Recognising and preventing phishing
What is phishing?
Phishing is a fake message that poses as a trustworthy sender, with the aim of extracting your data, passwords or money. The sender pretends to be your bank, your supplier, a delivery service or even a colleague, and tries to get you to do something you normally wouldn't.
The word comes from "fishing": a bait is cast out, and the attacker hopes you'll bite. Sometimes it's mass, sloppy mail; sometimes carefully faked messages aimed at one person or company. You'll find a broader explanation of the concept on the page about what phishing is.
You come across different flavours. With ordinary phishing, the same fake email goes to thousands of addresses at once, in the hope that a handful of people fall for it. With spear phishing the mail is tailored to you or your company, with real names and details, which makes it look far more credible. And with CEO fraud the sender poses as the boss or a known supplier, with an urgent request to make a payment. The more targeted the attack, the harder it is to recognise, and so the more important a fixed checking routine.

Why recognising phishing matters
One wrong click can have major consequences: a drained bank account, a hijacked mailbox, or ransomware that holds your entire administration hostage. For an SME or practice that's not only money, but also trust: if your mailbox is abused, your customers suddenly receive fake messages in your name.
Phishing is moreover the gateway to other problems. Via a captured password, attackers can read along, forge invoices or use your domain to defraud others. That's why recognising fake mail isn't a luxury, but daily hygiene, just like locking your door.
How to recognise a phishing email
With a suspicious message, run through these signs. Often several jump out at once.
- The sender address is just slightly off. The displayed name looks genuine, but the address behind it is a strange or slightly misspelled domain. Always open up the full address.
- Pressure is applied. "Your account will be blocked within 24 hours" or "pay now to avoid a fine." Urgency is meant to make you act without thinking.
- The link leads somewhere else. Move your mouse over the link (without clicking) and see where it really points. If that differs from the text, be on your guard.
- Impersonal or slightly strange greeting. "Dear customer" where you expect your name, or oddly worded phrases and spelling mistakes.
- An unexpected attachment. Files you have to "enable" or run are especially suspicious.
- A request for data. Real organisations rarely ask you by email for passwords, PINs or full card details.
- The offer is too good. An unexpected refund, prize or inheritance is almost always bait.
In doubt? Don't go via the mail, but log in directly via the address you type yourself, or call the organisation on a number you look up yourself.
What to watch out for
- Look beyond the displayed name. Attackers easily forge the visible sender. What's sent on behalf of your own domain belongs to the story about preventing spoofing.
- Don't trust any message purely on the basis of the logo. Logos and house style are copied so easily.
- Be extra alert to invoice and payment requests. If a supplier "suddenly" changes their account number, call to check.
- Don't share login details via a link from an email. Always go to the site yourself.
- Did you click after all? Change your password immediately, turn on two-factor authentication, and warn your provider or IT manager. The faster, the smaller the damage.
- Make it a habit, not a panic. You don't have to be suspicious of every email; a few fixed reflexes (opening up the sender, checking links, calling when money is involved) catch most of it without it feeling like work.
A handy rule of thumb: don't be guided by how genuine a message looks, but by what it asks. If a mail asks you to log in, pay or download something, always go one step slower and check via a channel you choose yourself. That very intermediate step takes away the pressure that phishing relies on.
A good spam filter catches a lot of phishing before it reaches you. If legitimate mail disappears into spam instead, that's a different problem; you'll read about it in why mail ends up in spam.
And with Mailflux
With Mailflux every plan filters with machine learning against spam, phishing and malware, and includes antivirus, antispam and antimalware as standard. That way a good deal of fake mail is already held back before it appears in your inbox. In the plans with premium protection, that anti-malware goes a step further.
You get professional email on your own domain, hosted in Europe and GDPR-compliant, with automatic backups and optional two-factor authentication. Filtering catches a lot, but your alertness remains the last, best defence, and those two reinforce each other.
FAQ
Frequently asked questions
What's the quickest sign that a mail is phishing?
Check the full sender address, not just the displayed name. If the domain isn't right, or is slightly misspelled, that's a strong sign. Combine that with urgency and a suspicious link, and the chance of phishing is high.
What should I do if I clicked a phishing link?
Stay calm and act fast. Change the password of the account involved immediately, turn on two-factor authentication, and report it to your provider or IT manager. If you ran an attachment, have your device checked for malware and keep an eye on your accounts.
Can a spam filter fully stop phishing?
A good filter stops a lot of phishing, but no filter is a hundred percent. Attackers constantly adapt their tricks. That's why the combination of strong filtering and alert users stays safest: technology catches the masses, you catch the exception.