How to Spot a Phishing Email: A Practical Guide
Phishing — fake emails designed to trick you into handing over passwords or money — is the most common way businesses get breached. The good news: most phishing follows the same few patterns, and once your team knows the signs, the vast majority are easy to catch before any harm is done.
What phishing is trying to do
A phishing email impersonates someone you trust — a bank, a supplier, a colleague, a well-known brand like Microsoft or a courier — to get you to click a link, open an attachment, or reply with sensitive details. The aim is almost always to steal login credentials, plant malware, or redirect a payment into the criminal's account.
The tell-tale signs
- Urgency or threats. "Your account will be closed in 24 hours." Pressure to act fast, before you think, is the classic red flag.
- A mismatched sender. The display name looks right, but the actual email address is odd or off-domain (e.g. support@paypal-secure.net).
- Generic greetings. "Dear customer" instead of your name.
- Unexpected links or attachments — especially invoices, "delivery" notices, or shared documents you weren't expecting.
- Spelling and odd phrasing. Still common, though AI-written scams are getting cleaner, so don't rely on this one alone.
- Too good to be true. Refunds, prizes and unexpected windfalls.
Beware the more targeted attacks
Not all phishing is mass-mailed and sloppy. Spear phishing is tailored to you using details found online, and "CEO fraud" impersonates a director or supplier — often from a genuine, hacked mailbox — to push through an urgent payment or a change of bank details. These are the ones that cost businesses real money, and they can look completely legitimate. That's why a verify-by-phone rule for any payment change is so important (see our email security tips).
How to check a link safely
Before clicking, hover over a link on a computer (or press and hold on a phone) to preview where it really goes. If the address doesn't match the company it claims to be from, don't click. When in doubt, ignore the link entirely and go to the website yourself by typing the address you know, or using your own bookmark.
If you're not sure
- Verify through a known channel. Phone the supplier or colleague on a number you already hold — never one from the email itself.
- Never enter passwords from an email link. Log in the normal way, and use MFA so a stolen password isn't enough.
- Report it, don't just delete it. Tell your IT support so others can be warned. In the UK you can also forward suspicious emails to report@phishing.gov.uk.
What to do if you've clicked
Don't panic, and don't hide it — speed limits the damage. If you entered a password, change it immediately (and anywhere you reused it) and turn on MFA. If you opened an attachment, disconnect from the network and have the device checked. If money or bank details were involved, contact your bank straight away. Reporting it quickly is always the right move.
Protecting your whole business
Awareness is the first line of defence, but it works best alongside the right tools: multi-factor authentication, spam and link filtering, tested backups and regular staff training. That layered approach is exactly what our cyber security service provides, backed by our business IT support and managed IT services.
Official guidance: Forward suspicious emails to the NCSC’s free reporting service at report@phishing.gov.uk, and see the NCSC’s phishing guidance for the official advice.