Back to Blog & Resources
Cybersecurity · By Priya Sharma

How to Spot a Phishing Email: A 60-Second Guide for Your Team

Modern phishing emails look frighteningly real. Teach your team these six quick checks and you will stop the vast majority of attacks before they start.

Analysts monitoring security dashboards in an operations centre

Phishing remains the most common way criminals get into businesses — and the emails are better than ever. But almost every phishing email fails at least one of these six checks. Share them with your team.

1. Check the sender’s actual address

Display names are free — anyone can set theirs to “Microsoft” or “Sarah (Accounts)”. The real address is in the details. sarah@yoursupplier-security-alert.com is not Sarah.

2. Beware urgency and fear

“Your account will be suspended in 24 hours” exists to stop you thinking. Legitimate organisations almost never demand immediate action under threat.

3. Hover before you click

Hovering over a link reveals the true destination before you click. If the URL doesn’t match the organisation it claims to be from — don’t click. On a phone, long-press instead.

4. Be suspicious of unexpected attachments

Invoices you weren’t expecting, “delivery documents” for parcels nobody ordered, and password-protected ZIP files are classic carriers of malware. When in doubt, verify with the sender by phone.

5. Watch for subtle oddities

Slightly off branding, unusual greetings (“Dear Customer” from your own bank), odd times of day, and near-miss spelling (“Micr0soft”) all add up. One oddity might be innocent; three is a pattern.

6. Verify payment changes by voice

Business email compromise — fake “urgent bank detail changes” from suppliers or CEOs — costs UK businesses millions every year. Rule for your finance team: any change of payment details is verified by a phone call to a known number. No exceptions, no matter how senior the request appears.

Make reporting easy

The single biggest improvement most businesses can make: a one-click “Report phishing” button and a culture where reporting a false alarm earns thanks, not eye-rolls. Speed of reporting is what turns a near-miss into nothing at all.

Combine trained humans with proper email security filtering and you’ll stop the overwhelming majority of attacks. Want us to run a safe simulated phishing test for your team? Get in touch.

Need help putting this into practice?

Our engineers are happy to talk through your setup — no obligation, no jargon.

Get a Free Consultation

Ready to Make IT Easier?

Tell us about your business and we'll show you how the right technology can save you time, reduce risk, and support your growth. Your free consultation comes with no obligation — just honest, practical advice.