A phishing email is a fake message designed to look like it comes from a trusted source. They are the most common entry point for cyberattacks and they almost always leave clues that give them away.
Phishing emails are the most common way cybercriminals get into business systems. They do not need to hack through firewalls or crack passwords if they can simply trick one of your staff into clicking a link or handing over their login details. And they are getting better at it every year.
The good news is that phishing emails almost always leave clues. Once you know what to look for, they become much easier to spot.
What Is a Phishing Email?
A phishing email is a fake email designed to look like it comes from someone you trust. It could pretend to be your bank, Microsoft, a courier company, a government department or even a colleague. The goal is to get you to click a link, open an attachment or enter your details on a fake website.
Some phishing emails are obvious. Others are extremely convincing and have caught out people who consider themselves tech savvy. This is why knowing what to look for matters for everyone in your business, not just your IT team.
How to Spot a Phishing Email
Check the sender's email address carefully
The name displayed in your inbox can say anything. What matters is the actual email address behind it. Click or hover over the sender name to see the full address. A legitimate email from Microsoft will come from a microsoft.com address. If it comes from something like microsoft-support@outlook-helpdesk.net or any variation that looks slightly off, it is not real.
Cybercriminals often use addresses that look almost right at a glance. Things like micros0ft.com with a zero instead of an o, or recloud.support.co instead of recloud.co.za. Always look carefully.
Look at how the email addresses you
Legitimate companies that have your details will usually address you by name. Phishing emails often use generic greetings like "Dear Customer", "Dear User" or "Dear Account Holder." This is because the same email is being sent to thousands of people at once.
Watch out for urgency and pressure
Phishing emails almost always try to create panic. Your account will be suspended. Your payment has failed. Unusual activity has been detected. You must act now. This pressure is designed to make you react quickly without thinking.
Any email that demands urgent action, especially around money or account access, should be treated with suspicion. Legitimate companies give you time to verify and respond.
Do not trust links at face value
Before clicking any link in an email, hover your mouse over it to see where it actually goes. The text of the link might say www.yourbank.co.za but the actual destination shown at the bottom of your screen could be something completely different.
If you are on a mobile device, press and hold the link to preview the URL before opening it. If the destination address looks strange or does not match the company the email claims to be from, do not click it.
Be careful with attachments
Legitimate businesses rarely send unexpected attachments. If you receive an email with an attachment you were not expecting, even from someone you know, be cautious. Malware is often hidden inside documents, PDFs and zip files. If in doubt, contact the sender through a separate channel to confirm they actually sent it before opening anything.
Check for spelling and grammar mistakes
Many phishing emails contain spelling errors, awkward phrasing or sentences that do not quite read right. This is not always the case with more sophisticated attacks but it is still a useful indicator. A legitimate email from a professional company will generally be well written.
How to Check If an Email Is Real
If you receive an email and are not sure whether it is genuine, here is what to do:
- Do not click any links or open any attachments in the email
- Go directly to the company's website by typing the address into your browser yourself
- Log into your account there to see if there are any real notifications or issues
- If the email claims to be from a colleague, call or message them separately to confirm
- When in doubt, report the email to your IT team or provider before doing anything else
What to Do If Someone in Your Business Clicks a Phishing Link
Act quickly. The faster you respond the better the outcome.
- Disconnect the affected device from the internet and your office network immediately
- Contact your IT provider straight away and let them know what happened
- Change the passwords on any accounts that may have been compromised
- Check whether any sensitive data or financial information may have been accessed
- Report the incident if it involves client data, as you may have legal obligations to do so under POPIA
How Recloud Can Help
At Recloud we provide advanced email protection that filters out phishing attempts before they reach your staff. We also set up multi-factor authentication so that even if login details are compromised, your accounts stay protected.
We work with businesses across Cape Town to reduce the risk of email-based attacks and to make sure that when something does slip through, your team knows exactly what to do. If you want to sharpen your eye for the most common trick, our guide on how to spot a fake login page is worth a read.
Get in touch to find out how we can help protect your business from phishing and other email threats.