Business Tech & Tools
How do I recognize a phishing email before I click anything?
The short answer
Treat an unexpected request to log in, pay, open a file, change banking details, buy gift cards, or share a code as unverified, even when the name and logo look familiar. Do not use the link, attachment, phone number, or reply address in the message. Open the real account from your own bookmark or contact the person through a channel you already trust.
Phishing is not always badly spelled. The most convincing message may copy a real invoice, conversation, signature, or coworker's writing style.
Look for a dangerous combination
One odd detail does not prove fraud. Several together should make you stop:
- the request was unexpected.
- the message creates urgency, fear, secrecy, or an unusual reward.
- money, credentials, files, or account changes are involved.
- the visible sender name does not match the full address.
- the reply address differs from the sender.
- the link text and real destination are different.
- an ordinary process has suddenly changed.
- the sender asks you to bypass another person or normal approval.
- the attachment is unusual for the conversation.
The FTC lists common stories such as fake suspicious-login warnings, billing problems, unfamiliar invoices, payment links, and requests to confirm personal or financial information. See its guide to recognizing and avoiding phishing.
Inspect without opening
On a computer, hover over a link and read the destination shown by the browser or email program. On a phone, a long press may reveal the address, but do not continue to the site. Look at the part immediately before the first single slash. billing.example.com belongs to example.com. example.com.billing-help.net belongs to billing-help.net.
Expand the full sender address. Watch for a swapped letter, added word, unfamiliar domain ending, or personal email account pretending to represent a company.
An attachment can be risky even when it says “invoice” or “secure document.” A button inside a PDF or shared document can lead to a fake login page. If the file is truly expected, confirm it in the original project thread or by another known method.
Verify the request outside the message
If “your bank” says there is a problem, use the bank app or number on your card. If a client changes payment instructions, call the established contact at the number already in your records. If a contractor asks for a sensitive file, start a fresh message to the known address.
CISA advises reporting suspicious messages and verifying requests instead of responding through the possible phish. Its phishing guidance explains the basic pattern.
Use a tiny payment-change rule: no bank, routing, payroll, refund, or vendor-payment change becomes active from one email alone. Require confirmation through a previously agreed second channel. That one habit protects against polished business-email scams that contain no obvious spelling mistake.
Do not let urgency borrow your authority
A scammer wants you to act before you think. Give yourself a sentence that ends the pressure: “I verify all payment and account changes through our normal process.” A legitimate client or provider can wait while you confirm.
Be especially careful with:
- login alerts that include a button.
- new direct-deposit or wire instructions.
- fake document-share notices.
- QR codes that hide the destination.
- requests for multifactor or password-reset codes.
- “reply privately” requests from a familiar name.
- invoices that change only the payment account.
- voicemail-transcript attachments you did not expect.
Make reporting easy
Use the email service's phishing-report button so its security system can learn from the message. If it impersonates a client, alert the real client through a clean thread without forwarding a dangerous attachment. Keep enough evidence for your IT or security helper, then delete the message according to your response process.
If you already clicked, opened an attachment, entered a password, approved a prompt, or sent money, stop treating this as a recognition exercise. Begin the incident steps immediately from a trusted device.
Sources and further reading
- Federal Trade Commission: How to Recognize and Avoid Phishing Scams
- CISA: Recognize and Report Phishing
A free next step
Not sure which business fits you yet?
The free Freedom Path Assessment can help you compare your strengths, schedule, income goals, and preferred way of working before you commit to a business direction.
Related Questions
- Do I need a password manager, and how should I create and manage strong business passwords?
- What is two-factor authentication, and is text-message verification good enough?
- What should I do immediately after clicking a phishing link or entering my password on a suspicious site?
- What should I do if a business account or business email is hacked?
