Suspicious email with polished wording beside a verification checklist and warning symbol
← Rampart blog
Email

AI can write the scam email now. Here's how to check it before you click

The short answer

Do not use grammar as your main test anymore. An AI phishing email can be fluent, polite, personalized, and timed to something you really do. Check the route and the request instead: who sent it, where the link leads, why it needs an attachment or sign-in, what account or code it asks you to use, and whether you can verify the request outside the message.

AI can help a scammer research a target, write a convincing lure, register domains, run delivery infrastructure, and monitor which messages work. That does not mean every polished email was written by AI. It means a perfect sentence is weak evidence of safety.

What AI changes in a phishing email

Anthropic's September 2026 report covers operations it identified and disrupted between December 2025 and August 2026. It says the cases are notable and novel examples, not typical misuse data. In one cyber operation, AI-assisted workflows researched targets, registered domains, configured phishing infrastructure, sent messages, and monitored successful compromises. The report also describes device-code phishing that abused legitimate cloud-email sign-in flows.

Microsoft's April 2026 research describes a separate device-code campaign using role-specific lures such as invoices, requests for proposals, and manufacturing workflows. Microsoft says generative AI helped create targeted emails, while automation generated a live device code when the victim interacted with the link. These findings show why a message can look carefully written and still lead to an unsafe sign-in.

Neither report proves that AI wrote a particular message you received. Use the reports to update your checks, not to label every unusual email an AI scam.

The checks that still work

The message looks convincing because it...Check this before you act
Uses perfect grammar and a calm toneDoes the request make sense for this sender and this moment?
Uses your name, job, company, or a real invoice detailDid you expect the request, and can you confirm it through a known channel?
Comes from a familiar brandDoes the sender address and destination domain match exactly?
Includes a real Microsoft, Google, Adobe, or DocuSign pageWho initiated the sign-in or permission request, and what will you authorize?
Includes a calendar invite or document attachmentWere you expecting the file or event? Open the service directly instead of the attachment link.
Creates a deadline or asks for secrecyWhat changes if you wait ten minutes and verify it?
Asks for a code, QR scan, or device sign-inIs an unfamiliar device asking you to authenticate someone else's session?
Requests a payment, gift card, crypto transfer, or bank changeConfirm the payee and amount using a trusted contact, not the message.

The message can contain true facts and still be a scam. Treat personal details as context to verify, not as proof that the sender is genuine.

A legitimate sign-in page can still be part of the scam

Some phishing flows use a real identity provider. Microsoft explains that a device-code attack can begin with a lure that sends you to a page which eventually displays the official Microsoft device-login address. The victim enters a code, but the code authorizes the attacker's session. The victim may never type a password into the fake page, yet the attacker can receive valid access tokens.

Stop if an unexpected email asks you to:

Open the provider's app or website yourself. For a work account, ask your administrator whether the device, application, or request is expected. Do not assume that a microsoft.com, google.com, or other familiar domain makes the complete route safe.

A five-minute check before clicking

  1. Pause the deadline. A real request should survive a short verification delay.
  2. Read the complete sender address. Display names are easy to copy.
  3. Preview the destination without opening it. Look for a look-alike domain, shortened route, unexpected country code, or a redirect through an unrelated service. Use the link-checking guide for a slower inspection.
  4. Open the service directly. Type the known address or use the official app. Search for the invoice, message, event, or account notice there.
  5. Verify the request out of band. Call a known number or start a new conversation with the organization. Do not use the reply address or phone number in the suspicious message.
  6. Read every permission. If an app wants email, files, contacts, or calendar access for a narrow task, stop and ask why.
  7. Do not download an app from the message. CONDUSEF's September 2026 warning says links in SMS, email, WhatsApp, social networks, and other messages can lead to unsafe sites or apps. Use the official App Store or Google Play and verify the developer instead. Read the CONDUSEF warning.

For general phishing, the FTC also advises people not to click unexpected links or download attachments and to contact the organization through a known real channel. FTC phishing guidance.

What to do if you already interacted with it

Close the page. Do not download anything it offered. Open the real service directly and check for unfamiliar sign-ins, devices, connected apps, forwarding rules, or new recovery details. Keep the original message for reporting.

You entered a password or verification code

Change the password from the real provider site, sign out other sessions, review recovery methods, and change any reused password. If it is a work account, call your security or IT team immediately. Do not keep testing the suspicious page to see whether it works.

You entered a device code or approved a sign-in

Treat it as an account-compromise event even if you never typed a password into a fake page. Revoke sessions or tokens through the provider's security controls, change the password, review mailbox rules and recent activity, and tell your administrator or provider what happened.

You approved an app

Revoke the unfamiliar app or consent grant first, then change the password and inspect recent account activity. Use the OAuth recovery guide for provider-specific steps.

You paid or sent personal information

Contact the bank or payment service immediately using a number you looked up independently. Preserve the message, receipts, recipient details, and screenshots. Report the incident through the relevant national fraud or cybercrime channel. Recovery is not guaranteed, so act quickly without promising yourself a refund.

Where Rampart can help, and where it cannot

Rampart can flag suspicious sender, domain, link, attachment, and urgency patterns in SMS and connected Gmail or Outlook email. That can give you another warning before a polished lure turns into a click or reply. See what Rampart checks.

Rampart does not reliably determine whether AI wrote a message. It does not inspect every browser redirect, service worker, device-code session, or OAuth grant, and it cannot revoke provider tokens for you. Use the provider's security controls and independent verification for those steps.

Frequently asked questions

Can I spot an AI phishing email from its grammar?

No. Grammar can be a clue, but fluent writing is no longer a safety test. Check the sender, route, request, timing, and independent verification path.

Does a real Microsoft or Google page mean the email is safe?

No. A scam can use a legitimate sign-in flow to authorize an attacker's session or a malicious application's access. Read the device, app, and permission context carefully.

Is every personalized email AI-generated?

No. People have long used public profiles, old invoices, data leaks, and compromised accounts to personalize scams. AI can make that work faster and at greater scale, but the message alone may not reveal how it was made.

Should I reply and ask whether the email is real?

No. Start a new conversation with the organization or use a website and phone number you already trust.

What should I do with an unexpected attachment?

Do not open it. Verify the sender and request independently, then use the service's official app or website to find the document if it is real.

Sources

This guide will continue to be reviewed as AI-assisted phishing techniques, provider controls, and official guidance change.