What Are Spam and Phishing Emails? Types Explained

Spam is unsolicited email sent in bulk, mostly advertising nobody asked for. A phishing email is a fraud: it imitates a trusted […]

Madhurendra SachanBy Madhurendra Sachan
June 9, 2018
7 min read
Updated October 5, 2026
What Are Spam and Phishing Emails? Types Explained

Spam is unsolicited email sent in bulk, mostly advertising nobody asked for. A phishing email is a fraud: it imitates a trusted sender, such as a bank, a delivery company or your own CEO, to steal logins, money or data, or to get malware onto your computer. All phishing emails are unwanted, but not all spam is phishing.

The two get mixed up because phishing hides inside spam volume. Kaspersky found that spam made up 44.99% of all email sent worldwide in 2025, according to its spam and phishing report for 2025. Most of it is noise. The dangerous part is the small share designed to look like mail you’d expect.

Spam vs phishing emails

SpamPhishing email
PurposeSell something, or get clicks and replies at scaleSteal credentials, money or data, or install malware
SenderOften an honest but unwanted marketer, sometimes a scammerAlways pretends to be someone trusted
TargetingHuge lists, little personalizationAnything from mass mailings to one carefully researched person
Risk if you open itMostly wasted timeAccount takeover, payment fraud, malware
What to doMark as spam or unsubscribe from senders you recognizeDon’t click. Report it and delete it

The money involved is real. The FBI’s Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025, with reported losses of about $3.05 billion, in its 2025 Internet Crime Report. Phishing and spoofing were again the most reported crime type that year, with 191,561 complaints.

Types of spam emails

Email spam, also called junk email, is the practice of sending unsolicited messages in bulk. Some of it is simply unwanted marketing. Some of it is the first step towards something worse, such as financial fraud or reputational damage. The common types:

  • Commercial spam: unrequested ads for products, loans, SEO services or software.
  • Scam spam: advance fee offers, lottery wins, inheritance claims and “investment opportunities”.
  • Malware spam (malspam): fake invoices, shipping notices or voicemail alerts with an infected attachment or link.
  • Extortion spam: threats claiming the sender has hacked your device or has compromising material, with a demand for payment in cryptocurrency.
  • Hoaxes and chain letters: false warnings and “forward this to everyone” messages that spread misinformation.

If spam appears to come from your own address, that’s usually spoofing rather than a hacked account. We explain how to check in why am I receiving spam email from my own address.

Types of phishing emails

Email phishing

Email phishing is the most common way these attacks are carried out. The aim is to craft the message so that it appears to come from someone, or somewhere, known to the user, rather than its actual source. Attackers forge the sender name or tamper with the domain so the mail seems to originate from a known organization. The link usually leads to a fake login page.

Spear phishing

Spear phishing uses the same kind of legitimate looking message, but it’s written for one person or a small group. The attacker uses personal details gathered from social media, company websites or earlier breaches, and the email appears to come from a trusted source. It may link to a bogus website asking for financial or personal information, or carry an attachment containing malware.

Whaling

Whaling is a phishing attack variation aimed at a company’s senior officials. The email or fake web page takes a more serious, executive tone, and it’s often called CEO fraud. The content usually concerns an urgent executive matter that affects the whole company, a legal issue or a customer complaint, written for someone with high level access.

Business email compromise

In business email compromise, the attacker poses as an executive, a colleague or a supplier and asks for a payment, a change of bank details or sensitive files. There’s often no link or attachment at all, which is why spam filters miss it. Sometimes the attacker writes from a lookalike domain, and sometimes from a real mailbox they’ve already taken over.

Clone phishing

The attacker copies a real email you received earlier, such as a shared document notice or an invoice, swaps the link or attachment for a malicious one, and resends it as a “corrected” version.

Attachment and QR code phishing

Instead of a link in the body, the payload sits in an HTML attachment, a PDF or a QR code. A QR code moves the click to a phone, away from the protections on a work laptop.

Examples of spam and phishing emails

Typical examples look like this:

  • “Your parcel couldn’t be delivered. Pay a small redelivery fee here.”
  • “Unusual sign-in detected. Verify your account within 24 hours or it will be suspended.”
  • “Please find the updated invoice attached. Note our new bank details.”
  • “You have 3 pending messages. Log in to your mailbox to read them.”
  • “Congratulations, you’ve been selected for a gift card. Claim it today.”

What they share is urgency, a request to click or pay, and a sender that’s almost, but not quite, the real one. The FTC’s guide to phishing lists the same warning signs and explains how to report these messages.

What to do with a suspicious email

  • Check the actual sender domain, not just the display name.
  • Hover over links to see where they really go. Don’t open unexpected attachments.
  • If a message asks for a payment change or a login, verify it through a phone number or website you already know.
  • Report it using your mail client’s report button or your security team’s process, then delete it.

For a longer checklist, see how to identify a phishing email.

Organizations need more than inbox hygiene, because the fake login pages and lookalike domains behind these emails sit outside their network. TIKAJ’s anti-phishing services find and remove them. TIKAJ and its platform Hunto handle more than 100,000 takedowns a year for over 150 enterprise customers. Contact us with any questions about anti-phishing services.

FAQ

What is a phishing email?

A phishing email is a fraudulent message that pretends to come from a trusted organization or person, such as a bank, a delivery firm or a colleague. Its goal is to get you to click a link to a fake login page, open a malicious attachment, share personal details or send money. The sender address is often forged or slightly misspelled.

What are the main types of spam email?

The main types are commercial spam (unwanted ads), scam spam (lottery, inheritance and advance fee offers), malware spam (fake invoices or delivery notices with infected attachments), extortion spam (threats demanding cryptocurrency) and hoaxes or chain letters. Phishing emails are a separate, more targeted category, though they are often delivered alongside ordinary spam.

What are fake emails called?

Fake emails that pretend to be from someone else are usually called phishing emails or spoofed emails. Spoofing describes the forged sender address. Phishing describes the scam itself. Targeted versions are called spear phishing, and those aimed at executives are called whaling or CEO fraud. Payment fraud by email is called business email compromise.

Is spam the same as phishing?

No. Spam is any unsolicited bulk email, and much of it is just unwanted marketing. Phishing is a specific kind of fraudulent email that impersonates a trusted sender to steal credentials, money or data. Phishing can arrive as spam, but it is more dangerous and often more targeted. Report phishing rather than simply deleting it.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch