
How to Spot a Phishing Email Before It Costs You
Almost every security incident I've cleaned up for a small business started with a single email. Not a clever zero-day exploit, not a targeted attack; just an email that looked plausible enough for someone to click.
Phishing is still the number one way small businesses get hacked. The good news is that nearly all phishing emails give themselves away if you know where to look. Here's what I teach every client to check before clicking, replying, or entering a password.
1. Check the sender's actual email address
The display name is the easiest thing in the world to fake. An email can say it's from "Microsoft 365 Support" while actually being sent from
If the domain doesn't match the organisation you'd expect, stop reading and delete the email. Legitimate Microsoft emails come from microsoft.com. Legitimate HMRC emails come from hmrc.gov.uk. Anything else pretending to be them is a fake.
2. Look at how the email addresses you
"Dear Customer", "Dear User", or "Dear sir/madam" are classic phishing openers. Real companies you do business with know your name, your account number, or at least something specific about you. Generic greetings are a strong signal that the email has been blasted to thousands of addresses.
3. Watch for artificial urgency
Phishing works because it rushes you. The email will tell you your account will be closed in 24 hours, your mailbox is over quota, your invoice is overdue, or HMRC is about to take legal action. The point of the urgency is to stop you thinking clearly.
Real organisations don't operate this way. If something genuinely needs your attention, you'll have plenty of time to check it through official channels.
4. Hover over every link before you click
On a computer, hovering over a link shows you the real destination in the bottom corner of the screen. On a phone, press and hold the link to see the preview. If the email claims to be from your bank but the link goes to secure-banking-login.info, you've found your phishing email.
When in doubt, don't click the link at all. Open a new browser tab and go to the real website yourself.
5. Be suspicious of unexpected attachments
If you weren't expecting a document, a ZIP file, or a PDF, don't open it, no matter who it's from. Attackers routinely compromise one business email account and use it to send malware to everyone in that person's contact list. The name on the sender looks familiar because it genuinely is familiar; the content just isn't really from them.
The safest move is to phone the sender and ask if they actually sent it.
6. Treat password and payment requests with extra caution
No legitimate IT provider, bank, or software company will ever email you asking for your password. And no genuine supplier changes their bank details by email without a phone call to confirm. These two scams, credential harvesting and invoice redirection, are responsible for huge losses at small businesses every year.
What to do if you've clicked something
Don't panic, but do act quickly. Disconnect the device from the network, change any password you entered, turn on multi-factor authentication if it isn't already on, and tell your IT provider straight away. The faster we know, the more we can contain.
Training your team
Most phishing incidents aren't caused by careless people; they're caused by busy people. A good security posture means assuming someone will eventually click, and making sure the damage is limited when they do. That means proper email filtering, multi-factor authentication on every account, endpoint protection, and regular reminders to staff.
If you'd like a simple phishing awareness briefing for your team, I include this as standard for my managed support clients.
ClearPath IT Services provides cyber security support for small businesses across Kent, Medway and South East London. Find out more about our cyber security services.