Spot a phishing email before you click

Most break-ins still start with one convincing email. Five quick checks catch the large majority of them, and if you've already clicked, here is exactly what to do next.

By John E. Phillips ·

By the end of this guide, you'll have five checks you can run on any suspicious email in under a minute, and a clear plan for what to do if you've already clicked.

Who it's for

Everyone who reads email for work or at home, and especially anyone who handles payments, invoices or passwords. It takes about ten minutes to read and practise. Share it with your team: one person clicking is all it takes.

Phishing emails pretend to come from someone you trust (your bank, a supplier, Microsoft, your boss) to get you to click a link, open an attachment, type a password or send money. They have become much more convincing, so spelling mistakes are no longer a reliable sign.

Steps

  1. Notice the pressure

    Phishing works by rushing you. Be suspicious of any email that pushes urgency ("within 24 hours"), fear ("your account will be closed"), money ("invoice overdue", "refund waiting") or secrecy ("keep this between us"). When you feel rushed, slow down: that feeling is the attack.

  2. Check the real sender address

    The name shown can say anything. Look at the actual address behind it: on a computer, hover over or click the name; on a phone, tap it. Watch for lookalikes such as rn in place of m, extra words (microsoft-support-team.com), or a different ending (.co instead of .com). A personal Gmail or Outlook address claiming to be a company is a warning sign.

  3. See where a link really goes

    Before clicking, hover over the link (on a phone, press and hold) to see the real address. Read the part between https:// and the next /, from right to left: the last two parts are the real site. paypal.com.account-check.co/login belongs to account-check.co, not PayPal. Treat QR codes in emails the same way: they're links you can't inspect first.

  4. Be wary of unexpected attachments

    Don't open attachments you weren't expecting, even from people you know, since their account may have been taken over. Be especially careful with compressed files (.zip), web pages sent as attachments (.html), and any document that asks you to "enable content" or "enable editing" to see it.

  5. Verify another way

    If an email might be real, check it without using anything in the email. Call the person or company on a number you already have, or type the website's address yourself or use your bookmark. Never confirm a change of bank details or an urgent payment by replying to the email that asked for it.

  6. Report it, then delete it

    Use your email's Report phishing option (Outlook and Gmail both have one), and tell whoever looks after your IT, so they can warn others and block the sender. Then delete it.

Check it worked

Open your spam or junk folder and pick five messages. Run the five checks on each: the pressure, the real sender, where the links go, the attachments, and how you'd verify it. You should be able to say why each one is fake in under a minute. Then find the Report phishing option in your email, so you know where it is before you need it. For more practice, try Google's free phishing quiz.

If you've already clicked

Common mistakes

Want your team trained?

ISMC runs practical, plain-language security training for small teams, built around the emails and situations your people actually see.

Request a consultation
← All guides