Phishing emails succeed by rushing you. Slow down for ten seconds and run these five checks – together they catch nearly every fake that lands in a real inbox.
The five checks
- The real sender address. The display name says “Microsoft” but tap or hover on it and the address is security-alert@mail-notify-347.com. The display name is free text; the address is the truth.
- Urgency and threat. “Your account will be closed in 24 hours.” “Payment failed – act now.” Real companies don’t threaten you on a timer; scammers do because panic switches off scepticism.
- Where links actually go. Hover over any link (press and hold on a phone) and read the real destination. If the text says microsoft.com but the link goes somewhere else, that’s your answer.
- Unexpected attachments. Invoices you weren’t expecting, “voicemail” files, ZIPs and HTML attachments. If you weren’t expecting it, don’t open it – check with the sender by another route.
- Any request involving credentials or payment changes. Emails asking you to “re-enter your password”, approve an MFA prompt you didn’t trigger, or change a supplier’s bank details deserve a phone-a-colleague moment, not a click.
What to do with a suspicious email
- Don’t click, don’t reply, don’t unsubscribe (that confirms your address is live)
- Report it: use Outlook’s Report phishing button, or forward it to the helpdesk and we’ll check the headers for you
- Warn colleagues if it’s dressed up as an internal email – phishing rarely arrives alone
Already clicked? Don’t sit on it – follow Phishing – what to do if you clicked right now. The first 15 minutes matter most.