Phishing emails pretend to come from someone you trust, such as your bank, a supplier or your own boss. They try to get you to click a link, open a file, share a password or send money. Most share the same warning signs.
Warning signs of a phishing email
| Sign | Example |
|---|---|
| Urgency or threats | Your account will be closed today unless you confirm your details. |
| Sender address does not match | Display name says “Microsoft” but the address is a random domain. |
| Look-alike domains | rnicrosoft.com instead of microsoft.com |
| Unexpected attachments or links | An invoice you were not expecting, or a link to a login page |
| Requests for passwords or codes | Reply with the code we just sent you. |
| Payment or bank detail changes | Our bank details have changed, please pay the new account. |
| Generic greeting | Dear customer, from a company you deal with by name |
How to check a suspicious email safely
- Hover over any link (or press and hold on a phone) to see where it really goes, without clicking.
- Check the full sender address as well as the display name.
- If the email asks you to log in, go to the website yourself by typing the address.
- If it asks for money or new bank details, call the sender on a number you already have.
Watch out for payment change scams
Emails asking to update a supplier’s bank details are a common and expensive scam. Always confirm changes by phone, using a number from your own records, before paying.
What to do if someone clicks
- Tell whoever handles IT or security straight away. Speed limits the damage.
- If a file was opened, disconnect the device from the network.
- Change the password for any account that may be affected, and turn on multi-factor authentication.
- Watch those accounts for unusual activity.
Multi-factor authentication stops many phishing attacks even when a password is stolen. See our guide to password managers and MFA.
How to report phishing in the UK
Forward suspicious emails to report@phishing.gov.uk, the NCSC’s Suspicious Email Reporting Service. Forward scam texts to 7726. The NCSC’s phishing guidance has more detail.
Build a no-blame culture
People report mistakes faster when they know they won’t be blamed. Thank staff for reporting suspicious emails, including false alarms. For the other basics every business should cover, read our small business cybersecurity guide.