How to spot a phishing email: a checklist for staff
A plain-English checklist for spotting phishing emails: what to check in the sender, links, and request, how to report one, and what to do if you clicked.
To spot a phishing email, stop looking for bad spelling and check three things instead: who really sent it, where the link really goes, and whether the request makes sense. A message that pushes you to act fast, asks for a password, a code, or a payment, and arrives when you were not expecting it should be verified through a separate channel before anyone clicks, replies, or pays. The checklist below takes about a minute per message.
What is phishing, in one paragraph?
Phishing is a message that pretends to come from someone you trust (your bank, Microsoft, a vendor, a coworker) to get you to do something: click a link, open a file, type a password into a fake sign-in page, or send money. It arrives mostly by email, but also by text message, phone, and chat apps.
It is common. The FBI’s Internet Crime Complaint Center logged 191,561 phishing and spoofing complaints in 2025, more than any other category it tracks. Verizon’s 2026 Data Breach Investigations Report found that a person was involved in 62% of breaches, through a click, a reused password, or a mistake. Nobody is being careless. The messages are built to look normal.
The one-minute phishing checklist
Print this section or pin it in your team chat. No single item proves a message is fake. Two or more together means stop and verify.
1. Check who really sent it
- Look at the full address, not the display name. The name can say “Microsoft 365” or your manager’s name while the address behind it is something unrelated. On a computer, click or hover over the name. On a phone, tap it.
- Read the domain (the part after the @) slowly. Lookalikes swap or add characters:
rnicrosoft.com(r and n instead of m),yourvendor-billing.com, or.coinstead of.com. - Notice a changed reply address. If you hit Reply and the address that appears is different from the sender, treat that as a warning.
- A real address is not proof. If a vendor’s mailbox has been broken into, the phishing email comes from their genuine account. That is why the request matters more than the sender.
2. Check where the link really goes
- Hover before you click. On a computer, rest the pointer on the link and read the address that appears at the bottom of the window. On a phone, press and hold the link to preview it.
- Read the address from right to left. The real site is the last part before the first single slash.
microsoft.com.account-check.net/loginbelongs toaccount-check.net, not Microsoft. - Be careful with QR codes. A QR code in an email is just a link you cannot hover over, and it moves you to your personal phone, where your office protections may not apply. Microsoft now includes QR code phishing in its own staff training material for that reason.
- When in doubt, skip the link. Open a browser and type the address you already know, or use your bookmark.
3. Check the request itself
This is the check that still works when the writing is flawless. Ask:
- Was I expecting this? A shared document, invoice, voicemail file, or password reset you did not ask for deserves suspicion.
- Is it rushing me? “Your mailbox will be closed today” and “payment needed before 3 pm” are pressure, and pressure is the main tool.
- Is it asking for a secret? No legitimate company needs your password or the six digit sign-in code that was just sent to you. Nobody does, including whoever handles your IT.
- Does it involve money or bank details? New payment instructions, a changed bank account, gift cards, or a payroll deposit change should always be confirmed by phone using a number you already have. Our post on business email compromise covers that procedure in detail.
- Is it asking me to keep it quiet or skip a step? “Do not loop anyone in yet” is a strong sign of fraud.
4. Check attachments before opening
- Unexpected invoices, shipping labels, scanned documents, and “secure message” files are the most common carriers.
- Be wary of file types you rarely receive:
.zip,.iso,.html,.htm, or Office files that ask you to “enable content” or “enable editing.” - A password-protected attachment with the password in the same email is a technique for getting past email scanning, not a security feature.
Common phishing emails small offices receive
| What it looks like | What it is after |
|---|---|
| ”Your Microsoft 365 password expires today” or “storage is full” | Your email password, entered on a fake sign-in page |
| ”You have a new voicemail” or “scanned document from the copier” | A click on a malicious attachment or link |
| A shared file notice from OneDrive, Google Drive, DocuSign, or Dropbox you did not expect | Your sign-in details |
| An invoice or “updated bank details” from a supplier | A payment to the criminal’s account |
| A short note from the owner: “Are you at your desk? I need a favor” | Gift cards or a rushed transfer |
| A delivery problem or unpaid toll notice, often by text message | Card details or a malware download |
Why “look for typos” is no longer enough
Older advice told people to look for bad grammar and generic greetings. Those clues still show up sometimes, and the FTC still lists generic greetings as a sign. But the FBI has warned that criminals now use AI tools to write messages with fewer spelling and grammar errors, so a clean, well-written email proves nothing.
That is why this checklist leans on the sender, the link, and the request instead of the writing quality. For more on voice cloning and deepfakes, see our post on AI-powered phishing.
What should you do with a suspicious email?
- Do not click, open, reply, or forward it to coworkers.
- Verify through a different channel. Use a phone number or web address you already had, never one from the message.
- Report it with the built-in button. In Outlook, select the message, choose Report, then Report phishing. In Gmail, open the message, click More (the three dots next to Reply), then Report phishing. Reporting helps the filter learn and lets whoever manages your email see what is getting through.
- Tell the person who handles IT if the message was aimed at your business specifically (it names real staff, vendors, or invoices).
- Delete it.
You can also forward phishing emails to the Anti-Phishing Working Group at the address the FTC publishes, and forward scam text messages to 7726 (SPAM).
What if you already clicked?
Speed matters more than blame. An office where people report a mistake within minutes is much safer than one where they hide it.
| What happened | Do this now |
|---|---|
| Clicked a link but entered nothing | Close the tab, report the email, tell IT so the device can be checked |
| Entered your password | Change it right away from a different device, sign out of all sessions, confirm multi-factor authentication is on, tell IT |
| Entered or approved a sign-in code | Treat the account as taken over. Tell IT immediately so sessions can be revoked and mailbox rules checked |
| Opened an attachment or enabled content | Disconnect the computer from Wi-Fi or unplug the network cable, leave it on, and tell IT |
| Sent money or changed bank details | Contact your bank immediately to request a recall, then file a report at ic3.gov. The business email compromise post linked above has the full first-hour steps |
If the account was an email account, someone should also check for forwarding rules the attacker may have added. If customer or patient data may have been exposed, see what to do after a data breach.
What this checklist cannot do
A checklist lowers the odds. It does not remove them. Everyone has a distracted moment, and a message sent from a vendor’s genuinely compromised mailbox can pass every visual check. That is why people are one layer, not the only one:
- Email filtering removes most junk before anyone sees it. See spam filtering for business email.
- Multi-factor authentication limits the damage when a password is stolen.
- A payment verification rule stops the expensive mistakes even when the email looks perfect.
- Regular practice keeps the habit alive. See how to run security awareness training.
Common questions
Is it dangerous just to open a phishing email?
Usually not. With a current email app, reading a message is low risk. The harm comes from clicking a link, opening an attachment, enabling content in a document, scanning a QR code, or replying with information. If you opened a message and did nothing else, report it and move on.
Can a phishing email come from a real coworker or vendor address?
Yes. If someone’s mailbox has been taken over, the attacker sends from the genuine account, often replying inside a real conversation. The address check will pass. The request check still works: unexpected links, changed bank details, or urgency should be confirmed by phone on a number you already have.
Should I reply to ask whether the email is real?
No. If the account is controlled by an attacker, the attacker answers and says yes. Replying also confirms your address is active. Verify through a different channel: a known phone number, a chat message, or walking down the hall.
Are phishing text messages and phone calls handled the same way?
The same three checks apply: who is this really, where does the link go, does the request make sense. Verizon’s 2026 report notes that in phishing simulations, click rates on voice and text message lures ran 40% higher than email, so treat your phone with the same caution as your inbox.
How we can help
Coastal Growth Co. sets up the layers behind this checklist for small businesses in Orange County: email filtering and sender authentication, multi-factor authentication, the Report button, and short staff training that uses this same one-minute routine. If you want a review of how your office email is protected today, see our cloud and email services or get in touch. Scope and price are agreed before any paid work begins.
- phishing
- email security
- staff training
- checklist
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward