Modern phishing emails don’t look like the obviously fake messages of a few years ago. They’re well-written, use real company logos, and often reference something genuinely relevant to the recipient. Here’s what to actually check.
Check where it really came from, not just the display name
The name shown in an inbox can say anything the sender wants, “Microsoft Support” is easy to fake. What matters is the actual email address behind it. If it doesn’t match the domain you’d expect, that’s your first red flag.
Be suspicious of urgency
“Your account will be suspended in 24 hours” or “Invoice overdue, pay immediately” are designed to make you act before you think. Legitimate organisations rarely demand instant action by email alone.
Hover before you click
Before clicking any link, hover over it (on desktop) to see where it actually leads. A link that says “Office 365” but points somewhere unrelated is a clear warning sign.
Be extra cautious with unexpected attachments
An invoice, delivery notice, or document you weren’t expecting, especially one requiring you to “enable content” or “enable macros” to view it, is one of the most common ways malware gets onto a business network.
When in doubt, verify through a second channel
If an email claims to be from a colleague or supplier asking for a payment change or sensitive information, confirm it by phone or a separate message thread, not by replying to the email itself.
Report it, don’t just delete it
A phishing email caught and reported helps flag the pattern for the rest of the business. Deleting it quietly means the same email might land in someone else’s inbox with no warning.
Email filtering catches the majority of these before they ever arrive, but no filter catches everything, which is why a team that knows what to look for is still one of the strongest defences a business has.
Ready for IT that just works?
Get in touch and we'll tell you honestly whether we're a good fit.
Get in Touch