By the end of this guide, you'll have five checks you can run on any suspicious email in under a minute, and a clear plan for what to do if you've already clicked.
Who it's for
Everyone who reads email for work or at home, and especially anyone who handles payments, invoices or passwords. It takes about ten minutes to read and practise. Share it with your team: one person clicking is all it takes.
Phishing emails pretend to come from someone you trust (your bank, a supplier, Microsoft, your boss) to get you to click a link, open an attachment, type a password or send money. They have become much more convincing, so spelling mistakes are no longer a reliable sign.
Steps
-
Notice the pressure
Phishing works by rushing you. Be suspicious of any email that pushes urgency ("within 24 hours"), fear ("your account will be closed"), money ("invoice overdue", "refund waiting") or secrecy ("keep this between us"). When you feel rushed, slow down: that feeling is the attack.
-
Check the real sender address
The name shown can say anything. Look at the actual address behind it: on a computer, hover over or click the name; on a phone, tap it. Watch for lookalikes such as
rnin place ofm, extra words (microsoft-support-team.com), or a different ending (.coinstead of.com). A personal Gmail or Outlook address claiming to be a company is a warning sign. -
See where a link really goes
Before clicking, hover over the link (on a phone, press and hold) to see the real address. Read the part between
https://and the next/, from right to left: the last two parts are the real site.paypal.com.account-check.co/loginbelongs toaccount-check.co, not PayPal. Treat QR codes in emails the same way: they're links you can't inspect first. -
Be wary of unexpected attachments
Don't open attachments you weren't expecting, even from people you know, since their account may have been taken over. Be especially careful with compressed files (
.zip), web pages sent as attachments (.html), and any document that asks you to "enable content" or "enable editing" to see it. -
Verify another way
If an email might be real, check it without using anything in the email. Call the person or company on a number you already have, or type the website's address yourself or use your bookmark. Never confirm a change of bank details or an urgent payment by replying to the email that asked for it.
-
Report it, then delete it
Use your email's Report phishing option (Outlook and Gmail both have one), and tell whoever looks after your IT, so they can warn others and block the sender. Then delete it.
Check it worked
Open your spam or junk folder and pick five messages. Run the five checks on each: the pressure, the real sender, where the links go, the attachments, and how you'd verify it. You should be able to say why each one is fake in under a minute. Then find the Report phishing option in your email, so you know where it is before you need it. For more practice, try Google's free phishing quiz.
If you've already clicked
- If you typed a password: change it straight away, from a device you trust, and everywhere else you used the same password. Check that two-step sign-in is on for that account.
- If you opened an attachment or installed something: disconnect the computer from the network (unplug the cable or turn off Wi-Fi) and call your IT support before doing anything else.
- If you sent money or bank details: call your bank's fraud line immediately. The sooner they know, the better the chance of stopping the payment.
- In every case: tell someone. Reporting quickly matters far more than any embarrassment, and it protects your colleagues from the same email.
Common mistakes
- Trusting the name and logo. Both are trivial to fake. Only the real address and the real link destination count.
- Trusting an email because it's from someone you know. Accounts get taken over, and the attacker then emails everyone in the contact list.
- Thinking the padlock means safe. The padlock only means the connection is encrypted. Phishing sites have padlocks too.
- Replying to ask "is this real?" You'll be answering the attacker. Verify another way.
- Keeping quiet after a click. Most of the damage happens in the hours after. Report it straight away.
Want your team trained?
ISMC runs practical, plain-language security training for small teams, built around the emails and situations your people actually see.
Request a consultation