5 Phishing Red Flags Every Employee Should Know
By Byron Allen · Cybersecurity Specialist
By Byron Allen · Cybersecurity Specialist
Phishing training gets a bad reputation because it's usually delivered as a boring annual video nobody remembers. It doesn't need to be complicated. Most phishing emails share one of a handful of tells — if your team knows these five, they'll catch the overwhelming majority of attempts without needing to become security experts.
Attackers rely on people reading the display name, not the actual email address. "Microsoft Support" can be sent from anywhere.
The fix: Always check the actual sender address, not just the name — most email clients show it if you tap/hover the sender name.
"Your account will be suspended in 24 hours." "Unusual sign-in detected — verify now." "Invoice overdue — pay immediately to avoid service interruption." Urgency exists to short-circuit the part of your brain that would otherwise stop and check. Legitimate organizations rarely demand instant action over email.
The fix: Treat urgency itself as a red flag. If it's real, it'll still be real in ten minutes after you've verified it through a separate channel.
A link that displays as yourbank.com/login can be coded to actually go anywhere. This is one of the oldest tricks and it still works because most people don't check.
The fix: On desktop, hover over links before clicking and check the URL preview at the bottom of the browser. On mobile, long-press to preview. When in doubt, navigate to the site directly instead of clicking the link.
"Don't tell anyone else about this yet." "Use your personal email for this one." "Can you buy gift cards and send me the codes?" "Wire this to a new account — I'll explain later." These requests specifically ask you to skip verification, secrecy, or normal approval steps — because that's exactly what a legitimate request would never need.
The fix: Any request that asks you to bypass a normal process — especially involving money, credentials, or secrecy — gets verified through a second channel (a phone call, an in-person check) before acting, no exceptions.
"Dear Customer," "Dear Valued User," or no greeting at all — but the email claims urgent personal relevance ("your account," "your invoice," "your package"). Real organizations that have your actual account details usually address you by name.
The fix: A generic greeting combined with an urgent, personal-sounding claim is a strong combined signal — either one alone is weaker evidence, but together they're a solid reason to slow down.
Phishing readiness is one of 10 fundamentals covered in the free security self-assessment.
Take the Free Assessment