Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

How to Spot and Stop Phishing Emails

A practical, staff-facing guide to catching phishing emails before they cause harm — the tell-tale signs, the safe way to check, and exactly what to do when one gets through.

How do you spot and stop a phishing email?

You spot a phishing email by pausing on anything that pushes you to act fast, log in, pay, or open an attachment you weren’t expecting — and you stop it by checking through a separate channel before you do any of those things. Reporting it, rather than deleting it quietly, is what protects everyone else in the office.

That’s the short version. The longer version matters because phishing has moved well beyond the badly spelled “Nigerian prince” emails people still picture. Today’s attempts are polished, well-timed, and often copied straight from a real supplier or bank. Some are aimed at your whole company; some are written specifically for one person after a bit of research. Knowing the patterns is what turns a lucky escape into a reliable habit.

The signs worth training your eye on

No single clue proves an email is fake. It’s the combination that gives it away. The ones worth learning:

  • Urgency and pressure. “Your account will be closed in 24 hours.” “Pay this now or we lose the contract.” Real organisations rarely manufacture panic. Attackers do, because a rushed brain skips the checks.
  • An unexpected request to log in or pay. A link to “verify your password”, a changed set of bank details, an invoice you don’t recognise. Genuine password resets happen because you asked for one.
  • A mismatch between the name and the address. The display name says your bank; the actual address is a jumble, or a near-miss like micros0ft-support.com. Hover over the sender and any link before clicking to see where it really goes.
  • Slightly-off tone or branding. A greeting that’s too generic (“Dear Customer”), odd phrasing, a logo that’s a touch blurry. Modern fakes can look near-perfect, so treat this as a hint, not proof.
  • Attachments you weren’t expecting. Especially files that ask you to “enable content” or “enable macros”. That prompt is a common way to run malicious code.
  • A reply-to that differs from the sender. You reply to what looks like your director, and the response quietly lands in someone else’s inbox.

The hardest ones to catch are the targeted attacks — a message that names your actual manager, references a real project, and asks for something plausible. That’s why the habit matters more than any single sign: if a request involves money, credentials, or a change to payment details, you verify it another way, full stop.

The one check that beats almost everything

If you take a single thing from this: verify through a separate channel.

Got an email from your bank? Don’t click its link — open your banking app or type the web address yourself. Supplier changing their account number? Phone them on the number you already had, not the one in the email. Boss asking for an urgent payment? Walk over, or ring their known mobile. Attackers rely on you staying inside the channel they control. Step outside it and the whole trick usually falls apart in seconds.

This is also why the technical groundwork underneath your email matters. Properly configured email setup — with modern spam filtering and sender-authentication in place — quietly bins a large share of these before anyone sees them. It won’t catch everything, which is exactly why the human check stays essential.

What to do when one gets through

Even good teams get caught occasionally. What separates a scare from a serious incident is the response.

  1. Don’t interact further. No more clicks, no replies, no opening attachments. If you already entered a password, change it now on the real site, and anywhere else you reused it.
  2. Report it, don’t just delete it. Tell whoever handles your IT, and give colleagues a heads-up if it’s spreading. One person’s near-miss is everyone’s early warning. Deleting it quietly leaves the next person exposed.
  3. Disconnect if you downloaded something. If you opened an attachment or ran a file, take the device off the network (unplug the cable or turn off Wi-Fi) and get it checked before reconnecting.
  4. Watch for knock-on effects. A compromised mailbox is often used to attack your contacts next. Flag anything odd sent from your accounts, too.

A no-blame culture is the quiet hero here. People report faster when they won’t be told off for an honest mistake — and speed is what limits the damage. If your team has good cyber security habits and a clear place to raise a concern, most phishing stops at the first person who spots it.

A realistic bottom line

You won’t make phishing disappear, and you shouldn’t expect staff to be perfect filters. The aim is layered: sensible technical defences catching the bulk of it, a well-briefed team catching the clever ones, and a fast, blame-free way to report the few that slip through. That combination turns email from your biggest risk into a manageable one.

If you’d like a hand getting there — tightening up filtering and authentication, or running plain-English training so your team knows exactly what to look for — that’s the kind of thing our managed IT support covers day to day. We’re happy to take a look at your setup and tell you honestly where the gaps are.

Frequently asked questions

I clicked a link in a phishing email but didn't type anything. Am I safe?

Usually the real danger is entering details or downloading a file, so a single click with no further action is often low-risk — but don't assume. Some links quietly load tracking or trigger a download. Tell your IT support straight away, change the password for any account the email pretended to be from, and let them check the device. It's far better to report a false alarm than to stay quiet about a real one.

The email came from a colleague's real address. How is that possible?

Two common reasons. Their mailbox may have been compromised, so the email genuinely is from their account but sent by an attacker. Or the display name is faked while the underlying address is subtly wrong. If a message from a known contact asks for money, gift cards, a bank-detail change or urgent secrecy, verify it by phone or in person before acting — never by replying to the email.

Should we run phishing tests on our own staff?

Simulated phishing can help, but only as part of a supportive culture, not a gotcha exercise. The goal is confident reporting, not blame. Tests work best when paired with short, plain training and a clear, no-fault way to report anything suspicious — so people flag the real thing quickly instead of hiding a mistake.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.