How to Spot a Phishing Email: Red Flags Everyone Should Know
Spam filters, SPF, DKIM and DMARC all quietly stop enormous volumes of junk before it ever reaches an inbox — and yet phishing remains the single most common way attackers get into a business. The reason is simple: a well-crafted phishing email isn't trying to beat a filter, it's trying to convince a human being to click, reply, or pay. No amount of DNS configuration fixes that gap. The only real defense is people who know exactly what to look for.
The Red Flags That Give Phishing Away
Almost every phishing email — no matter how convincing — shares a handful of the same tells. Once you know to look for them, they become far harder to miss.
- The sender domain is almost right, but not quite. A single swapped letter, an extra word, or a different top-level domain than the real company uses.
- A generic greeting. "Dear Valued Customer" or "Dear User" instead of your actual name, even when the message claims to be from your own bank, courier or IT department.
- Manufactured urgency. A countdown, a threat of suspension, or a deadline measured in hours rather than days — designed to get you moving before you think to verify.
- A link that doesn't go where it says. The visible text might read "Verify My Account," but the actual destination — visible by hovering over the link, or checking the underlying URL — is something else entirely.
- An unusual request. Reply with your password, buy gift cards, change a bank account, open a compressed attachment you weren't expecting. Legitimate organizations essentially never ask for these things by email.
Five Scenarios That Show Up in Real Inboxes Constantly
The specific stories change, but the patterns are remarkably consistent:
- The fake password reset — a lookalike Microsoft or Google domain warning that your account will be suspended unless you "verify" immediately.
- Invoice and vendor fraud — an email that looks like a genuine supplier invoice, often with a note that "our bank details have changed," redirecting a real payment straight to an attacker's account.
- The package delivery scam — a courier notification claiming a delivery failed, with a small "customs fee" that quietly harvests your card details.
- CEO fraud / gift card scams — an urgent, secretive message that appears to come from an executive, asking someone in finance to buy gift cards or wire funds right away.
- Internal IT impersonation — a message that looks like it's from your own helpdesk, pushing a fake login page or a malicious attachment disguised as a policy update.
Practice Spotting Them Yourself
Reading a list of red flags is one thing — recognizing them in the moment, inside a real-looking email, is another. We built a free interactive tool, Phishing Email: Spot the Difference, that puts you inside five realistic fake emails modeled on the exact scenarios above. Click on anything you think is suspicious — the sender, a phrase, a link, an attachment — and it tells you immediately what you caught and what slipped past. It takes a few minutes and works well as a quick team exercise, not just a personal one.
Turning Awareness Into a Habit
A single quiz doesn't change behavior on its own — the businesses that actually reduce their phishing risk treat it as an ongoing habit, not a one-time email. That means regular phishing simulations, short refresher training, and a clear, low-friction way for staff to report a suspicious email the moment they see one, so it gets contained before anyone acts on it. Decoding IT's managed cybersecurity services build exactly this kind of ongoing security awareness program alongside the technical controls — because the best email filter in the world still can't stop someone from being convinced.
Decoding IT is a Muscat-based IT solutions provider helping businesses across Oman train their teams and lock down their systems against phishing and email fraud. Contact our team to talk through a security awareness program for your business.
- Log in to post comments