Tel: 03333 200 222
Email: info@swiftcomm.co.uk

How Can You Spot a Phishing Email?

02/04/2026
5 minute read
Could you identify a phishing email before it causes damage? From spoofed email addresses to convincing payment requests, it’s important to know what to look out for. In this guide, discover the key warning signs and what to do in the event of an attack.
By, Becky Mack
Share

From fake banking alerts to convincing messages from trusted sources, phishing emails are becoming more sophisticated, making it more difficult than ever before to determine what’s real and what’s a scam. So, how can you spot a phishing email and avoid it causing damage? Find out more about phishing emails below.

What is a Phishing Email?

Phishing emails are fraudulent messages that are designed to trick you into taking an unsafe action, such as opening an attachment that contains an infection, sharing sensitive information such as passwords or bank details, or clicking on a malicious link.

In the UK, we often see well known entities such as HMRC, parcel delivery firms and network providers being ‘spoofed’ as part of a phishing campaign, making it seem as though you are receiving a legitimate communication. Attackers can even attempt to mimic a CEO or Director’s email address to encourage you to interact.

The Most Common Types of Phishing Emails

  • Fake invoices asking you to send funds to an attacker’s account
  • Missed delivery scams encouraging you to open attachments or click links with malicious content
  • HMRC and tax refund emails requiring you to enter sensitive information
  • Director level impersonation, attempting to pressure staff to send payments or share credentials

How Are Phishing Emails Evolving?

Phishing attacks aren't standing still. While the classic signs — poor grammar, suspicious links — are still relevant, cybercriminals are increasingly using AI tools to craft more convincing messages. This means phishing emails are getting harder to spot, as they can now closely mimic the writing style and tone of the organisations they're impersonating, with far fewer of the telltale errors many people have been trained to look out for.

Attacks are also becoming more targeted. Spear phishing involves researching a specific individual — often using information found on LinkedIn or company websites — and crafting a personalised message that feels credible. A typical example might be an email appearing to come from your operations director, referencing a real project or supplier by name and requesting an urgent payment or document.

Businesses should be aware that the methods used by attackers are constantly changing, which is why awareness training needs to be an ongoing process rather than a one-time exercise.

7 Signs of a Phishing Email

So, how can you spot a phishing email in your inbox?

  1. Suspicious sender address: On first glance, the email address may look legitimate, but are there subtle spelling differences? Is the display name correct, but the email address behind it unrelated?
  2. Urgent language: Encouraging you to act quickly to avoid immediate account suspensions, for example. Legitimate businesses rarely demand immediate action.
  3. Unexpected attachments: Often disguised as an invoice or delivery notification, the file type may be a giveaway. These files may contain malware which infects your computer if opened.
  4. Poor spelling or unusual tone: Grammatical errors or odd phrasing are often seen in phishing emails.
  5. Strange links: Hover over links before clicking, to understand exactly where you’re being directed.
  6. Requests for sensitive information: Being asked for passwords, bank details or other confidential information over email should be seen as a red flag in most circumstances.
  7. Generic greetings: The use of ‘Dear Customer’ or ‘Dear User’ by peers or companies you have a relationship could be a sign of a phishing email.

What To Do If You Receive a Phishing Email

  • Don’t click anything or open any attachments
  • Report the email to your IT department or IT provider
  • Delete or quarantine the email
  • Warn colleagues to ensure awareness

What If Someone Clicks a Link or Opens an Attachment?

Speed Matters

Acting quickly can reduce the impact of an attack – for example, reporting immediately to your IT team when you input login details to a fake website could enable them to reset the account before it’s accessed and fully compromised.  

Immediate actions to take

  • Disconnect from Wi-Fi or your work network to prevent any malware from spreading
  • Report the incident to your IT team quickly, following your organisation’s incident reporting process
  • Change any passwords that may have been exposed
  • If possible, run a security scan on your device

Risks of clicking malicious links or opening attachments

  • Financial loss through fraudulent transactions
  • Compromised accounts, enabling attackers to access email and other systems
  • Data theft - both personal and company data
  • Malware infection - Viruses, ransomware or spyware could be installed

How Can Businesses Prevent Phishing Attacks?

Staff Awareness Training

Your employees are the first — and often most important — line of defence. Regular, practical training helps staff recognise the signs of a phishing attempt and know how to respond. This works best when it goes beyond a one-time presentation and includes simulated phishing exercises, which allow you to test awareness in a safe environment and identify where additional training may be needed. Training should be refreshed regularly as attack methods evolve.

Clear Reporting Processes

Staff need to know exactly what to do — and feel comfortable doing it — when they spot or fall for a phishing attempt. A clear, blame-free reporting process encourages early escalation, which can be the difference between a contained incident and a serious breach.

Email Filtering and Authentication

A good email security setup reduces the volume of phishing messages that ever reach your team's inbox. This includes spam filtering, anti-malware scanning of attachments, and email authentication protocols such as SPF, DKIM and DMARC, which help prevent attackers from successfully spoofing your domain or those of trusted senders.

Multi-Factor Authentication (MFA)

Even if an attacker obtains a password through a phishing attack, MFA provides a critical second barrier. With MFA in place, access to accounts requires an additional verification step — such as a code sent to a mobile device — which the attacker won't have. This significantly limits the damage that a compromised password can cause. Read more about how MFA works and why it matters.

Endpoint Protection

Having up-to-date endpoint security software across all devices means that even if a malicious link is clicked or an attachment opened, there's a greater chance of the threat being detected and contained before it spreads.

Regular Security Reviews

Periodic reviews of your email settings, access controls and overall security posture help ensure your defences remain effective as your business and the threat landscape both change.

Phishing and Business Email Compromise: Understanding the Financial Risk

For UK businesses, the financial impact of falling for a phishing attack can be significant. One of the most costly forms is Business Email Compromise (BEC), where an attacker either gains access to a real email account or convincingly impersonates a director or supplier to authorise fraudulent payments. These attacks frequently target finance teams and can result in large sums being transferred before anyone realises something is wrong.

Beyond direct financial loss, a successful phishing attack can also result in data breaches that carry regulatory implications under UK GDPR, reputational damage with clients, and the operational disruption of recovering compromised accounts and systems. For smaller businesses in particular, the recovery process can be costly and time-consuming.

A Quick Checklist – How Can You Spot a Phishing Email?

  • Do you recognise the sender?
  • Are you expecting the email?
  • Is the request unusual?
  • Do any links look genuine?

Whilst phishing emails are evolving and becoming more convincing, having the right awareness, tools and processes in place can avoid them becoming an issue for your business.

Think your team would spot a phishing email? Find out with a free cyber security review — our team will assess your current defences and highlight any gaps. Book your free review.

More from Swiftcomm

Managed IT Support vs In-House IT: What’s Right for a Growing UK Business?
When your business is growing, the question of whether to hire in-house IT staff or outsource to a managed IT provider is one of the most important decisions you'll face. Both options have genuine merit — and for some businesses, a hybrid of the two makes the most sense. In this guide, we break down all three models honestly, covering the trade-offs, cost considerations, and the five questions to ask before you decide.
Full Article
right-chevron
What is Cyber Essentials and Does My Business Need It?
Cyber Essentials is one of the most practical and achievable steps a UK business can take to improve its security posture. Find out more about the two certification levels, what changed in the 2026 update, and how to determine if you business needs it in this guide.
Full Article
right-chevron
grey-tick-icon
Trusted by 100s of businesses already
grey-tick-icon
Uniquely tailored approach
grey-tick-icon
Outstanding customer service
swift-tag

Talk with us

We pride ourselves on being an honest trustworthy business communications provider
phone-icon
Telephone
Call 03333 200 222 or if you would prefer us to call you.
Schedule a call
email-icon
Email
We love emails, to send us one use info@swiftcomm.co.uk or fill in our
Contact Form
chat-icon
Live Chat
Got a question? Our live chat is open and ready to assist
Chat Now
Contact a specialist
crosschevron-down