Skip to content
Cybersecurity

How to Spot a Phishing Email: The 7 Checks We Teach Staff

The seven checks that catch almost every phishing email, in the order to run them, plus what to do when you are not sure and what your IT team should have locked down already.

Jason Valerio 6 min read

Most people who get phished are not careless. They are busy, the email looked routine, and it arrived at 4:45 on a Friday. That is the whole design.

So learning how to spot a phishing email is less about being suspicious of everything and more about having a short list you run on the messages that ask you to do something. Here are the seven checks we teach client staff, in the order that catches the most with the least effort.

1. Read the actual sender address, not the display name

The display name is free text. Anyone can put “Microsoft 365” or your CEO’s name in it.

Click or tap the sender to expand the real address. You are looking for the domain after the @ sign. accounts@microsoft-verify-login.com is not Microsoft. jason@sagesolutionsllc.net is us. jason@sagesolutions-llc.net is not.

Lookalike domains are the entire game in business email compromise. A hyphen added, an “rn” where an “m” should be, .co instead of .com. On a phone the address is usually hidden by default, which is exactly why phishing works better on mobile.

2. Check whether the reply-to matches the from

Hit reply and look at where it is going before you type anything. A message that arrives from a spoofed address but replies to a Gmail account is not ambiguous. Delete it.

This one check catches a large share of invoice fraud, because the attacker needs your reply to land somewhere they control.

Do not trust the link text. “https://login.microsoftonline.com” as visible text can point anywhere.

On a desktop, hover and read the status bar. On a phone, long-press the link to see the destination without opening it. Look at the domain immediately before the first single slash. That is where you are actually going. Everything after it is decoration, and attackers stuff their URLs with real-looking words to fill the visible space.

Shortened links in business email deserve their own suspicion. There is rarely a good reason for a vendor to send you a bit.ly.

4. Ask what emotion it is going for

Phishing runs on urgency, authority, fear, and secrecy. Any message that combines a deadline with a request to break normal process is worth a second look.

Real patterns we see monthly:

  • “Your mailbox will be deactivated in 24 hours.”
  • “I am in a meeting, do not call me, I need this handled now.”
  • “Can you take care of a payment discreetly before end of day?”
  • “Payroll update: confirm your direct deposit details.”
  • A voicemail or fax notification from a system your company does not use.

Legitimate urgency almost never asks you to skip verification. Attackers need you moving fast enough not to think.

5. Was the attachment expected?

Unexpected attachments are the second most common delivery method after links.

Treat these as hostile until proven otherwise: .html and .htm files that open a fake login page locally, .zip and .iso files that hide the real payload from scanners, anything asking you to “enable content” or “enable macros,” and PDFs whose only content is a button that says View Document.

An invoice from a vendor you have never bought from is not an accounting problem. It is a phishing email with an accounting costume.

6. Is anyone asking to change where money goes?

This is the highest-cost category by a wide margin, and it deserves its own rule.

Any request to change bank details, wire instructions, direct deposit, or a payment portal gets verified by voice on a phone number you already had. Not the number in the email signature. Not by replying. Not over text.

Make this an actual written policy with a dollar threshold, and make it apply to the owner too. The whole point of a CEO fraud email is that nobody wants to make the boss verify himself.

7. Did you start the MFA prompt you just received?

If your phone buzzes with an approval request you did not trigger, someone has your password and is standing at the door.

Deny it, and then report it immediately, because the deny is not the fix. The fix is changing that password before the attacker moves to a service that does not prompt. MFA fatigue attacks work by sending prompts until someone taps approve to make the buzzing stop.

When you are not sure

You will not be sure sometimes. That is fine, and it is not a failure.

  • Do not reply to the email to ask if it is real. If it is fake, you are asking the attacker.
  • Call the sender on a number you already have.
  • Report it properly. In Outlook, select the message, click Report, then Report phishing from the dropdown. In Gmail it is the three-dot menu on the open message, then Report phishing. This routes the message to your security team and to Microsoft or Google, which improves filtering for everyone. In Outlook, reporting a message as phishing also deletes it from your mailbox, which is what you want.
  • If you already clicked and entered credentials, say so immediately. The first thirty minutes matter enormously and nobody is going to be angry at you. We would much rather reset a password than run an incident response engagement.

Speed of reporting is the single biggest variable in how bad a phishing incident gets. Companies that punish reporting get slow reporting, and slow reporting is how you end up reading our ransomware recovery checklist for real.

What should already be in place

Training staff is necessary and it is not sufficient. Someone will eventually click, so the technical controls have to catch what human judgment misses.

At minimum:

  • SPF, DKIM, and DMARC configured on your domain, with DMARC actually set to quarantine or reject rather than the “none” it got set to during setup and never revisited
  • External sender banners on inbound mail
  • Impersonation and lookalike-domain protection for your executives and finance staff
  • MFA on every account, with number matching rather than simple approve prompts
  • Conditional access rules that block sign-ins from countries you do not operate in
  • Mailbox rule auditing, because the first thing an attacker does after taking a mailbox is create a rule that hides their replies

Most of these ship with Microsoft 365 Business Premium and are simply switched off by default. We turn them on as part of standard cybersecurity onboarding, and the audit takes about a day for a company under 100 seats.

If you are not sure which of the above your tenant actually has enabled, ask us to look. We will tell you what is on, what is off, and which two settings would have stopped the last email that got through.

JV

Written by

Jason Valerio

Founder of Sage Solutions. 20+ years in NY/NJ IT and low-voltage, Certified Ethical Hacker (CEH), and ex-FDNY. More about Jason →

Related services

Want to talk about this?

We are happy to have a 30-minute call about anything in this article — your environment, your risks, your options.

Call Free assessment