Phishing emails are the on-ramp for most attacks on small businesses — from ransomware to drained bank accounts. The good news is that even AI-written phishing leaves clues, and a 10-second habit of checking a few things will catch the large majority of them.
Quick answer: To spot a phishing email, check five things: the real sender address (not just the display name), any urgent or threatening tone, links (hover to see where they actually go), unexpected attachments, and requests for passwords, payments, or bank-detail changes. If two or more feel off, treat it as phishing and verify through a separate channel.
What is a phishing email?
A phishing email is a fake message designed to trick you into doing something harmful — clicking a malicious link, entering your password on a fake login page, opening malware, or sending money. It usually impersonates a brand or person you trust: your bank, Microsoft 365, a supplier, or your own boss.
It matters because phishing is where so many attacks begin. As covered in our cyber threats hub, the human element is a factor in around 60% of breaches, and phishing is the most common way attackers get that first foothold.
The 7 warning signs of a phishing email
1. The sender address doesn’t match the display name
The display name might say “Microsoft,” but the actual address is something like security@micros0ft-support.co. Always expand and read the real email address.
2. It creates urgency or fear
“Your account will be suspended in 24 hours.” Phishing relies on panic to stop you thinking. Legitimate organisations rarely threaten immediate consequences over email.
3. The links don’t go where they claim
Hover over a link (on desktop) or long-press it (on mobile) to preview the real destination before clicking. A mismatch between the visible text and the actual URL is a major red flag.
4. There’s an unexpected attachment
Invoices, “voicemails,” shipping notices, or zip files you weren’t expecting are classic malware carriers. When in doubt, don’t open — verify with the sender first.
5. It asks for credentials, payment, or a bank-detail change
No legitimate provider asks you to confirm your password by email. Any request to change where a payment goes should be treated as suspicious until verified by phone. This overlaps with business email compromise.
6. The greeting or details are slightly off
Generic greetings (“Dear Customer”), the wrong logo, or details that don’t quite fit your relationship with the sender.
7. It’s too good (or too scary) to be true
Unexpected refunds, prizes, or bonuses — and threats of fines or legal action — are both designed to make you act before you check.
Note for 2026: AI now writes phishing with perfect grammar and personalised details, so “bad spelling” is no longer reliable. The signs above — especially checking the real sender and hovering links — still work. More in AI phishing and deepfake scams.
What does a phishing email look like? Real-world examples
| Lure | What it claims | The tell |
|---|---|---|
| Microsoft 365 login | “Your password expires today — verify now” | Link goes to a look-alike domain, not microsoft.com |
| Fake invoice | “Payment overdue, see attached” | Unexpected attachment from an unknown sender |
| CEO request | “Are you at your desk? I need a quick favour” | Display name matches your boss; reply-to address doesn’t |
| Delivery notice | “We couldn’t deliver your parcel — reschedule” | Urgency + link to a non-carrier domain |
| Bank-detail change | “Please update our new account for this invoice” | Request to redirect a payment — verify by phone |
What should you do if you receive a phishing email?
- Don’t click, reply, or open attachments.
- Report it — use your email provider’s “Report phishing” button and tell whoever manages IT.
- Delete it after reporting.
- If it impersonates a real company, you can forward it to that company’s abuse address.
What should you do if you already clicked?
Act quickly — speed limits the damage:
- Disconnect the device from the network if you downloaded anything.
- Change the password for any account you entered credentials into, from a different, trusted device — and turn on MFA if it isn’t already.
- Tell your IT/security contact immediately; don’t hide it.
- Watch for follow-on activity like unexpected logins or payment requests, and follow your incident response plan.
How do you protect your whole team from phishing?
Individual vigilance isn’t enough on its own. Combine it with:
- MFA everywhere, so a stolen password isn’t enough to get in.
- Email security that filters known phishing before it lands — see best email security for small business.
- Regular security awareness training with simulated phishing to build the habit.
Frequently asked questions
How can you tell if an email is phishing?
Check the real sender address, hover over links to see their true destination, and be suspicious of urgency, unexpected attachments, and requests for passwords or payments. Two or more red flags means treat it as phishing.
What happens if you open a phishing email?
Simply opening an email is usually safe. The danger comes from clicking links, opening attachments, or entering information. If you only opened it and did nothing else, delete and report it.
What should I do if I clicked a phishing link?
Disconnect the device, change the affected password from a trusted device, enable MFA, and tell your IT contact right away. Then watch for unusual account activity.
Can AI-generated phishing be detected?
Yes. AI removes the grammar mistakes but not the structural signs — look-alike sender domains, mismatched links, and requests to pay or change bank details still give it away.
Part of our cyber threats hub. Sources: Verizon 2025 Data Breach Investigations Report (DBIR). Last updated June 2026.
Reviewed by Nhon Dang, CEO Sunteco Cloud. See our editorial guidelines.
