Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
Satellite picture of the Earth as seen from space

10 January 2025

3 minutes read time

Phishing 101: 7 ways to spot a phishing email 

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Phishing attacks are on the rise. In 2024, the number of phishing scams increased by 34%. This figure represents millions of malicious emails zipping across the web daily. It’s not all doom and gloom, though. Armed with enough information, it is possible to spot a phishing email before any damage is done. 

Here’s how to spot a phishing email.

1. Errors in spelling and grammar 

Errors in spelling and grammar are telltale signs that something is wrong. Glaring spelling errors are easy to spot, but some are more subtle. For example:

  • “Bank of Amerca” instead of Bank of America 
  • “Sincerly” instead of sincerely 
  • “Permenent” instead of permanent 
  • “Acount” instead of account 

Professional companies are unlikely to make mistakes such as these. If you notice any errors or the email doesn’t read as expected, hold off doing anything while you investigate further.  

2. Domain name mismatch 

A suspicious email address is an obvious sign that the sender is not who they claim to be.

Scammers use email addresses that mimic the company they’re impersonating, but if you look closely, all is not as it seems. Take PayPal, for example. Let’s assume their official email address is support@paypal.com. A scammer might use iterations of this, such as: 

support@paypai.com 
notifications@pay-pal.com 
info@paypal.support.com  

What’s important here is what comes after the @ in the email address. If the domain looks suspicious, do not proceed. 

3. A sense of urgency 

It’s in the scammer’s interest to create a sense of urgency, leaving you little time to notice the glaring errors in their email. To achieve this, they often present a pressing problem that requires immediate action to avoid a worse outcome.

One typical example is claiming that payment information is missing, with the threat that your account will be closed if you don’t act right away. Avoid the temptation to jump straight into resolving the problem. Slow down and take the time to re-read the email.

4. Too good to be true offers 

If an offer seems too good to be true, that’s usually because it is. Limited-time offers and ‘while stocks last’ bargains are a ploy to get you to act quickly before you notice something is amiss with the email. Before taking up the offer, check with the company that it’s genuine by contacting them another way (don’t click the link in the email!). 

5. Suspicious links and attachments

Most phishing scams aim to get recipients to follow a link to a website asking them to provide personal information. Phishing emails are designed to push this agenda – hard.

Before you click the link, hover over it with your mouse. If the URL doesn’t match the sender, then something is amiss. The link text may say: ‘Click here to verify your account,’ but the URL could be fraudulent (e.g. http://secure-login.paypal-verification.com). 

Always verify that the domain matches the intended site before you proceed.

Read More: What to do if you click on a phishing link. 

6. Are you expecting the email? 

If you receive an email or text from someone you’ve had no previous contact with, take a moment to consider why before doing anything else. It could be a sales email, but it might also be a scam. Some email providers mark messages as ‘external’ or ‘outside of your organisation’ as part of their security process. Before responding, make sure to verify the sender independently.

7. Requests for personal information 

Legitimate organisations don’t make a habit of asking for personal information via email or text. Never reveal anything that could compromise your security, such as passwords or banking details. If you’re asked for sensitive information via an email, it’s likely to be a scam – even if it appears to come from a genuine organisation. 

Above all, if you doubt the legitimacy of an email, then err on the side of caution and check before you do anything else. 

If you found this helpful, you might also like Phishing vs blagging: What’s the difference? 

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more