Skip to article
Insights

5 Phishing Red Flags Every Employee Should Know

By Byron Allen · Cybersecurity Specialist

Phishing training gets a bad reputation because it's usually delivered as a boring annual video nobody remembers. It doesn't need to be complicated. Most phishing emails share one of a handful of tells — if your team knows these five, they'll catch the overwhelming majority of attempts without needing to become security experts.

1. The Sender Address Doesn't Quite Match

Attackers rely on people reading the display name, not the actual email address. "Microsoft Support" can be sent from anywhere.

Real example pattern: Display name reads "IT Helpdesk" but the actual address is something like [email protected] — a domain that looks plausible at a glance but isn't your organization's real domain, and isn't Microsoft's either.

The fix: Always check the actual sender address, not just the name — most email clients show it if you tap/hover the sender name.

2. Urgency and Fear Are Doing the Persuading

"Your account will be suspended in 24 hours." "Unusual sign-in detected — verify now." "Invoice overdue — pay immediately to avoid service interruption." Urgency exists to short-circuit the part of your brain that would otherwise stop and check. Legitimate organizations rarely demand instant action over email.

The fix: Treat urgency itself as a red flag. If it's real, it'll still be real in ten minutes after you've verified it through a separate channel.

3. The Link Text Doesn't Match Where It Actually Goes

A link that displays as yourbank.com/login can be coded to actually go anywhere. This is one of the oldest tricks and it still works because most people don't check.

Real example pattern: An email with a button reading "Reset Your Password" that, when hovered (on desktop) or long-pressed (on mobile), shows a completely unrelated domain in the preview — not your actual provider's domain.

The fix: On desktop, hover over links before clicking and check the URL preview at the bottom of the browser. On mobile, long-press to preview. When in doubt, navigate to the site directly instead of clicking the link.

4. A Request to Bypass Normal Process

"Don't tell anyone else about this yet." "Use your personal email for this one." "Can you buy gift cards and send me the codes?" "Wire this to a new account — I'll explain later." These requests specifically ask you to skip verification, secrecy, or normal approval steps — because that's exactly what a legitimate request would never need.

The fix: Any request that asks you to bypass a normal process — especially involving money, credentials, or secrecy — gets verified through a second channel (a phone call, an in-person check) before acting, no exceptions.

5. It's Addressed Generically, But Claims to Be Personal

"Dear Customer," "Dear Valued User," or no greeting at all — but the email claims urgent personal relevance ("your account," "your invoice," "your package"). Real organizations that have your actual account details usually address you by name.

The fix: A generic greeting combined with an urgent, personal-sounding claim is a strong combined signal — either one alone is weaker evidence, but together they're a solid reason to slow down.

Want to know where your team actually stands?

Phishing readiness is one of 10 fundamentals covered in the free security self-assessment.

Take the Free Assessment