7 Ways to Spot a Phishing Email
You can have the most robust and secure network and still get hacked. How? Someone clicks on a phishing email. Humans are the last line of defense in cybersecurity, and training your employees to recognize phishing emails can make a significant difference. Teaching them what to look for and how to respond can protect your organization from potential threats.
Did you know? According to the 2024 Email Security Risk Report by Egress:
- 94% of employers suffered from email security incidents.
- 58% suffered from account takeover attacks.
- 79% of those attacks started with a phishing email and 83% had multi-factor authentication (MFA) that was bypassed.
Here are 7 tips you can share with your employees to help them spot phishing attempts and keep your network secure:
1. Sender’s Email Address: Pay close attention to the email address from which the message is sent. Phishers often use addresses that mimic legitimate domains but contain subtle variations or additional characters. Be cautious of emails from unknown or suspicious sources.
Phishing Clue: This email address doesn’t have Microsoft in it and is threatening account deletion (urgency).
2. Urgent or Threatening Language: Phishing emails often use fear tactics to prompt immediate action. Watch out for messages that claim your account has been compromised or that there is an urgent matter requiring your attention. Legitimate organizations typically provide clear, professional, and non-threatening communication.
3. Suspicious Links: Hover your cursor over hyperlinks without clicking to reveal the actual destination. Phishers often disguise malicious URLs by displaying them differently than their true locations. Check for misspelled domain names, additional subdomains, or strange characters that suggest a potential scam.
4. Requests for Personal Information: Be wary of emails that ask for sensitive data, such as passwords, credit card numbers, or social security information. Legitimate organizations seldom request such details via email. When in doubt, contact the organization directly using verified contact information to verify the request’s authenticity.
5. Poor Grammar and Spelling: Many phishing attempts originate from non-native English speakers or automated systems, resulting in noticeable errors in grammar, spelling, or punctuation. While occasional mistakes can happen, consistent or glaring errors should raise suspicion.
6. Unexpected Attachments: Exercise caution when opening email attachments, especially if they are unexpected or from unknown senders. Attachments can contain malware or viruses that compromise your device’s security.
Phishing Clue: Unsolicited email, too many attachments, urgent time limit, “company was bought by another agency in 2021”, phone number is off by one number, old domain that no longer exists.
7. Sense of Urgency: Phishing emails often create a sense of urgency to manipulate recipients into acting without thinking. Beware of messages that claim you will face negative consequences or lose access to an account if you don’t respond or provide information immediately.
Encourage your employees to report phishing attempts and consider using phishing simulators for training. By fostering a culture of cyber vigilance, we can collectively combat phishing attempts and enhance online security.
Wondering if your data is secure? Get a complimentary copy of the 14 Step Guide to Securing your Company’s Data here. If your domain needs a checkup, you can also get a free vulnerability scan of your company’s domain here.
For any questions related to cybersecurity or cyber insurance, feel free to connect with me on LinkedIn or send an email to [email protected].
Don’t forget to subscribe to our newsletter for more updates and tips. Thank you for reading, and stay safe out there!


