How to Spot Phishing Emails Before They Spread

Featured Image | A professional reviewing a suspicious email on a laptop, with key warning signs highlighted

Published: 21 August 2026 Author: Cyber Resilience, Risk and Business Protection Faculty

A phishing email rarely announces itself as an attack. It arrives during a crowded morning, adopts the language of a supplier or colleague, and asks for something apparently routine: a document review, password reset, payment confirmation or sign-in. Knowing how to spot phishing emails is therefore not a matter of memorising a few obvious scams. It is a professional judgement skill, supported by clear process, calm attention and a culture where people can pause before acting.

For organisations, the risk is wider than a compromised inbox. One convincing message can lead to unauthorised payments, stolen credentials, disrupted operations, loss of confidential information and regulatory exposure. Technical controls matter, but they do not remove the need for informed human decisions at the point of contact.

Key Takeaways

  • Phishing works by creating urgency, authority, curiosity or fear before the recipient has time to assess the request.
  • A familiar name, company logo or convincing writing style is not proof that an email is legitimate.
  • Check the sender, the destination of links, the nature of the request and the surrounding context before responding.
  • Reporting a suspicious email promptly is a protective action, even when it turns out to be harmless.
  • Organisations reduce risk when cyber awareness is built into day-to-day decision-making rather than treated as an annual compliance exercise.

Table of Contents

  1. Why capable professionals still fall for phishing
  2. How to spot phishing emails using a four-point check
  3. The warning signs that require a pause
  4. What to do when an email seems suspicious
  5. Building a reporting culture that works
  6. Frequently asked questions

Why capable professionals still fall for phishing

Phishing does not depend on carelessness. It depends on timing and pressure. Attackers often exploit normal organisational rhythms: payroll periods, supplier invoices, annual leave, system migrations, recruitment activity or a request that appears to come from a senior leader.

A message may be technically imperfect, but still persuasive because it reaches a recipient who is busy, expects a delivery, works across several systems or does not want to delay a colleague. The question is not whether someone is intelligent enough to avoid an attack. The question is whether the organisation has made careful verification practical under real working conditions.

This distinction matters for leaders and HR teams. A blame-based approach encourages silence. A framework-led approach encourages staff to identify uncertainty, use an agreed verification route and escalate without embarrassment.

How to Spot Phishing Emails Using a Four-Point Check

Before clicking, replying, opening an attachment or approving a payment, apply a disciplined check. It should take less than a minute, but it creates a useful break between stimulus and action.

1. Check the sender, not just the display name

A display name can be copied easily. Look at the full email address and consider whether its domain is correct. A fraudulent address may substitute a character, add an extra word, use an unrelated domain or imitate a trusted organisation closely enough to escape a quick glance.

Context matters here. An email from a genuine colleague can still be unsafe if their account has been compromised. If the request is unusual, verify it through a known telephone number, established messaging channel or internal directory. Do not use contact details supplied in the suspicious message.

2. Check the request against normal process

The most significant warning sign is often not a spelling error. It is a request that bypasses ordinary governance. A finance colleague is asked to make an urgent payment to revised bank details. An executive asks for confidential information outside established channels. A software provider asks an employee to re-enter credentials through an unexpected form.

Ask whether the request is proportionate, expected and consistent with agreed procedure. Genuine urgency can exist, but it should not cancel controls. Payment approvals, password resets and disclosure of personal information require verification precisely because they are high-value actions.

3. Check links and attachments before opening them

Hover over a link without clicking it to inspect the destination address. On a mobile device, press and hold where appropriate. The visible text may state one destination while the underlying address directs the user elsewhere.

Treat unexpected attachments with similar caution, especially files that prompt users to enable content, macros or editing. A legitimate-looking invoice, CV or shared document can be used to deliver malware or capture credentials. If the document is expected, confirm it with the sender using a separate channel before opening it.

4. Check the emotional pressure in the message

Phishing frequently relies on emotional compression. The message may threaten account closure, imply a disciplinary issue, offer an unexpected reward or create artificial urgency around a senior request. The intention is to reduce reflection.

A useful professional habit is to name the pressure rather than react to it: “This message is asking me to act quickly and bypass my usual check.” That short pause improves decision quality. It also aligns cyber resilience with the wider performance disciplines of focus, clarity and considered judgement.

The Warning Signs That Require a Pause

No single sign proves an email is malicious. A genuine sender may make a typo, use an unfamiliar address after a merger or send an unexpected attachment. Assessment relies on the pattern.

Pause and verify when an email contains several of the following features:

  • an unfamiliar, misspelt or misleading sender address;
  • an unexpected request for passwords, payment details, personal data or access codes;
  • pressure to act immediately, keep the matter confidential or avoid normal approval routes;
  • links that lead to a domain unrelated to the stated organisation;
  • attachments that were not anticipated or that ask users to enable macros or content;
  • language, tone or timing that does not fit the sender’s usual behaviour.

Modern phishing can be highly polished. Generative AI has lowered the barrier to producing credible wording, and attackers can use publicly available information to tailor messages to teams, roles and live business activity. Poor grammar is still a possible clue, but it is no longer a reliable test.

Infographic | The Phishing Pause: Sender -> Request -> Link or Attachment -> Pressure -> Verify or Report

What to Do When an Email Seems Suspicious

Do not reply, click, forward externally or open an attachment merely to investigate. Use your organisation’s reporting function or cyber security process. If there is a designated phishing-report button, use it. Otherwise, notify the IT or security team in accordance with local procedure.

If you have already clicked a link or entered information, report it immediately. Speed is more valuable than trying to resolve the problem alone. Security teams may be able to reset credentials, block a malicious domain, review access activity and warn other recipients before further action is taken.

Where a payment or change to bank details is involved, follow the finance verification process without exception. A call to a previously verified contact number is usually more reliable than an email exchange. The minor inconvenience of confirmation is a reasonable trade-off against the potential loss.

Building a Reporting Culture That Works

Cyber security awareness becomes effective when it is operational, not performative. Employees need to know what a suspicious email looks like, how to report it and what will happen after they do. They also need confidence that reporting a false alarm is acceptable.

Leaders can reinforce this through short, regular learning interventions linked to actual work. A 90-minute briefing can give teams a shared language for phishing, social engineering, reporting routes and decision points without treating security as a purely technical issue. The value is consistency: the same principles are understood by finance, HR, leadership and operational teams.

Training should also reflect role-specific risk. Finance teams require disciplined payment verification. HR teams need safeguards around candidate and employee data. Executives and their support staff may be targeted through impersonation, while customer-facing teams may encounter fraudulent requests designed to extract account information. One generic message will not address every exposure.

The strongest control is a workforce that regards verification as professional judgement rather than friction. When people have permission to pause, ask and report, attackers lose much of the pressure they depend upon.

Frequently Asked Questions

What is the most common sign of a phishing email?

An unexpected request to act urgently is one of the most common signs, particularly when it involves credentials, payment, confidential information or a link. Assess it alongside the sender address and normal business process.

Can a phishing email come from a real colleague?

Yes. If a colleague’s account has been compromised, attackers can send messages from a legitimate address. Verify unusual requests independently, especially where money, data or access is involved.

Is a phishing email always badly written?

No. Many phishing emails are professionally written and carefully formatted. Treat unusual context, urgency and attempts to bypass controls as more meaningful indicators than grammar alone.

What should I do if I clicked a phishing link?

Report it immediately through your organisation’s security process. If you entered a password, change it using the approved method and follow any instructions from IT or cyber security staff.

Should I forward suspicious emails to colleagues?

Not unless your internal process specifically asks you to do so. Forwarding can spread a harmful link or attachment. Use the approved reporting route instead.

How often should teams receive phishing awareness training?

It depends on their exposure, role and organisational risk profile. Short, regular and role-relevant sessions generally support better retention than a single annual exercise.

The practical test is simple: when an email creates pressure, do not let the sender define the pace. Pause, verify through a trusted route and report early. That is not hesitation. It is disciplined professional control.

author avatar
Peter Kerry Director
Peter Kerry is a CMC Registered Civil and Commercial Mediator, ADR Group accredited Civil, Commercial and Workplace Mediator, founder of Echelon Advisory Group Ltd and Director of Echelon Academy UK. His work spans mediation, professional communication, corporate learning and live delivery, combining real-world dispute-resolution experience with decades of public speaking and a technical background in acoustics, media and visual production.

Leave a Reply

Your email address will not be published. Required fields are marked *