← Back to Blog
Cybersecurity

How to Spot a Phishing Email: A Guide for Small Business Staff

29 July 2026 · By Ethan Fernandes

How to Spot a Phishing Email: A Guide for Small Business Staff

Phishing is still the most common way small businesses get breached. Not zero-day exploits, not sophisticated hacking — just a convincing email that tricks someone into clicking a link or entering their password. It works because the emails are getting better, and most staff have never been shown what to look for.

91% of cyber attacks start with a phishing email. Your team is the last line of defence — and usually the first one targeted.

What Phishing Actually Looks Like in 2026

Forget the Nigerian prince emails. Modern phishing looks like a password reset from Microsoft, an invoice from a supplier you actually use, or a voicemail notification from Teams. The sender name looks right, the branding looks right, and the urgency feels real.

Here are the red flags your team should check every time:

1. Check the Sender Address, Not the Display Name

The display name might say "Microsoft 365" or "IT Support", but the actual email address tells the truth. Hover over (or tap on mobile) the sender name to reveal the real address. If it's support@m1crosoft-security.com instead of @microsoft.com, it's fake.

Attackers also use lookalike domains — swapping letters, adding hyphens, or using subdomains like microsoft.com.secure-login.net. The real domain is always the last part before the first slash.

2. Hover Over Links Before Clicking

Every phishing email wants you to click something. Before you do, hover over the link (without clicking) and look at the URL in the bottom-left corner of your browser or email client. Does it go where you'd expect? If a "Microsoft" email links to login-verify.sketchy-domain.com, don't click it.

On mobile, long-press the link to preview the URL. If you can't see where it goes, don't tap it.

3. Watch for Urgency and Threats

Phishing emails almost always create urgency: "Your account will be suspended in 24 hours", "Immediate action required", "Your payment failed". Real companies rarely threaten you via email. If it feels urgent and scary, slow down — that's the point.

4. Unexpected Attachments

If you weren't expecting a file, don't open it. This is especially true for .zip, .exe, .docm (macro-enabled Word), and .html attachments. Even PDFs can contain malicious links. When in doubt, contact the sender through a different channel to confirm they sent it.

5. Requests for Credentials or Payment Changes

No legitimate service will ask you to enter your password via email. And if a "supplier" emails asking you to update their bank details, pick up the phone and call them on a number you already have — not one from the email. This type of attack (business email compromise) costs UK businesses millions every year.

The CEO fraud variant: An email that appears to come from your boss asking you to urgently transfer money or buy gift cards. It's always fake. Always verify by phone or in person.

6. Poor Grammar and Formatting — But Not Always

Older phishing guides told you to look for spelling mistakes. That still applies to some attacks, but AI-generated phishing emails are now grammatically perfect. Don't rely on bad grammar as your only signal — use it alongside the other checks above.

What to Do If You Spot One

Don't just delete it — report it. In Outlook, use the "Report Message" button to flag it as phishing. This helps Microsoft block similar emails for everyone. If you've already clicked a link or entered credentials, tell your IT support immediately — the faster we know, the faster we can contain it.

Key takeaway: Phishing works because it targets people, not systems. A 30-second pause to check the sender, hover over the link, and question the urgency stops the vast majority of attacks. Share this with your team.

Want to test how your team handles phishing? We run simulated phishing campaigns that show you exactly where the gaps are — without the risk of a real attack.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.