Security · 7 min read · By IT Support Team

How to Spot Phishing Emails: Protect Yourself at Work

Phishing emails are the single most common cyber threat facing employees today. According to industry data, over 90% of data breaches begin with a phishing message. These emails impersonate trusted sources — your bank, your IT department, a colleague, a delivery service — to trick you into clicking malicious links, opening infected attachments, or handing over credentials. The good news is that phishing emails almost always leave detectable clues. This guide walks you through every major red flag, gives you a practical checklist to evaluate any suspicious email, and explains exactly what to do when one lands in your inbox.

Published 2025-07-25 · Updated 2025-07-25

What Is a Phishing Email?

Phishing is a type of social engineering attack where the sender disguises themselves as a trusted entity to manipulate the recipient into taking a harmful action. The term comes from "fishing" — the attacker casts a wide net of emails and waits for someone to bite. A more targeted variant, "spear phishing," tailors the message to a specific individual using personal details gathered from social media or data breaches, making it far harder to detect.
Within a corporate environment, phishing emails typically aim to:
  • Steal login credentials by directing you to a fake login page
  • Deliver malware through infected attachments or linked downloads
  • Trick you into authorising a fraudulent payment or wire transfer (business email compromise)
  • Gain access to internal systems by harvesting session tokens
Understanding the attacker's goal helps you recognise the urgency and pressure tactics they use to short-circuit your normal judgment.

7 Red Flags That Reveal a Phishing Email

Most phishing emails can be identified by paying attention to one or more of the following warning signs. You do not need to see all of them — even a single red flag warrants caution.

1. Mismatched or Spoofed Sender Addresses

The display name in your inbox might read "IT Support" or "Finance Department," but the actual email address tells the real story. Hover over or tap the sender name to reveal the full address. A legitimate internal email will come from your company domain. A phishing email often uses a look-alike domain: company-333985.dls.so might be impersonated as company-333985.dls.co or company333985-support.com. Watch for subtle character substitutions too — a lowercase "l" replaced by the digit "1", or an "o" swapped for a zero.

2. Generic Greetings Instead of Your Name

Legitimate organisations that know you — your bank, your employer, your service providers — address you by name. Phishing emails frequently use generic salutations like "Dear User," "Dear Customer," or "Dear Employee." If the email claims to be from your IT department but opens with "Dear Valued Team Member," that is a red flag. Attackers use generic greetings because they send the same message to thousands of recipients and do not know your name.

3. Urgency, Fear, or Threats

Phishing emails manufacture urgency to prevent you from thinking clearly. Common pressure tactics include:
  • "Your account will be suspended in 24 hours unless you verify your identity."
  • "Action required: your payment was declined. Update your billing information immediately."
  • "We detected suspicious activity on your account. Click here to secure it now."
Real IT departments and service providers do not threaten immediate account closure without prior notice. When an email tries to make you act before you have time to think, slow down and verify through a separate channel.

5. Unexpected Attachments

Attachments are a primary delivery method for malware. Be especially cautious with:
  • .exe, .scr, or .js files — these are executable and should never arrive by email
  • .zip or .rar archives — often used to hide malicious payloads
  • .docm, .xlsm, .pptm — Microsoft Office files with macros enabled
  • PDFs from unknown senders — while PDFs are generally safer, crafted PDFs can exploit reader vulnerabilities
If you are not expecting a file from the sender, do not open it. Contact the sender through a known, separate channel to confirm they sent it. If malware is causing slowdowns after opening a suspicious attachment, run a full system scan and contact IT support immediately.

6. Spelling and Grammar Errors

Large organisations employ copywriters and proofreaders. A legitimate email from your bank or IT department will not contain obvious spelling errors, awkward phrasing, or inconsistent formatting. Many phishing emails originate from non-native speakers or are machine-translated, producing telltale mistakes. That said, the rise of AI-assisted phishing means this signal is weakening — well-written phishing emails are now common. Treat the absence of grammar errors as neutral, not as proof of legitimacy.

7. Requests for Sensitive Information

No legitimate IT department, bank, or service will ever ask you for your password, full credit card number, or 2FA code by email. If an email requests:
  • Your password or "verification" of your password
  • Your 2FA backup codes
  • Your full credit card or bank account number
  • Remote access to your computer (via tools like AnyDesk or TeamViewer)
…it is phishing, full stop. End of discussion. Report it and delete it.

A Step-by-Step Checklist for Every Suspicious Email

When an email seems even slightly off, run through this mental checklist before taking any action:
  1. Check the sender address. Does it match the organisation's real domain exactly?
  2. Look at the greeting. Does it use your name, or a generic "Dear User"?
  3. Assess the tone. Is it urgent, threatening, or emotionally manipulative?
  4. Hover over links. Do the actual URLs match where the link text says it goes?
  5. Scan for attachments. Are there unexpected files? Are they executable or macro-enabled formats?
  6. Check for consistency. Does the email signature match the sender? Does the formatting look professional?
  7. Verify independently. If the email claims to be from a colleague or your IT department, contact that person directly using a known phone number or internal chat — not the contact details in the suspicious email.
If anything on this checklist fails, treat the email as phishing. Do not click, do not reply, and report it.

What to Do When You Receive a Phishing Email

If you identify a phishing email, take these steps immediately:
  1. Do not click any links or open any attachments. Even hovering is safe, but clicking is not.
  2. Do not reply to the sender. Replying confirms your email address is active and monitored, making you a target for future attacks.
  3. Forward the email to security@company-333985.dls.so. This is the dedicated security reporting address. The IT security team will analyse the email, check whether similar messages went to other employees, and take action to block the sender or domain.
  4. Delete the email from your inbox and your trash folder after forwarding it.
  5. If you already clicked a link or opened an attachment, contact IT support immediately at atif.1@company-333985.dls.so or call +33162290341. Quick reporting allows the security team to contain the damage, reset credentials, and scan your device before the attacker can pivot deeper.
For a quick refresher, you can also review our FAQ on what to do when you suspect a phishing email.

How to Report Phishing in Microsoft Outlook and Gmail

Most email clients allow you to report phishing directly from the interface, which helps your email provider improve filtering for everyone.

In Microsoft Outlook (Desktop)

  1. Select the suspicious email in your inbox.
  2. Click the "Report" button in the ribbon, then choose "Report Phishing."
  3. If you don't see the Report button, use the dropdown arrow on the Junk button and select "Report as Phishing."
  4. Confirm the dialog. The email is forwarded to Microsoft and moved to your Junk folder.

In Gmail (Web)

  1. Open the suspicious email.
  2. Click the three-dot menu icon (More) next to the Reply button.
  3. Select "Report phishing."
  4. Confirm in the dialog that appears. Google uses this data to improve its spam and phishing filters.

In Microsoft Teams

Phishing attempts can also arrive via Teams messages, not just email. If you receive a suspicious direct message from someone you don't know:
  1. Click the three-dot menu next to the message.
  2. Select "Report a concern" and follow the prompts.

Common Phishing Scenarios in the Workplace

Phishing attacks targeting employees often follow recognisable patterns. Here are the most common scenarios:

The CEO Fraud (Business Email Compromise)

The attacker impersonates a senior executive — often the CEO or CFO — and sends an urgent email to an employee in finance or HR requesting a wire transfer, gift card purchase, or sensitive employee data. The email typically cites a confidential matter, a time-sensitive deal, or an off-site meeting as the reason for bypassing normal procedures. Always verify financial or data requests through a second channel (phone call to the executive's known number, or in-person confirmation).

The IT Helpdesk Impersonation

The attacker pretends to be from IT support, claiming your account needs verification, your password is expiring, or suspicious activity was detected. The email includes a link to a fake login page that captures your credentials. Real IT support will never ask for your password by email. If you're unsure, contact IT directly using the number on the company intranet, not the one in the email.

The Package Delivery Scam

A message claiming a package is waiting for delivery, with a link to "track your shipment" or "pay customs fees." These emails spike during holiday seasons and target personal as well as work addresses. If you're not expecting a package, treat the email as suspicious. Track packages by going directly to the carrier's website and entering the tracking number there.

The Invoice or Billing Alert

An email claiming your subscription is expiring, a payment failed, or your account will be downgraded. It includes a link to "update payment information" that leads to a credential-harvesting page. Always verify billing changes by logging into the service directly through your browser.

How Company #333985 Protects You

Our organisation deploys multiple layers of email security:
  • Inbound email filtering scans all incoming messages for known phishing signatures, malicious links, and suspicious attachments before they reach your inbox.
  • DMARC, SPF, and DKIM authentication protocols verify that emails claiming to be from company-333985.dls.so actually originated from our servers, preventing domain spoofing.
  • Two-factor authentication (2FA) ensures that even if an attacker obtains your password, they cannot access your account without the second factor. Enable two-factor authentication (2FA) on your account today.
  • Security awareness training is provided to all employees to build recognition of phishing tactics.
These measures significantly reduce the volume of phishing emails that reach you, but no filter is perfect. Your vigilance remains the most important layer of defence.

Frequently Asked Questions

Common questions about phishing emails and email security.

What is the difference between phishing and spear phishing?

Phishing is a broad, untargeted attack — the same fake email is sent to thousands of recipients hoping a few will bite. Spear phishing is a targeted attack tailored to a specific individual, often using personal details like your name, role, or recent projects to appear legitimate. Spear phishing emails are harder to detect because they are customised and may reference real colleagues, meetings, or company initiatives.

Can phishing emails come from internal company email addresses?

Yes. If a colleague's account has been compromised, the attacker can send phishing emails from their real internal address. This is why you should always be cautious of unexpected requests for sensitive information or financial actions, even from people you know. If something seems out of character for a colleague, verify through another channel.

I clicked a link in a phishing email but didn't enter any information. Am I safe?

Possibly, but you should still report it. Clicking a link can trigger a "drive-by download" of malware or confirm to the attacker that your email address is active. Contact IT support immediately so they can scan your device and check whether any background activity occurred.

How can I check if a link is safe without clicking it?

Hover your cursor over the link to see the real URL in the bottom corner of your browser. On mobile, long-press the link to see a preview. You can also copy the link and paste it into a URL scanner like VirusTotal (virustotal.com) or URLVoid, which check the link against multiple security databases. Never paste a link directly into your browser if you have any doubt about its origin.

What should I do if I already entered my password on a phishing site?

Change your password immediately on the legitimate site, enable 2FA if you haven't already, and contact IT support. If you used the same password on other services, change those too. The faster you act, the more you limit the attacker's window of opportunity.

Will I get in trouble for clicking a phishing link?

No. Reporting a mistake quickly is exactly what IT needs to protect the organisation. You will not be penalised for reporting a phishing email or admitting you clicked a link. The only mistake that causes real damage is staying silent.

Stay vigilant, stay safe

Phishing attacks are relentless, but they rely on one thing: that you won't pause to look closely. Every red flag in this guide — mismatched sender addresses, generic greetings, manufactured urgency, suspicious links — is a crack in the attacker's disguise. Build the habit of pausing before you click, and when something feels off, trust that instinct and report it. If you receive a suspicious email, forward it to security@company-333985.dls.so and contact IT support at atif.1@company-333985.dls.so or +33162290341.