How to Identify a Phishing Email (And Avoid Costly Mistakes)

Phishing

Phishing emails remain one of the most common and successful ways cybercriminals gain access to business systems. Despite advances in security technology, attackers continue to rely on one simple tactic: tricking people.

At OBT, we regularly see phishing attempts slip through inboxes, even in organisations with strong technical controls. Knowing what to look for is one of the most effective ways to stop an attack before damage is done.

Here’s how to identify a phishing email, and what to do if you spot one.

What Is a Phishing Email?

A phishing email is a fraudulent message designed to appear legitimate, with the goal of getting you to:

  • Click a malicious link

  • Open an infected attachment

  • Share sensitive information (passwords, MFA codes, banking details)

These emails often impersonate trusted brands, suppliers, colleagues, or internal systems such as Microsoft 365.

Common Signs of a Phishing Email

1. A Sense of Urgency or Threat

Phishing emails often try to panic the recipient into acting quickly.

Examples include:

  • “Your account will be locked in 24 hours”

  • “Unusual login detected, verify immediately”

  • “Outstanding invoice, payment overdue”

Urgency is used to bypass rational thinking.

2. Suspicious Sender Details

The display name may look correct, but the actual email address often tells a different story.

Watch for:

  • Misspellings or extra characters

  • Public domains pretending to be business emails

  • Slight variations (e.g. micros0ft.com instead of microsoft.com)

Always check the full sender address, not just the name.

3. Generic Greetings

Legitimate internal or business emails usually address you by name.

Red flags include:

  • “Dear User”

  • “Dear Customer”

  • “Attention Account Holder”

Phishing emails are often sent in bulk and lack personalisation.

4. Unexpected Links or Attachments

If you weren’t expecting a document or link, be cautious, even if it appears to come from someone you know.

Before clicking:

  • Hover over links to see the real destination

  • Be wary of shortened URLs

  • Question attachments that require you to “enable content” or “log in”

5. Poor Grammar or Formatting

Many phishing emails contain:

  • Awkward phrasing

  • Spelling mistakes

  • Inconsistent logos or formatting

While some attacks are very polished, poor language is still a common warning sign.

6. Requests for Credentials or MFA Codes

No legitimate organisation will ask you to:

  • Share your password

  • Send an MFA code

  • Log in via an emailed link without context

If an email asks for this information, treat it as suspicious.

What a Phishing Email Typically Looks Like

Below is an example of a classic phishing email layout, showing the most common warning signs employees should look for.

https://learn.microsoft.com/en-us/troubleshoot/microsoft-365/admin/admin/account-security/media/account-security-alert-email/security-alert-message.png
Typical features include:
  • A trusted brand logo

  • An urgent subject line

  • A call-to-action button (“Verify Account”, “Review Activity”)

  • A sender address that looks almost legitimate

What To Do If You Receive a Suspicious Email

If you think an email may be phishing:

  1. Do not click links or open attachments

  2. Do not reply to the email

  3. Report it to your IT or security team

  4. Delete the email once reported

Early reporting helps protect the entire organisation.

Phishing Awareness Is a Business Responsibility

Technology alone isn’t enough. The most effective defence against phishing is a combination of:

  • User awareness and training

  • Strong email security controls

  • Ongoing simulated phishing exercises

  • Clear reporting processes

Businesses that invest in awareness dramatically reduce their risk of breaches caused by human error.

Want to Strengthen Your Organisation’s Defences?

At OBT, we help businesses:

  • Educate staff on real-world phishing threats

  • Run phishing simulations and awareness training

  • Implement email and identity security controls

  • Build a security-first culture

👉 Contact OBT today to learn how we can help protect your people and your business from phishing attacks.

Leave a Reply

Your email address will not be published. Required fields are marked *

Sign up for our Newsletter