Think you know what a phishing email looks like? Attackers are counting on you to click before you look twice.
A suspicious sender address. An urgent payment request. A link that looks legitimate but leads somewhere unexpected. These are some of the most common signs of a phishing email, and they can be surprisingly easy to miss.
In Datto’s 2022 SMB Cybersecurity Survey, 72% of IT decision-makers at small and midsize businesses said they believed their organization was likely to experience a phishing attack within the following year. Phishing messages were also among the most common cybersecurity issues respondents reported experiencing.
In this guide, we’ll walk through how to spot a phishing email, common phishing email examples, what to do if you receive or fall for one, and how businesses can build stronger layers of protection.
What Is a Phishing Email?
Phishing is a social engineering attack in which criminals impersonate someone you trust—a coworker, vendor, bank, software provider, or other organization—to trick you into taking an action that benefits the attacker.
That might mean clicking a malicious link, entering your credentials, opening an attachment, sending sensitive information, or making a payment. Because attackers can copy familiar branding, spoof display names, and create lookalike domains, phishing emails aren’t always obvious.
How to Spot a Phishing Email: 5 Red Flags
When an email feels unusual, slow down before clicking. A few seconds of extra scrutiny can help you identify a phishing attempt before it becomes a security incident.
1. The Sender Isn’t Who They Appear to Be
Don’t rely on the name displayed at the top of an email. Open the full sender address and look closely at the domain.
A message may appear to come from a familiar company or even someone inside your organization, while the actual address tells a different story. Attackers may use misspelled company names, extra characters, unusual domain extensions, or lookalike domains designed to resemble legitimate ones.
It’s also worth checking the reply-to address. If it doesn’t match the sender or doesn’t make sense for the organization, that’s another reason to pause.
Note: When an email involves money, credentials, or sensitive information, don’t trust the display name alone. Verify the request through a known phone number, website, or other trusted communication channel.
2. The Message Creates a Sense of Urgency
Phishing emails often try to rush you into making a decision before you have time to think. Urgency alone doesn’t make an email fraudulent, but it should make you pause, especially when the message also asks you to click, pay, or provide information.
3. They’re Asking for Something Unusual
Ask yourself whether the request makes sense. Would your CEO normally ask you to purchase gift cards by email? Would a vendor suddenly change their banking information? Would your IT provider ask for your password?
Unexpected requests involving money, credentials, sensitive documents, or account access deserve extra scrutiny. When something feels out of character, verify it through a separate communication channel.
4. The Link Looks Suspicious
A link can look completely legitimate while sending you somewhere else. Before clicking, hover over the link to preview its destination. Look at the actual URL, not just the words displayed in the email.
Be especially cautious with shortened or unfamiliar links, misspelled domains, and links that send you to an unexpected login page.
When you’re unsure, skip the link entirely. Instead, navigate directly to the company’s official website or use a known bookmark to access your account.
5. There’s an Unexpected Attachment
Attachments can be used to deliver malware or other malicious content, particularly when the recipient wasn’t expecting a file.
An invoice, document, or other attachment may look routine, but opening it can create an opportunity for an attacker to compromise a device or network.
Pay particular attention to unexpected ZIP files, executable files, HTML files, ISO files, or macro-enabled Office documents. If you weren’t expecting the attachment, verify it with the sender through another communication method before opening it.
Phishing Email Examples: What Do They Actually Look Like?
Phishing emails don’t always announce themselves as scams. Many are designed to look like ordinary business communications, which is exactly why examples can be so useful when training employees.
Here are some subject lines you may have already seen, or something very similar:
- URGENT: Your account will be suspended
- Action Required: Verify your account
- Your payment could not be processed
- Invoice #48291 – Payment Due Today
- You’ve received a secure document
- Unusual sign-in detected
- Your password expires today
- Final Notice: Update your billing information
- Payroll Update Required
- CEO Request – Are you available?
- Wire Transfer Confirmation Needed
- You have a new voicemail
- Package Delivery Attempted – Action Required
Notice the pattern? Many of these messages rely on one of four things: urgency, fear, curiosity, or authority. The goal is to get you to act before you stop to question the request.
Example: Fake CEO or Executive Request
Subject: CEO Request – Are you available?
Hi, I’m in a meeting and need you to pick up four gift cards for a client. Please send me the codes as soon as they’re purchased.
Red flags:
- Unusual request from an executive
- Gift card purchase
- Pressure to act quickly
- Bypasses normal purchasing procedures
This type of attack is often associated with business email compromise (BEC), where attackers impersonate or compromise a trusted business account to facilitate fraud.
Phishing Isn’t Always an Email
Phishing tactics can show up beyond your inbox. Smishing uses text messages to lure victims into clicking links or sharing information, while phishing phone calls use similar tactics over the phone. Business email compromise (BEC) targets organizations with convincing impersonation or account-compromise attempts, often involving payments, gift cards, credentials, or sensitive information.
The common thread is trust. The attacker wants the message to feel legitimate enough that you take an action you normally wouldn’t take.
What to Do If You Receive a Phishing Email
Don’t click, reply, or open attachments. Instead, report the message through your organization’s reporting process or your email platform’s “Report Phishing” feature.
If the email involves money, credentials, or another unusual request, verify it through a separate, trusted communication channel. When possible, leave the original message intact so your IT or security team can investigate it.
And don’t be embarrassed to report it. The earlier a suspicious message is identified, the more opportunity your team has to stop it from becoming an incident.
What If You Already Clicked a Phishing Link?
It happens. The most important thing is to act quickly.
First, notify your IT or security team or service provider. Then change the password for the affected account and any other account using the same password. If MFA isn’t already enabled, turn it on.
Your IT or security provider may also need to investigate active sessions, reset tokens, review sign-in activity, or remove malicious forwarding rules from the compromised account.
If you entered financial information or believe a payment may have been compromised, contact your financial institution immediately.
The faster a phishing incident is identified, the more opportunities your team has to limit the damage.
How Businesses Can Reduce Phishing Risk
Employees are an important part of your cybersecurity strategy, but they shouldn’t have to be the only line of defense. A stronger approach combines employee awareness with technical safeguards, clear business processes, and ongoing monitoring.
Strengthen Email Security
Email security should be the first layer of defense, not the last. Advanced filtering, link protection, attachment scanning, and quarantine tools can help identify suspicious messages before they reach an employee’s inbox.
Require Multi-Factor Authentication
MFA provides another layer of protection if an employee’s credentials are compromised.
Even if an attacker obtains a username and password through a phishing attack, an additional authentication requirement can make it significantly more difficult for them to access the account.
Train Employees Regularly
Ciberseguridad training shouldn’t be a once-a-year exercise. Employees need regular opportunities to learn what phishing looks like, practice identifying suspicious messages, and understand exactly how to report something they aren’t sure about.
Create Clear Verification Procedures
Businesses should establish verification procedures for high-risk actions such as changing vendor payment information, initiating wire transfers, purchasing gift cards, sharing sensitive information, or granting access to systems.
Keep Backups and Recovery Plans in Place
Phishing can also be the starting point for a larger cybersecurity incident, including ransomware or account compromise. That’s why phishing protection should be part of a broader cybersecurity and business continuity strategy.
How ALLO Business Helps Protect Your Business From Phishing
Even well-trained employees can miss a convincing phishing email. That’s why effective cybersecurity can’t depend on awareness alone.
ALLO Business takes a layered approach to help businesses strengthen their security and reduce the risk of phishing-related incidents. We build multiple layers of protection around them. Your employees are one layer of your security, but they shouldn’t have to be the only ones.
If you’re not sure whether your current email and cybersecurity protections are keeping up with today’s threats, ALLO Business can help you identify potential gaps and build a practical security strategy that fits your organization.
Talk with an ALLO Business security specialist to learn more.
Frequently Asked Questions About Phishing Emails
How can you tell if an email is phishing?
Start by checking the sender’s full email address, looking for urgent or unusual requests, hovering over links to inspect their destination, and being cautious with unexpected attachments. Most importantly, consider whether the request makes sense in context.
Can phishing emails look legitimate?
Yes. Phishing emails can use familiar branding, realistic language, legitimate-looking logos, and information specific to a business or employee. That’s why checking the sender, links, context, and request—not just the appearance of the email—is important.
What is the difference between phishing and business email compromise?
Phishing is a broad category of attacks designed to trick someone into taking a harmful action. Business email compromise is a targeted type of attack that often involves impersonating or compromising a trusted business account to facilitate fraud, payment changes, or theft of sensitive information.
Can you get a virus just by opening a phishing email?
Usually not. Simply opening a message is rarely enough to compromise a device on its own. The risk comes from what happens next, like clicking a link, entering credentials, opening an attachment, or enabling content in a document. That said, if you opened a suspicious message and something looked unusual afterward, report it to your IT or security team rather than assuming it was harmless.
Can a phishing email come from a real coworker’s email address?
Yes. If an attacker has compromised someone’s account, the message comes from the genuine address and passes every sender check you would normally run. This is common in business email compromise, where the attacker reads existing threads and replies in context. It’s why unusual requests involving money, credentials, or sensitive information should be verified by phone or in person, even when the sender address is legitimate.
Resources: Datto SMB Cybersecurity for MSPs Report Datto SMB Cybersecurity for MSPs Report. (n.d.). Retrieved September 1, 2026, from https://www.datto.com/wp-content/uploads/dlm_uploads/eBook-SMB-Cybersecurity-Report-for-SMBs-Datto-FINAL.pdf