Concepts

Spot a phishing email

The signs that give a phishing message away, and what to do when you are not sure.

PublicUpdated October 6, 2026

Phishing works by getting you to act before you think. The message wants a click, a password, a payment or a reply, and it wants it now. You don't need to be certain a message is fake to stop. You only need to notice that it is asking for something and that something about it is off.

Check who it is really from

  • Look at the address, not just the display name. "IT Service Desk" can sit in front of any address at all.
  • Watch for lookalike domains: an extra letter, a swapped letter, a different ending, or your company's name inside someone else's domain (yourcompany.support-desk.com belongs to support-desk.com).
  • A message from a colleague can still be phishing if their account was taken over. If the request is unusual for them, check with them another way.

Notice what it wants you to do

Phishing asks you to do something. These are the common requests:

  • Sign in. A link to a sign-in page for email, file sharing, payroll or a parcel service. Real services rarely need you to sign in from an email link.
  • Pay or change payment details. An invoice, a new bank account for a supplier, gift cards for a manager. These requests are worth a phone call to a number you already have.
  • Open something. An attachment you were not expecting, especially one that asks you to enable content or open a second file.
  • Call a number. "Your subscription renews today, call us to cancel." The phone call is where the scam happens.
  • Scan a QR code. A QR code takes your phone off the protected work network and hides the address until it is too late to judge it.
  • Approve a sign-in prompt. If your phone asks you to approve a sign-in you did not start, deny it and tell IT. Repeated prompts are an attack, not a glitch.

Notice how it makes you feel

Urgency, fear, curiosity and flattery are the levers. "Your account will be closed today." "You've been mentioned in a complaint." "Your bonus letter is attached." If a message makes you want to act quickly, that is the moment to slow down.

On a computer, rest the pointer on the link without clicking and read the address that appears. On a phone, press and hold the link to preview it. Read the domain from right to left, starting just before the first single slash: that part tells you who owns the page.

When you are not sure

Report it. A wrong guess costs nothing: the people who review reports would rather see ten safe messages than miss one real attack. See Report a suspicious email.

If you already clicked, entered a password or opened an attachment, report it straight away and tell your IT or security team. Changing a password ten minutes after a mistake is far better than finding out a week later.

Still stuck?Contact support

Related