Phishing emails remain one of the most common and successful ways cybercriminals gain access to business systems. Despite advances in security technology, attackers continue to rely on one simple tactic: tricking people.
At OBT, we regularly see phishing attempts slip through inboxes, even in organisations with strong technical controls. Knowing what to look for is one of the most effective ways to stop an attack before damage is done.
Here’s how to identify a phishing email, and what to do if you spot one.
What Is a Phishing Email?
A phishing email is a fraudulent message designed to appear legitimate, with the goal of getting you to:
Click a malicious link
Open an infected attachment
Share sensitive information (passwords, MFA codes, banking details)
These emails often impersonate trusted brands, suppliers, colleagues, or internal systems such as Microsoft 365.
Common Signs of a Phishing Email
1. A Sense of Urgency or Threat
Phishing emails often try to panic the recipient into acting quickly.
Examples include:
“Your account will be locked in 24 hours”
“Unusual login detected, verify immediately”
“Outstanding invoice, payment overdue”
Urgency is used to bypass rational thinking.
2. Suspicious Sender Details
The display name may look correct, but the actual email address often tells a different story.
Watch for:
Misspellings or extra characters
Public domains pretending to be business emails
Slight variations (e.g.
micros0ft.cominstead ofmicrosoft.com)
Always check the full sender address, not just the name.
3. Generic Greetings
Legitimate internal or business emails usually address you by name.
Red flags include:
“Dear User”
“Dear Customer”
“Attention Account Holder”
Phishing emails are often sent in bulk and lack personalisation.
4. Unexpected Links or Attachments
If you weren’t expecting a document or link, be cautious, even if it appears to come from someone you know.
Before clicking:
Hover over links to see the real destination
Be wary of shortened URLs
Question attachments that require you to “enable content” or “log in”
5. Poor Grammar or Formatting
Many phishing emails contain:
Awkward phrasing
Spelling mistakes
Inconsistent logos or formatting
While some attacks are very polished, poor language is still a common warning sign.
6. Requests for Credentials or MFA Codes
No legitimate organisation will ask you to:
Share your password
Send an MFA code
Log in via an emailed link without context
If an email asks for this information, treat it as suspicious.
What a Phishing Email Typically Looks Like
Below is an example of a classic phishing email layout, showing the most common warning signs employees should look for.

A trusted brand logo
An urgent subject line
A call-to-action button (“Verify Account”, “Review Activity”)
A sender address that looks almost legitimate
What To Do If You Receive a Suspicious Email
If you think an email may be phishing:
Do not click links or open attachments
Do not reply to the email
Report it to your IT or security team
Delete the email once reported
Early reporting helps protect the entire organisation.
Phishing Awareness Is a Business Responsibility
Technology alone isn’t enough. The most effective defence against phishing is a combination of:
User awareness and training
Strong email security controls
Ongoing simulated phishing exercises
Clear reporting processes
Businesses that invest in awareness dramatically reduce their risk of breaches caused by human error.
Want to Strengthen Your Organisation’s Defences?
At OBT, we help businesses:
Educate staff on real-world phishing threats
Run phishing simulations and awareness training
Implement email and identity security controls
Build a security-first culture
👉 Contact OBT today to learn how we can help protect your people and your business from phishing attacks.



