Five phishing red flags your team should know

The New Solutions team at a daily standup meeting

Written by

in

News & Insights

Five phishing red flags your team should know

Security 12 August 2026 4 min read
Working at a laptop in the New Solutions office

Overview

Nearly every security incident our team is called into begins the same way: one person, in a hurry, opens an email that looks exactly like the ones they get every day. The technology behind these attacks has improved, and the spelling mistakes we used to rely on as a warning sign have largely disappeared.

Good filtering stops most of it. What matters is what happens to the small number of messages that get through. Below are the five checks we teach client teams to make, in the order they are quickest to apply.

1. The request creates urgency

Payment must be made today. The account will be closed within the hour. The manager is in a meeting and cannot take a call. Urgency is the one feature almost every phishing email shares, because it discourages the pause in which someone would normally check. Treat a deadline in an email as a reason to slow down, not speed up.

2. The reply address is not the display name

A display name is free text and can say anything. Expand the sender field and read the full address, then read it again from the right: the domain at the end is the part that cannot be faked. Lookalike domains that swap a letter or add a hyphen are common, and they are much easier to spot when you know to check the last part first.

3. The link text and the link destination disagree

Hover over a link before clicking and compare what it says with where it goes. On a phone, press and hold to preview the address. Attachments deserve the same treatment: a document that asks you to click through to a second site to view it is worth a phone call.

If an email asks you to change bank details, confirm it by phone on a number you already have. Not the number in the email.

4. It asks for credentials or a code

No supplier, bank or IT provider needs your password, and none of them will ask for the six-digit code from your authenticator app. If a login page appears after clicking an emailed link, close it and reach the service through a bookmark or by typing the address yourself.

5. Something about it is slightly off

A supplier who has never emailed an invoice suddenly does. A colleague writes in a tone they do not usually use. A thread appears to continue a conversation you do not remember having. Staff instincts are accurate more often than they are given credit for, and the cost of asking is a two-minute interruption.

Make reporting easy

The single most useful change most businesses can make is giving people one obvious place to send a suspicious email, and thanking them when they do. If reporting feels like admitting a mistake, people delete instead, and you lose the chance to check whether anyone else received the same message.

If you would like us to review your email security settings or run a short awareness session with your team, get in touch and we will talk through the options.

What our clients say

“We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”

Elaine Hogg, Reproflex3

Looking for an IT partner that just gets it?

No silly questions, just straight up answers.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *