The document describes 16 features that are commonly present in phishing emails. These features include non-matching URLs between text and links, use of IP addresses in URLs, differences between sender domains and embedded link domains, high numbers of links, domains or pictures used as links, presence of HTML, JavaScript or forms, small message sizes, use of non-standard ports or hexadecimal/special characters in URLs, and being classified as spam. Each feature is analyzed programmatically and assigned a binary value to determine the likelihood that an email is phishing attempt.