Email academy

Recognising phishing: what it is and how to spot it

Phishing is a fake message that poses as a trustworthy sender (your bank, a supplier, a colleague) to extract your password, money or data. You usually recognise phishing from a handful of signs together: a sender that's just slightly off, a link that goes somewhere other than it promises, unexpected pressure to act fast, and a request you weren't expecting. Below you'll read what phishing exactly is, how to calmly learn to recognise it, and what to do if you're in doubt.

By the Mailflux team Published on

What is phishing?

Phishing (pronounced like "fishing") is a form of fraud via email, text message or chat. The sender "fishes" for something of yours: a login password, a payment, your bank details or access to your systems. The message poses as coming from a party you trust, so that you click or respond without thinking.

Most phishing is mass work: the same fake message goes to thousands of people at once, in the hope that some fall for it. There's also targeted phishing (sometimes called "spear phishing"), where an attacker tailors a message to you or your company, with your real name or that of a colleague in it. That's harder to recognise, because it looks personal.

Recognising phishing: the signs

Rarely does one thing give a fake email away; it's the sum that sets off the alarm bells. Run through these signs:

  • The sender is just slightly off. The display name may look genuine, but the email address behind it differs: an odd domain, extra characters, or a slightly misspelled company name. Click the sender name to see the full address.
  • The link goes somewhere else. Hover your mouse over a link (without clicking) and see where it really points. If that differs from the text, or is a strange web address, be on your guard.
  • There's a rush. "Your account will be blocked within 24 hours", "pay now or a fine follows". Pressure and threats are meant to make you act quickly and without thinking.
  • The request is unexpected. An invoice you didn't expect, a password reset you didn't request, a boss suddenly asking by email for an urgent payment. Unexpected is a reason to double-check.
  • The content feels "just off". An odd greeting ("Dear customer" without your name), stilted language, spelling mistakes, or a logo that's just slightly wrong.
  • Sensitive info is requested. A real bank or service never asks by email for your full password or PIN.

More worked-out examples of phishing emails help you recognise the pattern even faster.

How phishing works

A phishing attack usually goes in three steps. First the bait: a credible message that imitates a trusted sender. Then the hook: a link to a fake website that looks exactly like the real login screen, or an attachment containing malware. Finally the catch: if you enter your details on the fake site, they go straight to the attacker.

To come across as trustworthy, fraudsters often misuse the name of a real company. They can also forge the sender name, so an email appears to come from someone you know. That's called spoofing. How to prevent someone from emailing in your domain's name, you'll read in preventing spoofing.

What's striking in recent years is how polished phishing can look. Where a fake email used to be full of spelling mistakes, they now often look professional, with correct logos and smooth language. So don't blindly trust "it looks real". It's about the sum of the signs and your common sense: was I expecting this message, is the sender correct, and am I being pressured? Those questions protect you better than the appearance of an email.

What to watch out for

Beyond recognising it, your habits count. A few rules of thumb that save you a lot of trouble:

  • Don't click, go there yourself. Don't trust a message from your bank or a service? Then don't go via the link, but type the address yourself in your browser or use the official app.
  • Check via another channel. Does a colleague or supplier ask by email for an urgent payment or a changed account number? Give them a call. One phone call prevents most damage.
  • Don't open unexpected attachments. Certainly not zip files or documents you "have to enable". If in doubt, don't open them.
  • Never enter login details after a link in an email. Not your 2FA code either. A real service doesn't force you to do that via an email.
  • Fallen for it after all? Immediately change the password concerned (and everywhere you used that same password), turn on two-factor authentication and report it to your IT contact or the relevant authority. Acting fast limits the damage.

And at Mailflux

You don't have to stop phishing on your own. At Mailflux, ML-driven filtering against spam, phishing and malware is included by default in every plan: many fake messages are stopped before they reach your inbox. The system keeps learning, so it grows along with new tricks.

On top of that, every plan includes antivirus and anti-malware; with Pro and Premium you get premium anti-malware for an extra sturdy layer against malicious attachments. And because you email on your own domain, you can use technical arrangements (SPF, DKIM, DMARC) to help prevent fraudsters from misusing your name. More on that in email on your own domain. A filter catches a lot. Your alertness does the rest.

Ready to get started?

Professional email on your own domain, hosted in Europe and GDPR-compliant. Request your mailbox with no obligation.

Get started

FAQ

Frequently asked questions

What is the difference between phishing and spam?

Spam is unsolicited advertising or bulk mail: annoying, but usually not directly harmful. Phishing is targeted deception that wants to steal your data, money or access. A spam filter catches both, but phishing is more dangerous because it deliberately tries to mislead you into an action.

I clicked a phishing link. What now?

Don't panic, but act fast. If you haven't entered anything yet, there's usually little harm done, so close the page. If you did enter details, change that password immediately (and everywhere you reused it), turn on 2FA and warn your IT contact or the relevant service.

Can a spam filter stop all phishing?

No, no filter catches everything. A good, ML-driven filter stops the lion's share, but targeted or new phishing sometimes slips through. That's why your own alertness remains indispensable: check the sender and links, and be critical of unexpected or urgent requests.