Security · 7 min read · By IT Support Team
How to Spot Phishing Emails: Protect Yourself at Work
Phishing emails are the single most common cyber threat facing employees today. According to industry data, over 90% of data breaches begin with a phishing message. These emails impersonate trusted sources — your bank, your IT department, a colleague, a delivery service — to trick you into clicking malicious links, opening infected attachments, or handing over credentials. The good news is that phishing emails almost always leave detectable clues. This guide walks you through every major red flag, gives you a practical checklist to evaluate any suspicious email, and explains exactly what to do when one lands in your inbox.
Published 2025-07-25 · Updated 2025-07-25
What Is a Phishing Email?
- Steal login credentials by directing you to a fake login page
- Deliver malware through infected attachments or linked downloads
- Trick you into authorising a fraudulent payment or wire transfer (business email compromise)
- Gain access to internal systems by harvesting session tokens
7 Red Flags That Reveal a Phishing Email
1. Mismatched or Spoofed Sender Addresses
2. Generic Greetings Instead of Your Name
3. Urgency, Fear, or Threats
- "Your account will be suspended in 24 hours unless you verify your identity."
- "Action required: your payment was declined. Update your billing information immediately."
- "We detected suspicious activity on your account. Click here to secure it now."
4. Suspicious Links That Don't Match the Real URL
- URLs that use an IP address instead of a domain name (http://192.168.1.5/login)
- Domains with extra subdomains (login.company-333985.dls.so.evil-site.com)
- URL shorteners (bit.ly, tinyurl) used to hide the real destination
- Misspelled domain names (company-333985.dIs.so with a capital I instead of lowercase l)
5. Unexpected Attachments
- .exe, .scr, or .js files — these are executable and should never arrive by email
- .zip or .rar archives — often used to hide malicious payloads
- .docm, .xlsm, .pptm — Microsoft Office files with macros enabled
- PDFs from unknown senders — while PDFs are generally safer, crafted PDFs can exploit reader vulnerabilities
6. Spelling and Grammar Errors
7. Requests for Sensitive Information
- Your password or "verification" of your password
- Your 2FA backup codes
- Your full credit card or bank account number
- Remote access to your computer (via tools like AnyDesk or TeamViewer)
A Step-by-Step Checklist for Every Suspicious Email
- Check the sender address. Does it match the organisation's real domain exactly?
- Look at the greeting. Does it use your name, or a generic "Dear User"?
- Assess the tone. Is it urgent, threatening, or emotionally manipulative?
- Hover over links. Do the actual URLs match where the link text says it goes?
- Scan for attachments. Are there unexpected files? Are they executable or macro-enabled formats?
- Check for consistency. Does the email signature match the sender? Does the formatting look professional?
- Verify independently. If the email claims to be from a colleague or your IT department, contact that person directly using a known phone number or internal chat — not the contact details in the suspicious email.
What to Do When You Receive a Phishing Email
- Do not click any links or open any attachments. Even hovering is safe, but clicking is not.
- Do not reply to the sender. Replying confirms your email address is active and monitored, making you a target for future attacks.
- Forward the email to security@company-333985.dls.so. This is the dedicated security reporting address. The IT security team will analyse the email, check whether similar messages went to other employees, and take action to block the sender or domain.
- Delete the email from your inbox and your trash folder after forwarding it.
- If you already clicked a link or opened an attachment, contact IT support immediately at atif.1@company-333985.dls.so or call +33162290341. Quick reporting allows the security team to contain the damage, reset credentials, and scan your device before the attacker can pivot deeper.
How to Report Phishing in Microsoft Outlook and Gmail
In Microsoft Outlook (Desktop)
- Select the suspicious email in your inbox.
- Click the "Report" button in the ribbon, then choose "Report Phishing."
- If you don't see the Report button, use the dropdown arrow on the Junk button and select "Report as Phishing."
- Confirm the dialog. The email is forwarded to Microsoft and moved to your Junk folder.
In Gmail (Web)
- Open the suspicious email.
- Click the three-dot menu icon (More) next to the Reply button.
- Select "Report phishing."
- Confirm in the dialog that appears. Google uses this data to improve its spam and phishing filters.
In Microsoft Teams
- Click the three-dot menu next to the message.
- Select "Report a concern" and follow the prompts.
Common Phishing Scenarios in the Workplace
The CEO Fraud (Business Email Compromise)
The IT Helpdesk Impersonation
The Package Delivery Scam
The Invoice or Billing Alert
How Company #333985 Protects You
- Inbound email filtering scans all incoming messages for known phishing signatures, malicious links, and suspicious attachments before they reach your inbox.
- DMARC, SPF, and DKIM authentication protocols verify that emails claiming to be from company-333985.dls.so actually originated from our servers, preventing domain spoofing.
- Two-factor authentication (2FA) ensures that even if an attacker obtains your password, they cannot access your account without the second factor. Enable two-factor authentication (2FA) on your account today.
- Security awareness training is provided to all employees to build recognition of phishing tactics.
Frequently Asked Questions
Common questions about phishing emails and email security.
What is the difference between phishing and spear phishing?
Phishing is a broad, untargeted attack — the same fake email is sent to thousands of recipients hoping a few will bite. Spear phishing is a targeted attack tailored to a specific individual, often using personal details like your name, role, or recent projects to appear legitimate. Spear phishing emails are harder to detect because they are customised and may reference real colleagues, meetings, or company initiatives.
Can phishing emails come from internal company email addresses?
Yes. If a colleague's account has been compromised, the attacker can send phishing emails from their real internal address. This is why you should always be cautious of unexpected requests for sensitive information or financial actions, even from people you know. If something seems out of character for a colleague, verify through another channel.
I clicked a link in a phishing email but didn't enter any information. Am I safe?
Possibly, but you should still report it. Clicking a link can trigger a "drive-by download" of malware or confirm to the attacker that your email address is active. Contact IT support immediately so they can scan your device and check whether any background activity occurred.
How can I check if a link is safe without clicking it?
Hover your cursor over the link to see the real URL in the bottom corner of your browser. On mobile, long-press the link to see a preview. You can also copy the link and paste it into a URL scanner like VirusTotal (virustotal.com) or URLVoid, which check the link against multiple security databases. Never paste a link directly into your browser if you have any doubt about its origin.
What should I do if I already entered my password on a phishing site?
Change your password immediately on the legitimate site, enable 2FA if you haven't already, and contact IT support. If you used the same password on other services, change those too. The faster you act, the more you limit the attacker's window of opportunity.
Will I get in trouble for clicking a phishing link?
No. Reporting a mistake quickly is exactly what IT needs to protect the organisation. You will not be penalised for reporting a phishing email or admitting you clicked a link. The only mistake that causes real damage is staying silent.
Stay vigilant, stay safe
Phishing attacks are relentless, but they rely on one thing: that you won't pause to look closely. Every red flag in this guide — mismatched sender addresses, generic greetings, manufactured urgency, suspicious links — is a crack in the attacker's disguise. Build the habit of pausing before you click, and when something feels off, trust that instinct and report it. If you receive a suspicious email, forward it to security@company-333985.dls.so and contact IT support at atif.1@company-333985.dls.so or +33162290341.