Skip to content

Security

Phishing: how to spot a fake email before you click

Security· 02 July 2026· 4 min read
Phishing: how to spot a fake email before you click

A phishing email no longer looks like it did ten years ago, full of typos and absurd offers. Today it convincingly imitates invoices, delivery notifications, or a message "from the boss." The good news: there is almost always a tell, if you know where to look. Here is what to check before clicking any link or opening any attachment. A message that looks like it came from "Fast Courier," with an "attached tracking slip," can reach dozens of employees in a single morning, and one click is enough to compromise a computer.

The real sender address and lookalike domains

Your email client usually shows a friendly name, like "Invoicing Dept" or "Courier Delivery." That name says nothing about who actually sent the message. Always check the full address behind it — often it is a foreign domain, a random string of letters, or a free address (gmail, outlook) used instead of the company's official domain.

A common trick is swapping a single letter in the domain: "micros0ft.com" instead of "microsoft.com," or adding a word: "accounting-firm.com" becomes "accounting-firm-secure.com." At a quick glance, the difference goes unnoticed.

Simple rule: if the display name sounds official but the address or domain does not match that company exactly, check it letter by letter before trusting the message.

Artificial urgency and pressure to act fast

Almost every phishing email contains a pressure element: "your account will be locked in 24 hours," "your invoice is overdue, penalties apply," "reply urgently, I'm in a meeting." The goal is to rush you so you skip checking the details.

A serious vendor, a bank, or a tax authority never demands immediate action solely by email, under threat. If you feel pressured, that is one more reason to check, not to act.

Attachments and masked links

  • Unexpected attachments — invoices, "offers," or "resumes" in .zip, .exe, or even .pdf format from unknown senders should not be opened directly.
  • Masked links — the displayed text may say "Open invoice," but the actual address behind it (visible by hovering, without clicking) leads somewhere else.
  • Shortened URLs — bit.ly and similar services hide the real destination; treat them with suspicion in unexpected emails.
  • Double extensions — a file named "invoice.pdf.exe" looks like a PDF at first glance, but it actually runs a program instead of opening a document.

Invoice phishing and CEO fraud

Two variants are common in businesses: an email imitating a real invoice from a known supplier, but with a different bank account for payment, and a message that appears to come from the company's director, urgently requesting a transfer or a change to a supplier's payment account. Both rely on the fact that the accounting employee will not call to verify, especially if the "boss" seems in a hurry.

A company with 30 employees can lose, in a single day, the equivalent of an entire month's invoice from a supplier, simply because the payment went out without a verification call.

Protection rule: any change of bank account or unusual payment request gets confirmed by phone, on a number you already know, not the one in the email signature.

What to do if you already clicked

If you opened an attachment or entered a password on a fake site, disconnect the computer from the network immediately, change the affected account's password from another device, and notify your IT provider. If you sent money to the wrong account, contact your bank right away — there is often a short window in which the transfer can be stopped or recovered.

Do not delay reporting it out of embarrassment — the faster you act, the smaller the damage.

Write down exactly what happened and when — the time you clicked, what information you entered. That detail helps your IT team or your bank limit the damage faster.

How to train your employees

Training does not mean a single session once a year. Short, repeated sessions work better, plus periodic phishing simulations, so you can see realistically who needs more attention. It pairs well with clear password and two-factor authentication rules — a related topic we cover separately on our blog — and with automatic protection at the computer and email level.

How to start

A security audit shows you how exposed your business is to phishing and other attacks. You can add endpoint protection on every computer in the company, or contact us to talk through the risks specific to your business.

Need help with your IT?

Schedule a free IT audit and let’s talk.

Get in touch

FAQ

Frequently asked questions

Look at the sender's full address, not just the display name, and hover over links without clicking to see where they actually lead.
Disconnect the computer from the network immediately and notify your IT provider, so they can check for and limit any damage.
Many well-written ones slip through filters. Antivirus and endpoint protection help, but employee awareness remains the main line of defense.