Overview
Phishing emails try to make you act before you think — sign in here, approve this payment, open this invoice. Modern ones are well written, correctly branded, and often reference real colleagues.
You don't need to be technical to catch them. You need a short checklist and permission to slow down.
The 60-second checklist
- Check the actual sender address, not the display name.
Microsoft Account Teamcan sit in front of any address at all. - Look for a lookalike domain —
micros0ft.com,cyber9O4.com,contoso-billing.net. One changed character is the whole trick. - Notice urgency and threats. “Within 24 hours”, “account will be closed”, “final notice”. Real organisations rarely work like this.
- Hover over links and read the destination in the bottom-left of the window before clicking. On a phone, press and hold to preview.
- Treat unexpected attachments as hostile, especially .html, .zip, .iso and anything asking you to enable macros.
- Question the request itself. Payment detail changes, gift cards, and urgent wire transfers are almost always fraud, however plausible the wording.
- Check for an external-sender banner on a message that claims to be from a colleague.
Legitimate vs phishing
| Signal | Usually legitimate | Likely phishing |
|---|---|---|
| Sender domain | Exactly your provider's real domain | Lookalike, misspelled or free webmail |
| Greeting | Uses your name and real context | “Dear User”, “Dear Customer” |
| Tone | Informative, no deadline pressure | Urgent, threatening, secretive |
| Links | Go to the provider's own domain | Redirects, shorteners, odd subdomains |
| Request | Nothing unusual | Credentials, payment change, gift cards |
| Attachment | Expected, from a known sender | Unexpected .html, .zip, .iso |
What to do with a suspicious message
Step 1 — Don't click, don't reply, don't unsubscribe
Any interaction confirms your address is live. Unsubscribe links in phishing emails are just another link.
Step 2 — Verify through a channel you already trust
Call the person on their known number — never a number in the email. For a bank or supplier, use the number on your statement or their official website typed in by hand.
Step 3 — Report it in Outlook
Use Report → Report phishing in Outlook. This removes it and teaches Microsoft's filters to catch the next one for everybody.
Step 4 — Tell your IT provider
One report often reveals a campaign hitting several staff members. Forward the details to CYBER904 rather than only deleting it.
Step 5 — If you already clicked or entered a password
Act immediately — the first hour matters most.
Change your password, sign out of all sessions, confirm your MFA methods haven't been altered, check for new mailbox forwarding rules, and contact CYBER904 straight away.
- Change the password from a different, known-clean device.
- Use Sign out everywhere in your Microsoft security info page.
- Review Settings → Mail → Rules for forwarding rules you didn't create.
- Check the Sent Items folder for messages you didn't send.
- Report it — do not keep it quiet.
Expected result
Suspicious messages get reported and removed, and nobody is blamed for reporting a false alarm — a wrongly reported email costs nothing, a missed one can cost everything.
Common questions
Still stuck?
If you'd rather not work through this yourself, CYBER904 can take it from here. Reach the team directly during business hours and we'll get it sorted.