A sense of urgency is the first clue
Scam emails push you to act fast: an account will be closed, a payment has failed, a parcel is held. The urgency is deliberate, because it stops you thinking. A genuine organisation rarely demands an immediate response under threat. When a message is trying to rush you, that alone is reason to slow down and look harder before doing anything.
Check the real sender address
The display name is easy to fake; the actual address is harder. Hover over or tap the sender to see the real email behind the friendly name, and look for odd domains, extra words or near-misses of a real company. A message from your bank that comes from a free webmail account, or a domain spelled almost but not quite right, is a clear warning.
Hover before you click any link
The text of a link can say anything. Before clicking, hover on a computer or press and hold on a phone to see where it really goes. If the address does not match the company it claims to be from, or it points to a string of random characters, do not click. When in doubt, go to the website directly by typing the address you already know.
Watch for unexpected attachments and requests
Be wary of attachments you did not expect, especially ones asking you to enable content or log in to view them. Be just as wary of requests to change bank details, buy gift cards or move money urgently, even when they appear to come from a colleague or supplier. Attackers impersonate people you trust precisely because it works.
Poor detail, and the clever fakes
Spelling mistakes, odd grammar and generic greetings still give many scams away. But the better ones are now polished and personalised, so the absence of mistakes does not make a message safe. The reliable test is not how tidy it looks, it is whether the request makes sense and whether you can verify it through a channel you trust.
What to do with a suspicious message
Do not click, reply or open attachments. If it claims to be from a person or company, contact them through a number or address you already have, never the details in the email. Report it to whoever handles your IT, delete it, and if you think you have already clicked or entered a password, change that password and raise it straight away. Acting quickly limits the damage.
What to do next
Pause before acting on any email that creates urgency or asks for money, login details or a change of bank details. Check the real sender, hover over links, and verify anything important through a channel you already trust rather than the message itself.
Symnetrix can help set up business email with stronger protection against scams and advise on the habits that keep a small team safer day to day. Learn more about business email & microsoft 365 in Hastings and East Sussex, or contact Symnetrix to discuss your setup.