Knowledge base

Spot a phishing email before you click

The five checks that catch almost every fake email.

Phishing emails succeed by rushing you. Slow down for ten seconds and run these five checks – together they catch nearly every fake that lands in a real inbox.

The five checks

  1. The real sender address. The display name says “Microsoft” but tap or hover on it and the address is security-alert@mail-notify-347.com. The display name is free text; the address is the truth.
  2. Urgency and threat. “Your account will be closed in 24 hours.” “Payment failed – act now.” Real companies don’t threaten you on a timer; scammers do because panic switches off scepticism.
  3. Where links actually go. Hover over any link (press and hold on a phone) and read the real destination. If the text says microsoft.com but the link goes somewhere else, that’s your answer.
  4. Unexpected attachments. Invoices you weren’t expecting, “voicemail” files, ZIPs and HTML attachments. If you weren’t expecting it, don’t open it – check with the sender by another route.
  5. Any request involving credentials or payment changes. Emails asking you to “re-enter your password”, approve an MFA prompt you didn’t trigger, or change a supplier’s bank details deserve a phone-a-colleague moment, not a click.

What to do with a suspicious email

  • Don’t click, don’t reply, don’t unsubscribe (that confirms your address is live)
  • Report it: use Outlook’s Report phishing button, or forward it to the helpdesk and we’ll check the headers for you
  • Warn colleagues if it’s dressed up as an internal email – phishing rarely arrives alone

Already clicked? Don’t sit on it – follow Phishing – what to do if you clicked right now. The first 15 minutes matter most.

Was this helpful?
Still stuck? Log a ticket Browse more guides

Still stuck?

Raise a ticket and we’ll pick it up. Clear updates until it’s resolved.