Phishing remains one of the most common ways attackers get inside company networks. The logic is simple: they don't need to break through a firewall, they only need one person to click. A well-crafted email can convincingly imitate a supplier, a bank, or even your managing director, and the daily pressure of a full inbox does the rest.
The good news is that almost every phishing message leaves traces. Below are seven signals you can check in a matter of seconds, plus the correct procedure when something feels off.
1. The real sender address doesn't match the display name
A display name is just text — it can say anything. Attackers write "Finance Department" or "Microsoft 365" and count on nobody expanding the details. Always check the full address, not the label.
Watch for domains that look almost right: swapped letters, added hyphens, different extensions, or subdomains that mimic a brand. An address ending in a free public domain while claiming to represent a large company is an immediate red flag.
2. Artificial urgency or veiled threats
"Your account will be suspended within 24 hours." "This invoice is overdue and must be paid today." "Final warning before lockout."
Urgency is the core tool of social engineering because it removes thinking time. Serious organisations don't demand action within minutes by email, and public institutions don't threaten account closure through generic messages. When you feel pressure, slow down deliberately.
3. Links that lead somewhere other than they appear
Link text can display a legitimate address while the actual destination is entirely different. On desktop, hover over the link and read the URL shown at the bottom of the window. On mobile, press and hold to see the preview.
Suspicious signs include:
- The main domain isn't the one belonging to the supposed sender.
- Shortened links that hide the final destination.
- Long URLs with random characters or crowded subdomains.
- Login pages requesting your password after clicking through from an email.
A practical rule: never authenticate from a link received by email. Open the portal manually, from a bookmark or by typing the address.
4. Unexpected attachments or unusual file types
An invoice you weren't expecting, a "scanned document", a "delivery confirmation" — all classic pretexts. Be especially careful with executable files, password-protected archives, scripts, or Office documents that ask you to enable content or macros.
If a genuine partner sends an unusual attachment, a 30-second phone call to a known number settles the matter.
5. Requests for credentials or payments
No reputable supplier asks for your password, MFA code, or full card details by email. Just as importantly, a change of bank account communicated by email is one of the costliest fraud patterns affecting businesses today.
Any IBAN change, any urgent payment request, and any credential request must be verified through a separate channel using contact details you already have — never the phone number written in the suspicious email.
6. Language, formatting and details that don't add up
Machine translation has improved, but details still slip: stiff phrasing, incomplete signatures, low-resolution logos, generic greetings such as "Dear customer", or inconsistent branding.
Tone is another subtle clue. If a colleague who normally writes short, direct notes suddenly sends a formal, insistent request, verify in person.
7. The context makes no sense for your role
A password reset notification for a service you don't use? A payment approval request when you have no financial responsibilities? A message from a "director" asking for discretion and immediate action?
These attacks — known as CEO fraud or business email compromise — rely on hierarchy and the fear of delaying something important. A real director will never blame you for double-checking.
What to do when you suspect an email
- Don't click links and don't open attachments.
- Don't reply and don't use the contact details it contains.
- Report the message to your IT team or through the report button in your email client.
- If you already clicked or entered your password, notify IT immediately, change the password and revoke active sessions.
Speed of reporting matters far more than the mistake itself. An incident flagged within minutes is usually straightforward to contain.
Technical controls that reduce the risk
User awareness is essential, but it can't be the only line of defence. A minimum control set includes:
- Multi-factor authentication on all accounts, especially email and remote access.
- Advanced email filtering with link rewriting and attachment analysis.
- Correct SPF, DKIM and DMARC configuration for your own domain, making spoofing harder.
- Alerting on automatically created mailbox forwarding rules — a frequent sign of compromise.
- Regular phishing simulations followed by training, not punishment.
- Tested backups, for scenarios where phishing leads to ransomware.
For organisations in scope of NIS2, managing human-related risk and reporting incidents are no longer optional; they form part of your security obligations.
Phishing keeps evolving, and AI-assisted messages are increasingly convincing. That is precisely why the combination of clear procedures, properly configured filtering technology and trained people makes the difference. If you would like an assessment of how well your company email is protected, a phishing simulation, or a training session for your team, a specialised partner can help you move from reaction to prevention.