How to spot a phishing email

The tell-tale signs, real examples, and exactly what to do if someone clicks.

Phishing is the scam email that tries to make you click a link, open an attachment or hand over a password, and it starts most small business breaches. AI has made the fakes fluent, so the old advice about bad spelling no longer protects you.

Ask us about phishing training

Enter your details and we will call you back to talk through training and email protection for your team.

You will speak to our Brighton-based team, rated 4.9 stars on Google.

Five checks that catch most phishing emails

Check the sender’s real address, not the display name. A familiar name over a strange email address is the classic tell of a suspicious email.
Hover over links before you click. If the destination does not match the company the message claims to be from, stop there.
Question urgency and secrecy. Pay this today, keep it quiet, your account closes tonight: real suppliers and banks do not write like that.
Treat unexpected attachments and QR codes with care. Both are ways of getting past your filters.
Verify any request to change bank details by phone, using a number you already hold. Every time, no exceptions.

How AI has changed phishing

The National Cyber Security Centre's assessment of AI and the cyber threat is blunt: AI now gives criminals of every skill level the ability to produce convincing phishing, and the old tells are disappearing.

The spelling tell is dead. AI writes fluent, correctly branded emails in any language, so bad grammar no longer marks a message as fake.
Personal targeting is now cheap. AI can draft a convincing message from your LinkedIn page and website in seconds, so tailored scams arrive in bulk rather than one at a time.
Automation runs the whole scam. Criminals use AI to pick targets, write the emails, build the fake sign-in pages and keep the conversation going when someone replies.

Spot the tells: the fake invoice

Annotated example of a fake invoice phishing email with lookalike sender domain, urgent subject line and changed bank details

1 A lookalike sender domain, print spelt with a lowercase L. 2 Urgency in the subject line. 3 New bank details, which are the real goal.

What phishing looks like in 2026

The fake invoice. A supplier you recognise, correct branding, new bank details. The payment goes to the criminal.
The boss message. An email or text message that looks like it comes from a director, asking for an urgent payment or gift cards.
The MFA bombardment. Repeated sign-in prompts sent until someone taps approve to make them stop.
The QR code. A poster, delivery note or email that sends your phone to a fake sign-in page, past your email filters entirely.

Spot the tells: the boss message

Annotated example of a boss impersonation phishing email showing external sender address, urgency and secrecy

1 An outside email address, not your company domain. 2 Urgency plus secrecy, so you do not check with a colleague. 3 Pressure to act immediately.

If someone has already clicked

Change the password for that account first, from a different device, and check multi-factor authentication is still on.
Tell whoever runs your IT straight away. Speed matters far more than blame, and people report faster when nobody gets shouted at.
If money moved, call your bank immediately, then report it to Action Fraud.
Forward the phishing email to report@phishing.gov.uk, the National Cyber Security Centre’s reporting service, and forward scam texts to 7726.

Train your team to protect yourself from phishing

Spotting scams is a habit, and habits need practice. We run phishing awareness training for Sussex businesses, and our support clients get security courses for the whole team on Lightbulb, our training portal.

This guide covers spotting and responding. For locking down the email system itself, read our secure email guide.

Frequently asked questions

What is phishing?

Phishing is any message designed to trick you into giving away personal information, a password or a payment. Email is the biggest channel, but the same scams arrive by text message and phone call.

We use Microsoft 365. Does that stop phishing?

It filters a lot out, but no filter catches everything, and the most convincing scams are written to sail through. Settings reduce the volume; trained people catch the rest.

What is the difference between phishing and spear phishing?

Phishing is sent in bulk to anyone. Spear phishing is aimed at a named person, usually using details about your company to sound convincing, and it is far harder to spot. Our comparison explains both.

Should we report phishing emails even when nobody clicked?

Yes. Forward them to report@phishing.gov.uk. Reports take scam sites down and protect the next business, and it takes ten seconds.

Get new guides by email

One short email when a new guide goes live, and nothing else.