Phishing vs Spam: Telling Them Apart and Responding to Each
By MercPrivacy · Published 2026-08-24 · Updated 2026-09-07
Spam is bulk email trying to sell you something; phishing is a message built to take a credential, a payment or access. The tells, the header checks, where to report each, and the employee protocol that assumes someone will click.
Spam is unsolicited bulk email trying to sell you something; phishing is a message built to make you hand over a credential, a payment or access to a system. The difference is intent, and the response follows it. Spam gets filtered, reported and, when the sender is legitimate, unsubscribed from. Phishing gets isolated, reported to the impersonated brand and to the FTC or the FBI's Internet Crime Complaint Center, and handled under an employee protocol that assumes someone will eventually click. A business that treats both as inbox clutter is one message away from a wire loss.
This article gives working definitions, the tells that separate phishing from ordinary marketing, a two-minute header check anyone in the office can run, the reporting channel for each type, an employee protocol that holds up on a busy afternoon, and the pattern to watch for when a flood of spam is cover for a fraud already in progress.
“Spam wastes ten seconds. Phishing waits for the one afternoon your bookkeeper is rushing. You filter for the first and you drill for the second.”
Definitions That Matter in Practice
Spam is commercial email you did not ask for, sent in bulk by a sender who wants a sale. It is regulated by the CAN-SPAM Act, which requires the sender to identify itself, use a truthful subject line, include a postal address and honor an opt-out, enforced by agencies rather than recipients. The sender is usually a real business or a list operator, and the harm is time and attention.
Phishing is deception. The message impersonates a bank, a vendor, a software provider or a colleague to obtain login credentials, a payment, personal data or a malware install. Spear phishing targets a named person with details pulled from public sources; business email compromise impersonates an executive or a supplier to redirect a payment; smishing and vishing are the same play by text and phone. The harm is a stolen account, a wired invoice or an encrypted network, and the sender is a criminal, not a marketer.
The categories overlap at the edges, since scam campaigns often arrive in bulk with an unsubscribe link. The test is what the message wants from you: a purchase decision, or an action that would hurt you if the sender is lying.
| Question | Spam | Phishing |
|---|---|---|
| What does the sender want? | A sale or a click on an offer | A credential, a payment, data or a malware install |
| Who is the sender? | An identifiable business or list operator | Someone impersonating a brand, a vendor or a colleague |
| What law applies? | CAN-SPAM's sender requirements | Fraud, identity-theft and computer-crime statutes |
| What is the right response? | Filter, report, opt out if legitimate | Isolate, verify out of band, report, preserve |
The Tells of a Phishing Message
Urgency with a consequence is the signature: an account that will be closed today, an invoice that is overdue, a package that cannot be delivered, a payroll change that must be confirmed before noon. Legitimate organizations rarely combine a deadline with a link in the same message.
The sending address rarely matches the display name. A vendor's name over a free webmail account, a domain with an extra word or a swapped letter, or a subdomain designed to read like the brand is impersonation. Hover over every link before clicking; the text can say one thing and the destination another. A link that leads to a login page is the most important tell of all, because a credential page hosted on an unrelated domain is the mechanism of the theft.
Watch attachments that are executable in disguise, including HTML files, disk images and documents that ask you to enable content, and QR codes, which move the link off the screen where your tools can inspect it. Any request to change bank details is the whole point of the most expensive category, described in fake invoice and renewal scams.
A Two-Minute Header Check
Every email carries headers that record where it actually came from, hidden behind the message view. Opening them takes a few clicks, and how to find email headers shows where they are in each major mail client.
Three lines answer most questions. The Return-Path shows the address that receives bounces, often the real sender. The Received lines trace the servers the message passed through, bottom to top, and the earliest names the originating system. The Authentication-Results line reports whether the message passed SPF, DKIM and DMARC checks for the domain it claims, which SPF, DKIM and DMARC in plain English explains without the jargon.
Read the results carefully. A failure on a claimed brand domain is decisive: the message did not come from that brand. A pass is not proof of legitimacy, because a criminal who registers a lookalike domain and sets up authentication for it will pass every check. The headers tell you whether the sender is who it claims; the tells above tell you whether that sender is honest.
Where to Report Each Type
Spam goes to your email provider through its report control, which improves filtering for everyone on the service, and to the FTC's spam reporting address. If the sender is a real business with a postal address and a working opt-out, unsubscribing is appropriate and the statute obliges the sender to honor it.
Phishing goes to more places. Report it to the impersonated brand through the abuse or phishing address most large companies publish, because the brand can act against the lookalike domain; to the FTC through its fraud reporting site; to the FBI's Internet Crime Complaint Center if the message targeted your business or caused any loss; and through your mail provider's report-phishing control so the credential page gets flagged. Forward a phishing text to 7726, the short code carriers use to collect them.
If money has already moved, call your bank's fraud line before anything else and ask for a recall; the first hours decide whether funds can be retrieved. Then file the IC3 report and preserve the original message with its headers.
The Employee Protocol That Holds Up on a Busy Day
Training slides do not stop phishing. A short, practiced routine does, because it gives an employee under time pressure something to do other than comply.
Pause on the four triggers. Any message asking for a payment or bank-detail change, a login, a gift card or an urgent exception to normal process gets no action until it is verified.
Verify out of band. Call the vendor or the executive on a number already on file, never one in the message. A payment-detail change is confirmed by phone with a known contact every time, no exceptions.
Report through the button, not by forwarding. Use the mail client's report-phishing control or forward the message as an attachment to the security mailbox; forwarding inline strips the headers and spreads the link.
If someone clicked or typed a password, say so immediately. Disconnect the device, change the password from a different device, reset multi-factor authentication, revoke active sessions, and tell whoever manages the systems. Speed matters more than blame.
Preserve the original. Keep the message with full headers, the link destination, and a note of what was clicked and when, as evidence for the bank, the insurer and any investigator.
Behind the routine sit the standing controls: multi-factor authentication on email and banking, DMARC enforcement on your own domain so criminals cannot send as you, a written no-change-without-a-call rule for payment details, and a quarterly walk-through with the people who handle money.
When Spam Is Really a Scam Campaign
A sudden flood of spam is sometimes the fraud itself. Criminals who have obtained a credential or placed an order in your name subscribe your address to thousands of newsletters so that the confirmation email, the password-reset notice or the bank's alert is buried in the noise. The pattern to recognize is volume from nowhere, at the same time as a transaction or account change you did not initiate. The mechanics of a suddenly flooded business inbox and what to check first are covered there.
Other scams dress as spam on purpose: a fake renewal notice for software you do use, a domain-expiry invoice from a company that is not your registrar, an “unsubscribe” link that exists only to confirm a live address. When the office has more of this than anyone can triage and you are not sure which messages are cover for something, the free 30-minute assessment is a practical way to have someone sort the pile with you.
Where MercPrivacy Fits
MercPrivacy is a data-privacy and unsolicited-contact defense firm in Houston, Texas. For a business inbox under pressure we classify the traffic into compliant marketing, non-compliant senders and scam campaigns, build the header-level evidence file, identify the U.S. company behind the spam where one exists, file the reports that enforcers and impersonated brands act on, and trace how the addresses were exposed so removal and suppression requests can go to the brokers and lists feeding them, re-checked because listings return.
We are not a law firm or an incident-response provider, and we do not give legal advice. If a phishing attack has already caused a loss, the bank, your insurer and the FBI's reporting channel come first; when a matter warrants a demand or a lawsuit, a licensed attorney is engaged. Our own investigative, documentation and administrative work is billed as a straightforward recurring service fee set out in writing before any work starts. More on the spam email page.
Frequently Asked Questions
What is the difference between phishing and spam?
Spam is unsolicited bulk email from a sender who wants a sale; it is regulated by CAN-SPAM and its harm is clutter. Phishing is deception aimed at obtaining a credential, a payment, personal data or a malware install by impersonating a brand, a vendor or a colleague; it is a crime and its harm is theft. The test is what the message wants you to do if the sender is lying.
How can I tell if an email is phishing?
Look for urgency paired with a link or attachment, a sending address that does not match the display name, a lookalike domain, a link whose destination differs from its text, a login page reached from the email, a request to change bank details, and disguised executable attachments. Then check the headers: an authentication failure on the claimed brand's domain settles it.
Where do I report a phishing email?
To the impersonated brand through its published abuse address, to the FTC through its fraud reporting site, to the FBI's Internet Crime Complaint Center if your business was targeted or lost anything, and to your mail provider through its report-phishing control. Forward a phishing text to 7726; report spam separately through your provider and the FTC.
What should an employee do after clicking a phishing link?
Say so immediately. Disconnect the device, change the affected password from a different device, reset multi-factor authentication, revoke active sessions, and notify whoever manages the systems. If a payment was made or bank details were changed, call the bank's fraud line first and request a recall. Preserve the original message with its headers.
Is phishing illegal?
Yes. Phishing is prosecuted under federal and state fraud, identity-theft and computer-crime statutes, and falsified headers also violate CAN-SPAM. The practical problem is that the sender is usually anonymous or overseas, which is why reporting to the impersonated brand, the FTC and the FBI matters more than any claim against the sender.
Filter the spam, drill for the phish, and know which is which. MercPrivacy sorts a business inbox into compliant marketing, non-compliant senders and scam campaigns, builds the header-level evidence file, files the reports that brands and enforcers act on, and works the brokers and lists that exposed the addresses. The free assessment maps the exposure and says what is worth pursuing. Stephanie answers instantly and free, or book your free 30-minute privacy assessment with a specialist at (830) 587-5011.
Start Your Free Privacy Assessment Ask StephanieThis article is for educational purposes only and is not legal advice. MercPrivacy is not a law firm; when a matter requires legal representation, a licensed attorney is engaged. Statutory figures are the amounts the statutes provide, not predictions of any outcome, and laws change — verify the current text before relying on it.