How to Spot a Phishing Email: A 60-Second Check Anyone Can Run
6 min readEmail & Payment Fraud
This one is written to be forwarded. If you run a company, send it to your team — that is more useful than anything you could ask them to sit through.
Stop looking for spelling mistakes
The advice most people carry around is roughly: watch out for bad grammar, strange greetings, and obvious urgency. That advice made sense when phishing emails were translated badly and sent in bulk.
It does not describe what arrives now. Modern phishing email is fluent. It uses your company's real vocabulary, your manager's real name, your actual vendor's real logo, and often lands inside a genuine conversation. A clean, well-written, entirely reasonable email is now the normal case, not the reassuring one.
Worse, the old advice creates a false sense of safety. People run the checklist, find no typos, conclude "it's fine", and click. The absence of red flags is not evidence of legitimacy.
What still works is not a list of warning signs. It is one question about what the message is asking you to do.
The 60-second check
Three questions, in this order. It takes less than a minute and it does not require any technical knowledge.
1. What does this email want from me?
Almost every phishing email wants one of four things:
- Your password (a link to a login page)
- A code from your phone (an MFA prompt, or "read me the number you just received")
- Money (payment, bank detail change, gift cards)
- A file opened or a program installed
If the answer is none of those — it is a newsletter, a notification, a colleague saying thanks — you can stop. The check only applies to emails that want an action with consequences.
If the answer is one of those four, continue. Every one of those four requests deserves verification regardless of how legitimate the email looks. That is the whole trick: you are not judging the email, you are reacting to the ask.
2. Did I go to this page, or did the page come to me?
This single distinction stops most credential theft.
If you clicked a link in a message and arrived at a login page, do not type your password. Not because the page looks wrong — it will look perfect, because it is usually a pixel copy or a live proxy of the real thing — but because of how you got there.
Instead, leave. Open a new tab and reach the service the way you normally do: your bookmark, your password manager, typing the address yourself, or the app on your phone. If the notification was real, the same message will be waiting for you inside your account. If nothing is waiting there, you have your answer.
This works even against attacks that defeat MFA, because you never enter anything into the attacker's page in the first place.
A useful side effect: a password manager will not autofill on a lookalike domain, because it matches the exact domain rather than the visual design. If your password manager unexpectedly does not offer to fill, treat that as a warning, not an inconvenience.
3. If this is asking for money or access, have I verified it out loud?
For anything involving payment details, bank accounts, payroll, or granting someone access — pick up the phone and confirm, using a number you already had, not one in the email. Call the person, not the message.
If the email appears to come from your boss and asks you to do something unusual, urgently, and quietly: that combination is the signature of the scam. Real executives do not mind being called back. See business email compromise for how these actually run.
Get the 31-point security checklist
The checklist, then one email a week on what changed and what a company your size should do about it.
Weekly. Unsubscribe in one click. See the checklist first.
The four pressures every phishing email uses
You will not always have time for the full check. If you learn to notice these four feelings, you will catch most of what matters — because these are levers on human psychology, and unlike typos they cannot be edited out. The attack needs them.
Time pressure. "Within 24 hours", "before end of day", "final notice". Urgency exists to stop you from checking. It is the most reliable single indicator, and it is deliberately manufactured.
Authority. A message from the CEO, the tax authority, the bank, the IT department. Authority makes verification feel rude. Notice when you are reluctant to double-check because of who it's from — that reluctance is the attack working.
Fear or consequence. Your account will be closed, your invoice is overdue, your package will be returned, there is a problem with your payslip.
Curiosity or reward. A shared document with no context, an unexpected bonus, a delivery you did not order, a colleague's file titled with your name.
One of these is present in essentially every phishing email, because without an emotional lever nobody acts. When you feel one, that is your cue to slow down — the feeling itself is the signal.
What to do when you are not sure
The correct answer is almost never "decide alone". Make these normal in your company:
- Forward it and ask. To whoever owns this at your company. Twenty seconds of someone's time is cheap.
- Do not reply to the email to check. If the account is compromised, you are asking the attacker whether the attacker is legitimate.
- Ask on a different channel. A message on Slack or a phone call to the sender: "did you just email me about X?" Different channel, same person.
- When in doubt, do nothing and say so. Nothing bad happens if you delay a real request by an hour. A great deal can happen if you action a fake one immediately.
If you already clicked
First: this is not a disaster, and it is definitely not something to hide. Speed matters far more than the mistake does, and every hour of silence costs more than the click did.
If you entered your password: change it immediately — on the real site, reached your own way — and change it anywhere else you reused it. Then tell whoever handles IT so they can sign out active sessions. A stolen password is still live in an existing session even after you change it; only revoking sessions closes that.
If you approved an MFA prompt or read out a code: say so straight away. This means someone is likely in the account right now. It needs sessions revoked and MFA re-enrolled, not just a password change.
If you opened an attachment or ran something: disconnect the device from the network — turn off Wi-Fi — and leave it powered on. Then tell someone. Powering it off can destroy evidence that helps determine what happened; disconnecting it stops the spread.
If you sent money: call the bank first, before anything else, and use the word "fraud". Minutes matter. Then follow the first four hours.
If you are not sure whether anything happened: report it anyway. The report costs nothing.
Make reporting the easy option
This part is for the founder, and it matters more than the training does.
The most expensive phishing incidents at small companies are rarely the ones where someone clicked. They are the ones where someone clicked, felt stupid, hoped it was nothing, and said nothing for four days. By then the mailbox rules are set, the invoices have gone out to your customers, and the window for the bank to recall the transfer has closed.
You cannot train people out of clicking — everyone clicks eventually, including the people who write articles like this one. You can make reporting fast and painless:
- One obvious place to report. A dedicated address, a Slack channel, one named person. If people have to work out who to tell, they will not tell anyone.
- Say the no-blame rule out loud, in advance. "If you click something, tell us immediately and nothing will happen to you. That is a promise." Then keep the promise, especially the first time — everyone will be watching how you react.
- Thank people publicly for reports, including the false alarms. The company that gets ten harmless reports a month is far safer than the one that gets none.
A team that reports in ten minutes will beat a team that has been trained for ten hours and stays quiet.