Phishing Emails: The Tells That Still Work
Phishing emails have become more convincing.
Poor spelling, obvious scams and badly copied logos still exist, but modern phishing messages can look almost identical to genuine emails from Microsoft, banks, delivery companies, suppliers and senior colleagues.
Attackers now use polished templates, realistic branding and personal information gathered from websites or social media. Some messages are even written or improved using artificial intelligence.
Yet phishing emails still leave clues.
The warning signs may be more subtle than they once were, but knowing what to check can help you identify a malicious email before you click a link, open an attachment or disclose sensitive information.
What Is a Phishing Email?
A phishing email is a fraudulent message designed to persuade you to take an action that benefits an attacker.
That action might include:
- Entering your password on a fake login page
- Opening a malicious attachment
- Approving a multi-factor authentication request
- Sending money to a fraudulent bank account
- Sharing confidential information
- Installing remote-access software
- Calling a fake support number
- Downloading malware
The email may pretend to come from a trusted organisation, colleague, customer or supplier.
Phishing relies heavily on social engineering. Rather than attacking technology directly, the criminal attempts to manipulate the recipient through urgency, fear, curiosity, authority or financial pressure.
Why Phishing Emails Are Harder to Spot
Traditional advice often tells people to look for spelling mistakes and poor grammar.
Those remain useful warning signs, but they are no longer enough.
Modern phishing emails may include:
- Accurate company logos
- Professional formatting
- Correct names and job titles
- References to real projects
- Familiar email signatures
- Convincing invoices
- Genuine-looking Microsoft 365 pages
- Information taken from LinkedIn or company websites
- Text generated by AI
Some attacks begin with a real email account that has already been compromised. In that situation, the sender’s address may be genuine, and the malicious message may appear within an existing conversation.
This means you need to assess the entire context of an email rather than relying on one obvious mistake.
1. The Email Creates Artificial Urgency
Urgency remains one of the strongest phishing indicators.
Attackers want you to act before you have time to think, verify the request or ask a colleague.
Typical phrases include:
- Your account will be suspended today
- Payment is required immediately
- Your password expires in one hour
- Final warning
- Immediate action required
- Your mailbox is full
- Confirm your identity now
- The invoice is overdue
- Complete this before the end of the day
Legitimate organisations may send urgent messages, but pressure combined with a request to click, pay or provide information should make you cautious.
Pause before acting. A delay of a few minutes is usually safer than responding immediately to a fraudulent request.
2. The Display Name Does Not Match the Real Address
Email applications often show a sender’s display name more prominently than the underlying email address.
An attacker can set the display name to almost anything, including:
- Microsoft Support
- HMRC
- Your bank
- A company director
- A known supplier
- A colleague’s name
Always inspect the full sender address.
For example:
Display name: Microsoft 365 Support
Actual address: account-security@unrelated-domain.example
The display name looks reassuring, but the domain reveals that the message did not come from Microsoft.
On a phone or tablet, you may need to tap the sender’s name to reveal the complete address.
3. The Domain Is Almost—but Not Quite—Correct
Attackers frequently register domains designed to resemble genuine ones.
They may use:
- Missing letters
- Additional words
- Replaced characters
- Unusual hyphens
- Different domain endings
- Lookalike characters
Examples might resemble:
- micros0ft.example
- company-secure.example
- supplier-payments.example
- businessname-support.example
The difference can be difficult to notice at a glance.
Pay particular attention to the part of the address immediately before the final domain ending. An email mentioning a trusted brand does not mean it belongs to that organisation.
4. The Link Destination Does Not Match the Text
A phishing email may contain a button labelled:
- View document
- Sign in
- Track parcel
- Review invoice
- Secure account
- Listen to voicemail
- Open shared file
The visible wording tells you what the attacker wants you to believe. The actual destination tells you where the link will take you.
On a computer, hover over the link without clicking it. Your email application or browser should display the destination.
On a mobile device, press and hold the link carefully to preview it, but avoid opening it.
Be suspicious when:
- The destination uses an unfamiliar domain
- The address is shortened or obscured
- The domain does not belong to the claimed organisation
- The link uses an IP address rather than a normal domain
- The URL contains long, confusing strings
- The message claims to be from Microsoft but links elsewhere
Do not assume a page is genuine simply because it contains the expected company name somewhere in the address.
5. The Email Asks You to Sign In Through a Link
Fake login pages remain one of the most common phishing techniques.
The email may claim that you need to:
- Review a shared Microsoft 365 document
- Prevent your password from expiring
- Increase your mailbox storage
- Listen to a voicemail
- Accept a secure message
- Confirm unusual activity
- Read a protected PDF
- Reauthenticate your account
Instead of using the link, open the relevant service independently.
For example, type the known website into your browser, use an existing bookmark or open the official application.
If there is genuinely an account issue, it should normally also appear within the legitimate service.
6. The Request Is Unusual for the Sender
Context is one of the best phishing defences.
Ask whether the request is normal for the person or organisation supposedly sending it.
Be cautious when a familiar contact suddenly asks you to:
- Buy gift cards
- Change bank details
- Make an urgent payment
- Keep a request confidential
- Send a password or security code
- Open an unexpected file
- Move the conversation to WhatsApp
- Approve a login request
- Download remote-access software
A message can come from a genuine but compromised account.
If the request is unusual, verify it through another method. Call the person using a trusted number or speak to them directly.
Do not use telephone numbers supplied in the suspicious email.
7. The Email Uses Authority or Secrecy
Business phishing often impersonates directors, managers or finance staff.
A message might say:
- I need this completed urgently
- I am in a meeting and cannot speak
- Do not discuss this with anyone
- This is a confidential acquisition
- Process the payment before I return
- Send me your mobile number
- Are you available to handle a sensitive task?
This is sometimes known as business email compromise or executive impersonation.
The attacker relies on employees being reluctant to challenge someone senior.
A legitimate security culture should allow staff to verify unusual requests regardless of who appears to have sent them.
8. The Payment Details Have Changed
Invoice fraud is one of the most financially damaging forms of phishing.
An attacker may impersonate a supplier and claim that:
- Its bank account has changed
- A payment should be redirected
- Previous details are no longer valid
- An overdue invoice must be paid urgently
- A new account is being used temporarily
Never change supplier payment information based solely on an email.
Confirm the request using a known telephone number already held in your records. Do not use contact details included in the message requesting the change.
Businesses should have a documented verification process for all changes to bank details.
9. The Attachment Was Not Expected
Malicious attachments may be disguised as:
- Invoices
- Purchase orders
- Delivery notices
- CVs
- Scanned documents
- Voicemail messages
- Shared files
- Remittance advice
- Legal documents
Common attachment types include:
- Microsoft Office files
- PDF documents
- ZIP archives
- HTML files
- Disk images
- Executable files
- Shortcut files
Even a familiar file type can be dangerous.
Ask yourself whether you expected the attachment and whether the sender normally communicates this way.
When uncertain, contact the sender separately before opening it.
10. The Email Asks You to Enable Content or Bypass Security
Treat any document that asks you to weaken security as suspicious.
Warning instructions may include:
- Enable editing
- Enable content
- Enable macros
- Disable protected view
- Allow this application
- Ignore your browser warning
- Turn off antivirus
- Install this certificate
- Run this file as administrator
Legitimate business documents should rarely require you to bypass several security controls simply to read them.
Do not follow instructions designed to disable the protections on your device.
11. The Greeting or Wording Feels Wrong
Generic greetings can still be a useful warning sign:
- Dear customer
- Dear user
- Dear mailbox owner
- Dear account holder
However, personalised greetings do not prove an email is genuine.
Attackers can obtain names from:
- Company websites
- Social media
- Data breaches
- Previous emails
- Compromised address books
Pay attention to wording that feels inconsistent with the supposed sender.
A colleague may suddenly use an unusual tone, unfamiliar sign-off or phrases they would not normally use.
Small contextual inconsistencies can be more revealing than spelling mistakes.
12. The Message Contains Unexpected QR Codes
QR-code phishing has become a popular way of bypassing traditional email-link scanning.
The email may ask you to scan a code to:
- Sign into Microsoft 365
- Review a secure document
- reset a password
- Verify your account
- Access a voicemail
- Complete multi-factor authentication
Scanning the code transfers the attack from your work computer to your phone, where the destination may be harder to inspect.
Treat a QR code as a link. Do not scan one from an unexpected email without verifying the request independently.
13. The Email Includes a Phone Number Instead of a Link
Not every phishing email contains a malicious link.
Some encourage you to call a fake support or billing number.
Examples include:
- Your antivirus subscription has renewed
- A large payment has been authorised
- Your account has been charged
- Contact support to cancel
- Suspicious activity was detected
- Call immediately to stop the transaction
The person answering may attempt to persuade you to install remote-access software, share banking details or provide security codes.
Use the organisation’s official website or documentation to find its genuine contact number.
14. The Message Triggers an Unexpected MFA Request
Multi-factor authentication offers valuable protection, but attackers try to exploit it.
You may receive an email asking you to:
- Approve a login
- Enter a one-time code
- Confirm an authentication request
- Re-register your authenticator app
- Scan a QR code to restore access
Never approve a request you did not initiate.
A genuine support agent should not ask you to read out an authentication code or approve an unexpected sign-in.
Repeated prompts may indicate an attacker already has your password and is trying to make you approve access.
15. The Reply-To Address Is Different
An email can appear to come from one address but direct replies somewhere else.
This is not always malicious. Businesses sometimes use separate systems for sending and receiving emails.
However, an unexpected Reply-To address is worth checking, particularly when the email involves payments, passwords or confidential information.
A mismatch may indicate that the attacker wants your response redirected to an account they control.
16. The Email Is Too Convenient or Too Alarming
Phishing often exploits strong emotional reactions.
The message may offer:
- An unexpected refund
- A prize or reward
- A valuable job opportunity
- A tax rebate
- A free subscription
- A large discount
Alternatively, it may claim:
- Your account has been hacked
- A payment has been made
- Your files will be deleted
- Legal action is imminent
- Your parcel cannot be delivered
- Your business account will be closed
Excitement and fear both reduce careful decision-making.
When an email causes an immediate emotional reaction, pause and verify it before taking action.
Why the Padlock Icon Is Not Proof of Safety
Many phishing websites use HTTPS.
The padlock icon means that the connection between your browser and the website is encrypted. It does not confirm that the website belongs to the organisation it claims to represent.
A criminal can obtain an encryption certificate for a fraudulent website.
Always check the domain as well as the connection status.
What to Do When You Receive a Suspicious Email
Do not click links, open attachments, scan QR codes or call numbers contained in the message.
Instead:
- Check the full sender address.
- Inspect links without opening them.
- Verify the request through a separate channel.
- Report the email using your organisation’s reporting process.
- Delete it after your IT or security team has reviewed it.
- Warn colleagues if the message targets multiple people.
Reporting is important even when you did not interact with the email. It may help protect other recipients.
What to Do If You Clicked a Phishing Link
Clicking a link does not always mean your account has been compromised, but you should act promptly.
Close the page and report the incident to your IT provider or security team.
Tell them:
- Which email you received
- What you clicked
- Whether you entered any information
- Whether anything downloaded
- Whether you approved an authentication request
- What device you were using
Do not hide the mistake. Quick reporting gives your support team the best chance of limiting the damage.
What to Do If You Entered Your Password
Change the password immediately using the genuine website or application.
You should also:
- Sign out of other active sessions
- Check recent sign-in activity
- Enable or review MFA
- Change the password anywhere else it was reused
- Inform your IT or security team
- Check for unexpected forwarding rules
- Review recovery email addresses and phone numbers
- Look for unfamiliar applications with account access
If the password was reused elsewhere, assume those accounts may also be at risk.
What to Do If You Approved an MFA Request
Contact your IT team immediately.
An approved authentication request may allow an attacker to access the account even if the password is changed shortly afterwards.
The response may need to include:
- Revoking active sessions
- Resetting authentication methods
- Changing the password
- Reviewing sign-in logs
- Removing malicious inbox rules
- Checking for downloaded data
- Investigating connected applications
Speed is important.
What to Do If You Opened an Attachment
Disconnecting the device from the network may be appropriate when malware is suspected, but follow your organisation’s incident-response procedure.
Do not delete evidence or attempt random cleaning steps before speaking to your IT provider.
The device may need:
- Endpoint security scanning
- Process and log review
- Account investigation
- Isolation from the business network
- Malware removal
- Recovery from a known-good backup
Provide as much detail as possible about what you opened and what happened afterwards.
How Businesses Can Reduce Phishing Risk
Staff awareness is essential, but employees should not be the only line of defence.
Businesses should also use:
- Multi-factor authentication
- Email filtering
- Domain-protection controls
- Endpoint detection and response
- Regular software updates
- Secure password management
- Conditional Access
- Restricted administrator privileges
- Verified payment-change procedures
- Reliable backups
- Clear incident-reporting processes
Phishing prevention works best when people, processes and technology support one another.
Why Phishing Simulations Can Help
Controlled phishing simulations can help employees practise identifying suspicious messages in a safe environment.
Effective training should be:
- Regular
- Relevant to real business risks
- Supportive rather than punitive
- Followed by practical guidance
- Adjusted based on common mistakes
The aim is not to catch people out. It is to build confidence and encourage early reporting.
Employees who report uncertainty are an asset to the organisation’s security.
Phishing Emails Are Not Always Obvious
There is no single test that proves an email is safe.
A message may have perfect spelling, correct branding and a genuine sender address while still being malicious.
The most reliable approach is to consider several factors together:
- Does the request make sense?
- Is it expected?
- Is the sender address correct?
- Does the destination match the claimed service?
- Is there unnecessary urgency?
- Is the sender asking you to bypass normal procedure?
- Can the request be verified independently?
When something feels wrong, stop and check.
How Hamilton Group Can Help
Phishing remains one of the most common routes into business systems, but effective protection involves more than telling staff not to click suspicious links.
Hamilton Group can help your organisation reduce phishing risk through:
- Advanced email filtering
- Microsoft 365 security
- Multi-factor authentication
- Entra ID Conditional Access
- Endpoint protection
- Security-awareness training
- Phishing simulations
- Account-compromise investigations
- Incident response
- Secure backup solutions
- Ongoing managed IT support
We can review your current email security, identify weaknesses and help put practical protections in place without making everyday work unnecessarily difficult.
To discuss phishing protection or arrange a business cyber-security review, call Hamilton Group on 0330 043 0069 or visit hgmssp.com.