How to Spot a Phishing Email: 9 Red Flags and What to Do Next

By J. Mesa

Each new year brings new technology and the same old threat. Phishing sounds like a tired topic. It keeps coming up because it still works, and criminals reach for it first.

This guide shows you how to recognize a phishing message, the forms it takes, and what to do when one lands in your inbox.

What is phishing?

Phishing is a scam where a criminal sends a message that appears to come from a source you trust, such as a bank, a delivery service, a coworker, or a vendor. The goal is to get you to click a link, open a file, share a password, or send money.

Why does phishing still work?

  • It targets people. Software can be patched. A busy person in a hurry can be rushed.
  • It is cheap. A criminal can send thousands of messages for almost nothing.
  • It looks better every year. Attackers copy real logos and layouts, and writing tools remove the spelling mistakes that used to give them away.
  • One click is enough. A single response out of thousands pays for the campaign.

What are the types of phishing?

  • Email phishing. Mass messages that imitate well-known companies.
  • Spear phishing. A message written for one person, using details about their job or life.
  • Business email compromise. A message that poses as an owner, executive, or vendor and asks staff to send money or change bank details.
  • Smishing. Phishing by text message.
  • Vishing. Phishing by phone call, often with a fake caller ID.
  • QR code phishing. A code that leads to a fake login page.

What are the red flags of a phishing email?

  1. You didn’t expect it. Be wary of any unsolicited message that asks for information or payment.
  2. It creates urgency. “Your account closes in 24 hours” is meant to stop you from thinking.
  3. It asks for personal information. Legitimate companies don’t ask for passwords or card numbers by email.
  4. The sender address is off. Look at the full address, not the display name. Watch for swapped letters and odd domains.
  5. The link doesn’t match. Hover over it to see where it goes.
  6. It has an unexpected attachment. Invoices, shipping notices, and “scanned documents” you didn’t ask for are common lures.
  7. The greeting is generic. “Dear customer” from a company that knows your name is a warning.
  8. The request is unusual. Gift cards, wire transfers, and secrecy are scam hallmarks.
  9. Something feels wrong. Odd tone, odd timing, or an odd request from someone you know deserves a second look.

Spelling and grammar errors are still a sign. Their absence proves nothing.

How do I verify a sender?

Before you respond, confirm who sent the message. Contact the company or person through a phone number or address you already know to be real. Don’t use the contact details in the message, and don’t reply to it.

For any request that involves money or a change to payment details, make a phone call. This one habit stops most business email compromise.

What should I do if I receive a phishing email?

  1. Don’t click, reply, or open attachments.
  2. Report it with your email program’s “Report phishing” button.
  3. At work, tell your IT contact so they can warn others.
  4. Delete it.

What should I do if I clicked a phishing link?

Act right away. Speed matters more than embarrassment.

  1. Disconnect the device from the network if you opened a file or installed something.
  2. Change the password for the affected account from a different device, and for any account that shares it.
  3. Turn on multi-factor authentication.
  4. Tell your IT contact or manager at work.
  5. Call your bank if you entered payment details or sent money.
  6. Run a security scan on the device.
  7. Report it to the FBI at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

How do I protect my business from phishing?

  • Train your team. Use real examples. Repeat through the year.
  • Run simulated phishing tests and use the results to teach, never to punish.
  • Turn on multi-factor authentication for email. It limits the damage when a password is stolen.
  • Use email filtering and turn on the security features your email provider offers.
  • Set a payment verification rule. Any change to bank details gets a phone call to a known number.
  • Make reporting easy. One button, no blame.

How does my online information help phishers?

Attackers research their targets. Your social media tells them your employer, your job title, your coworkers, and where you spent the weekend. They use those details to write messages that sound real.

  • Keep your home address and phone number off public profiles
  • Limit what you share about your role and your workplace
  • Use strong, unique passwords for every account

You would be surprised how much a criminal can learn from a public profile.

Does multi-factor authentication stop phishing?

It stops most of it. If you give away a password, the attacker still needs the second step. Some attacks trick people into approving a login prompt or typing a code into a fake page, so never approve a prompt you did not start. Security keys and passkeys resist phishing best, because they only work on the real website.

Can phishing happen by phone or text?

Yes. A text about a missed delivery or a call from “your bank’s fraud team” follows the same pattern as a phishing email. Hang up, and call the number on your card or the company’s official website.

How do I teach my family?

Share three rules: don’t click links in unexpected messages, never give a code or password to anyone who contacts you, and confirm any request for money with a phone call.

What does a real example look like?

Picture an email from “Microsoft 365 Support” that says your mailbox is full and will stop receiving mail today. A button reads “Increase storage.” The sender’s address ends in an unfamiliar domain, and the button leads to a login page that looks right and sits at the wrong web address. That one message shows urgency, a mismatched sender, and a mismatched link.

Your next step

Stay informed about the latest phishing methods, and teach yourself and your team how to spot them. Cerberus Cybersecurity offers training and awareness programs that use real examples and hands-on practice. Contact us to see how we can help your organization. Stay alert, stay safe, and keep your digital life secure.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *