Everyday IT fixes

How to spot a phishing email

The signals worth checking every time, including the invoice fraud that targets small businesses hardest.

Last reviewed 20 August 2026

Modern phishing is well written and well branded. Spelling mistakes are no longer the giveaway — pressure and payment details are.

  • Urgency: 'act within 24 hours', 'account will be suspended', 'the director needs this before the end of the day'.
  • A sender name you know but an address you don't — hover over it and read the full domain, including the bit after the @.
  • Lookalike domains: arkasslst.co.uk, micros0ft-support.com, an extra hyphen, a swapped letter.
  • Any link asking you to sign in to Microsoft 365 to 'view a document' or 'release a held message'.
  • A supplier emailing new bank details, or a change to an invoice you were expecting.
  • An unexpected MFA prompt you didn't trigger — that means someone already has your password.

What to do

  1. 1Don't click, don't reply, don't open attachments.
  2. 2For anything involving money or bank details, phone the supplier on a number you already had — never a number from the email.
  3. 3Forward the message to us as an attachment if you can, or raise a ticket and tell us the subject line and sender.
  4. 4Delete it once we've confirmed.
Nobody is ever in trouble for reporting a suspicious email — or for admitting they clicked one. Speed matters far more than embarrassment.

Common questions

I reported a phishing email — will you tell me what it was?
Yes. We check the message and headers and reply on the ticket confirming whether it was malicious and whether anyone else received it.

Still stuck?

Log it with the helpdesk and a real engineer will pick it up — or book a call if you'd rather talk it through.