Outbound Wiki

Article

How to Spot a Phishing Email – with Real Examples and Red Flags

grcsolutions.io

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Sender clues Is it from a public domain (e.g. @gmail.com) but pretending to be from a company? Is the domain slightly misspelled (e.g. amaz0n.com)?

    In Email risk classification

  2. Is it from a public domain (e.g. @gmail.com) but pretending to be from a company? Is the domain slightly misspelled (e.g. amaz0n.com)? Does it differ from how that organisation normally emails you?

    In Email risk classification

  3. Quick phishing checklist: is this email a scam? Answering ‘yes’ to any of the questions below is a sign the email may be fraudulent. Sender clues

    In Email risk classification

  4. Is the domain slightly misspelled (e.g. amaz0n.com)? Does it differ from how that organisation normally emails you? Content and tone

    In Email risk classification

  5. Are there spelling or grammatical errors? Does it urge immediate action (e.g. “Act now”, “Your account will be closed”)? Is the tone inconsistent with the sender’s usual communication style?

    In Email risk classification

  6. Links and attachments Does the link URL differ from the anchor text? Is there an unexpected attachment?

    In Email risk classification

  7. Does the link URL differ from the anchor text? Is there an unexpected attachment? Are the call-to-action buttons vague (e.g. “Click here”, “Log in now”)?

    In Email risk classification

  8. Phishing is also the most prevalent form of attack: the UK government’s Cyber Security Breaches Survey 2025 found that phishing accounted for 93% of all cyber crime in the UK. Phishing attacks are designed to manipulate people into giving up sensitive information, clicking malicious links or downloading dangerous attachments. But while phishing tactics are evolving, so are the ways we can identify and mitigate them. This guide walks you through the most common red flags, updated for 2025 with real examples to help you stay vigilant.

    In Email risk classification