How to Spot a Phishing Email: 6 Red Flags Everyone at Work Should Know
September 1, 2026 — by admin
Phishing emails have moved on a long way from the badly spelled messages of ten years ago. The ones landing in inboxes across Buckinghamshire and Oxfordshire today are polished, well written, and often copied word for word from a genuine invoice or delivery notice. We see the fallout regularly: a small business that paid a real invoice into a criminal’s bank account, or a homeowner who gave away their email password without realising it. The good news is that almost every phishing attempt still gives itself away somewhere. Here are six red flags worth sharing with your team or your family.
1. Check the actual email address, not the display name
The name at the top of an email is only a label, and anyone can type whatever they like into it. A message that appears to be from “Microsoft Account Team” might really be coming from a free webmail account or a lookalike domain such as micros0ft-support.net. On a computer, hover your mouse over the sender’s name to reveal the full address. On a phone, tap the name to expand it. Pay close attention to everything after the @ symbol, because that part is much harder for a scammer to fake convincingly. If the domain does not match the organisation the email claims to come from, stop reading and delete it.
2. Be suspicious of anything that rushes you
Urgency is a scammer’s favourite tool. Your account will be suspended within 24 hours. Your parcel could not be delivered and will be returned today. Payment is overdue and legal action will follow. The point is to make you act before you think, because a moment of calm consideration is usually all it takes to spot the con. Genuine organisations rarely give you a few hours to respond to something important, and your bank will never threaten you by email. If a message makes your stomach drop, treat that reaction as a warning sign rather than a reason to hurry.
3. Hover over links before you click anything
Link text can say one thing while pointing somewhere completely different. Hovering your mouse over a link shows the real destination in the bottom corner of your screen, and on a phone you can press and hold the link to preview it. Read the address from left to right and find the main domain, which is the bit immediately before the first single slash. A link to hsbc.secure-login-verify.com is not HSBC, it is a site called secure-login-verify.com. When in doubt, ignore the link entirely and type the company’s web address into your browser yourself, or use the app on your phone.
4. Treat unexpected attachments with real caution
Attachments are still one of the most common ways ransomware gets onto a business network. Be wary of anything you were not expecting, particularly invoices, CVs, quotes, and scanned documents from senders you do not deal with. Files ending in .exe, .zip, .iso, or .html are especially risky, and a Word or Excel file that asks you to “enable content” when you open it should be closed straight away. A quick phone call to check takes thirty seconds and could save you weeks of disruption.
5. Any request to change bank details deserves a phone call
This is the one that costs local businesses the most money. It usually arrives as a polite note from a supplier you genuinely use, explaining that they have changed banks and asking you to update their details before the next payment. Sometimes the criminals have been reading the real email thread for weeks, so the tone and timing are perfect. The rule should apply without exception: never change payment details on the strength of an email. Ring the supplier on a number you already hold, not the number printed in the message, and confirm the change with a person you know.
6. What to do if you think you have already clicked
Acting quickly makes a huge difference, and nobody should feel embarrassed about being caught out by a convincing fake. If you have entered a password or opened something suspicious, work through these steps.
- Disconnect the device from Wi-Fi or unplug the network cable to stop anything spreading.
- Change the password for the affected account from a different device, and change it anywhere else you have used the same one.
- Switch on two-factor authentication for your email first, since that is the account criminals use to reset everything else.
- Run a full antivirus scan, and check your email for any forwarding rules you did not create.
- Tell your bank immediately if money or payment details were involved, and report the message to report@phishing.gov.uk.
Prevention beats cure, and it is cheaper too
Most of the phishing damage we are called out to fix could have been prevented by a few straightforward measures: two-factor authentication on email and banking, a password manager so nobody reuses passwords, decent spam filtering, and a tested backup kept away from the main network. None of it is expensive or technical. It just needs setting up properly once.
Geni-Tech provides friendly, plain-English IT support to homes and small businesses across Buckinghamshire and Oxfordshire, including cyber security reviews, email protection, two-factor authentication setup, and backups you can actually rely on. If you would like someone to look over your systems, or you think you may have clicked something you shouldn’t have, we are happy to help. Get in touch today →