Practical technology guide

Phishing Emails: The Warning Signs to Watch For

Most successful attacks on small businesses start with an email rather than anything technical. A convincing message persuades someone to click a link, hand over a password or pay a fake invoice, and the rest follows. Learning to spot the signs is one of the cheapest and most effective protections a business has.

By Symnetrix / / Approximately 5 minute read

A sense of urgency is the first clue

Scam emails push you to act fast: an account will be closed, a payment has failed, a parcel is held. The urgency is deliberate, because it stops you thinking. A genuine organisation rarely demands an immediate response under threat. When a message is trying to rush you, that alone is reason to slow down and look harder before doing anything.

Check the real sender address

The display name is easy to fake; the actual address is harder. Hover over or tap the sender to see the real email behind the friendly name, and look for odd domains, extra words or near-misses of a real company. A message from your bank that comes from a free webmail account, or a domain spelled almost but not quite right, is a clear warning.

Hover before you click any link

The text of a link can say anything. Before clicking, hover on a computer or press and hold on a phone to see where it really goes. If the address does not match the company it claims to be from, or it points to a string of random characters, do not click. When in doubt, go to the website directly by typing the address you already know.

Keep the goal practical. The best technology choice is the one that fits the building, workload and level of support available.

Watch for unexpected attachments and requests

Be wary of attachments you did not expect, especially ones asking you to enable content or log in to view them. Be just as wary of requests to change bank details, buy gift cards or move money urgently, even when they appear to come from a colleague or supplier. Attackers impersonate people you trust precisely because it works.

Poor detail, and the clever fakes

Spelling mistakes, odd grammar and generic greetings still give many scams away. But the better ones are now polished and personalised, so the absence of mistakes does not make a message safe. The reliable test is not how tidy it looks, it is whether the request makes sense and whether you can verify it through a channel you trust.

What to do with a suspicious message

Do not click, reply or open attachments. If it claims to be from a person or company, contact them through a number or address you already have, never the details in the email. Report it to whoever handles your IT, delete it, and if you think you have already clicked or entered a password, change that password and raise it straight away. Acting quickly limits the damage.

What to do next

Pause before acting on any email that creates urgency or asks for money, login details or a change of bank details. Check the real sender, hover over links, and verify anything important through a channel you already trust rather than the message itself.

Symnetrix can help set up business email with stronger protection against scams and advise on the habits that keep a small team safer day to day. Learn more about business email & microsoft 365 in Hastings and East Sussex, or contact Symnetrix to discuss your setup.

Start a conversation

Talk about business email & microsoft 365

Get practical guidance based on your premises, equipment and priorities.

Contact Symnetrix