Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Spot a Phishing Email (and What to Do About It)

In short

Phishing emails trick you into clicking a link, opening a file, or handing over a password by pretending to be someone you trust. Most share the same tells: urgency, a slightly wrong sender address, and a link that does not go where it claims. This article shows you the warning signs, the common patterns to expect, what to do when one lands, and how to get your team spotting them too.

Why phishing works so well

Phishing is a con trick delivered by email. The criminal pretends to be someone you trust — a supplier, your bank, Microsoft, a colleague, HMRC — and tries to get you to do one of three things: click a bad link, open an infected attachment, or hand over a password or payment.

It works because it targets people, not computers. A convincing email that arrives at a busy moment can catch out even careful staff. That is why learning the tells matters more than any single piece of software. The good news is that most phishing emails share the same handful of giveaways, and once you know them, they are hard to unsee.

The classic tells

No single sign proves an email is fake, but the more of these you spot, the more suspicious you should be.

  • A sense of urgency or fear. “Your account will be closed in 24 hours.” “Unusual login detected — verify now.” Pressure is designed to stop you thinking.
  • A sender address that is slightly wrong. The display name might say “Microsoft”, but the actual address is a jumble of letters or a lookalike domain such as micros0ft-support.com. Always check the real address, not just the name.
  • A link that does not match its label. Hover over a link on a computer (or press and hold on a phone) to reveal where it really goes. If the link text says one thing and the destination says another, stop.
  • Requests for passwords, codes, or payment details. Legitimate organisations do not ask you to confirm your password by email.
  • Unexpected attachments. Especially invoices, delivery notes, or “secure documents” you were not expecting.
  • Generic greetings and small errors. “Dear Customer”, odd phrasing, or slightly-off logos. Note that modern phishing is often well written, so clean grammar does not make an email safe.

Real-world patterns to expect

Criminals reuse the same storylines because they work. Watch for these:

  • The fake login page. An email about a “shared document” or “held email” links to a page that looks exactly like the Microsoft 365 or Google sign-in screen. You type your password straight into the criminal’s hands.
  • The invoice or payment switch. A supplier’s email (or a convincing fake of it) says their bank details have changed. Pay the “new” account and the money is gone. This is one of the most costly scams for UK small businesses — we cover it in detail in our guide to stopping invoice fraud with SPF, DKIM and DMARC.
  • The boss request. A message that appears to come from a director asks a staff member to buy gift cards, move money, or send payroll details urgently and discreetly.
  • The delivery or tax lure. A missed parcel, a refund from HMRC, or a fine — anything that makes you click before thinking.
  • The attachment trap. An attachment that, once opened, tries to install malware or ransomware. If that concerns you, read our advice on protecting against ransomware.

What to do when one lands

Having a simple, agreed routine removes the guesswork under pressure.

If you are suspicious but have not clicked:

  1. Do not click any links or open attachments.
  2. Do not reply — replying confirms your address is active.
  3. Verify through a channel you already trust. Phone the supplier on their known number, or check your account by typing the website address in yourself. Never use the contact details in the email.
  4. Report it, then delete it. Forward it to your IT provider and, in the UK, to the NCSC at report@phishing.gov.uk.

If you have already clicked or entered a password:

  1. Change that password immediately on the real website, and turn on multi-factor authentication.
  2. Tell your IT provider straight away so they can check for unusual activity and warn others.
  3. If you entered card or bank details, contact your bank.

The safest habit is simple: never act on an unexpected email that creates urgency until you have confirmed it through a channel you already trust.

Getting your staff spotting them too

Your team is your best defence, not your weakest link — provided they know what to look for and feel safe speaking up. A few practical steps go a long way:

  • Make reporting easy and blame-free. The worst outcome is a member of staff who clicked something and stays silent out of fear. Make clear that reporting fast is always the right call.
  • Share real examples. A short monthly note showing an actual phishing email that reached your inbox is more memorable than any policy document.
  • Agree a rule for payments. Any change to bank details, or any unusual payment request, must be confirmed by phone using a known number — no exceptions.
  • Turn on the technical basics. MFA, spam filtering, and email authentication (SPF, DKIM and DMARC) catch a lot before it ever reaches a person.
  • Consider simulated tests. Occasional, gentle phishing simulations show where training is needed, without catching anyone out unfairly.

The bottom line

Phishing relies on speed and trust. Slow down, check the sender and the real link destination, and confirm anything unexpected through a channel you already know. Back that human awareness with MFA and proper email filtering, and make it easy for staff to report mistakes without fear.

Want help hardening your email and training your team? Explore our cyber-security services or get in touch for a straightforward chat about your risks.

Frequently asked questions

What is the single biggest giveaway of a phishing email?

A mismatch between what the email claims and where it actually wants to send you. Hover over any link (or press and hold on a phone) and check the real address before clicking. If an email from "your bank" points to an address that is not your bank's proper website, it is phishing — regardless of how convincing the wording and logos look.

I think I clicked a phishing link. What should I do?

Do not panic, but act quickly. If you entered a password, change it immediately on the real website and turn on multi-factor authentication. If it was a work account, tell your IT provider straight away so they can check for unusual activity. If you entered card details, contact your bank. Speed limits the damage, and reporting is never something to be embarrassed about.

How is phishing different from a scam call or text?

They are all forms of the same trick — impersonation to steal information or money. Phishing is the email version, "smishing" is by text, and "vishing" is by phone. The warning signs are similar: unexpected contact, pressure to act fast, and a request for passwords, payments, or personal details. Treat all unexpected requests with the same healthy suspicion.

Should we report phishing emails, and to whom?

Yes. In the UK you can forward suspicious emails to the National Cyber Security Centre at report@phishing.gov.uk, and report scam texts by forwarding them to 7726. Internally, tell your IT provider so they can warn others and block the sender. Reporting helps protect other people, not just you.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.