a few rules protect a team even on a bad day.
- Payment changes need a phone call. Any change of supplier bank details is confirmed by phone, on a known number, by a second person.
- Multi-factor authentication everywhere. A stolen password is far less useful when a second factor is required.
- Protect your own domain. Set up SPF, DKIM and DMARC so attackers cannot easily send e-mail that appears to come from you.
- Make reporting easy and blame-free. People who report a click quickly limit the damage; people who fear blame stay silent.
- Short, regular training. Ten minutes a quarter with real, current examples beats a long annual course.
- A written AI use policy. Spell out what staff may paste into AI tools, including suspicious messages. Our AI privacy checklist for business is a good starting point.
Frequently Asked Questions
How can I tell if an email was written by AI?
Usually you cannot, and it does not matter much. AI detectors are unreliable, and plenty of legitimate e-mails are drafted with AI. Focus instead on what the message asks you to do and who really sent it: check the sender’s domain, the real link destinations, any request to change payment details or log in, and pressure to act quickly. Those signs reveal phishing whatever wrote the text.
Are AI phishing emails more dangerous than older ones?
They are harder to spot by language alone, because AI writes fluent, personalised text in many languages, including smaller ones. The underlying trick is the same, though: getting you to click, log in, pay or share information without checking. Verifying unusual requests through a separate channel and using multi-factor authentication stop most attacks, whether a person or an AI wrote the message.
Is it safe to paste a suspicious email into an AI assistant?
It is reasonably safe if you remove personal and sensitive details first, such as names, account numbers and signatures, and paste only the text or headers. Do not paste passwords or customer data, and do not ask the assistant to visit links in the message. Treat the assistant’s answer as a second opinion; if money or credentials are involved, still verify directly with the sender.
What should I do if I clicked a phishing link?
Do not panic, but act quickly. If you entered a password, change it at once from a device you trust, and change it anywhere else you used the same one. Turn on multi-factor authentication if it is not active. Tell your IT contact or account manager, and if you entered payment details, call your bank using the number on your card.
What are SPF, DKIM and DMARC?
They are e-mail authentication standards. SPF lists which servers may send mail for a domain, DKIM adds a cryptographic signature to messages, and DMARC tells receiving servers what to do when those checks fail and sends reports to the domain owner. Together they make it much harder for attackers to send e-mail that pretends to come from your domain.
The Bottom Line
AI phishing emails have made perfect grammar meaningless as a safety signal, but the signs that matter are unchanged: who really sent it, where the links go, what it asks you to do and how hard it pushes. Stop, check the sender and links, verify through a separate channel and report it. An assistant can explain red flags, headers and DNS records in plain language, as long as you strip personal data first. To try that kind of second opinion, see Ask Mio’s plans or start with the free plan.
