Skip to content

KB-0011 · Security

How to Spot a Phishing Email

A 60-second checklist your whole team can use, plus exactly what to do if someone already clicked.

Difficulty
Easy
Time needed
10 minutes
Applies to
Microsoft 365 · Outlook · All staff
Last updated

Overview

Phishing emails try to make you act before you think — sign in here, approve this payment, open this invoice. Modern ones are well written, correctly branded, and often reference real colleagues.

You don't need to be technical to catch them. You need a short checklist and permission to slow down.

Callouts: Three giveaways in one message: an external-sender banner, a lookalike domain, and manufactured urgency.1External sender banner2Lookalike sender domain3Suspicious action button

The 60-second checklist

  1. Check the actual sender address, not the display name. Microsoft Account Team can sit in front of any address at all.
  2. Look for a lookalike domain — micros0ft.com, cyber9O4.com, contoso-billing.net. One changed character is the whole trick.
  3. Notice urgency and threats. “Within 24 hours”, “account will be closed”, “final notice”. Real organisations rarely work like this.
  4. Hover over links and read the destination in the bottom-left of the window before clicking. On a phone, press and hold to preview.
  5. Treat unexpected attachments as hostile, especially .html, .zip, .iso and anything asking you to enable macros.
  6. Question the request itself. Payment detail changes, gift cards, and urgent wire transfers are almost always fraud, however plausible the wording.
  7. Check for an external-sender banner on a message that claims to be from a colleague.

Legitimate vs phishing

SignalUsually legitimateLikely phishing
Sender domainExactly your provider's real domainLookalike, misspelled or free webmail
GreetingUses your name and real context“Dear User”, “Dear Customer”
ToneInformative, no deadline pressureUrgent, threatening, secretive
LinksGo to the provider's own domainRedirects, shorteners, odd subdomains
RequestNothing unusualCredentials, payment change, gift cards
AttachmentExpected, from a known senderUnexpected .html, .zip, .iso

What to do with a suspicious message

Step 1 — Don't click, don't reply, don't unsubscribe

Any interaction confirms your address is live. Unsubscribe links in phishing emails are just another link.

Step 2 — Verify through a channel you already trust

Call the person on their known number — never a number in the email. For a bank or supplier, use the number on your statement or their official website typed in by hand.

Step 3 — Report it in Outlook

Use Report → Report phishing in Outlook. This removes it and teaches Microsoft's filters to catch the next one for everybody.

Step 4 — Tell your IT provider

One report often reveals a campaign hitting several staff members. Forward the details to CYBER904 rather than only deleting it.

Step 5 — If you already clicked or entered a password

Act immediately — the first hour matters most.

Change your password, sign out of all sessions, confirm your MFA methods haven't been altered, check for new mailbox forwarding rules, and contact CYBER904 straight away.

  1. Change the password from a different, known-clean device.
  2. Use Sign out everywhere in your Microsoft security info page.
  3. Review Settings → Mail → Rules for forwarding rules you didn't create.
  4. Check the Sent Items folder for messages you didn't send.
  5. Report it — do not keep it quiet.

Expected result

Suspicious messages get reported and removed, and nobody is blamed for reporting a false alarm — a wrongly reported email costs nothing, a missed one can cost everything.

Common questions

Still stuck?

If you'd rather not work through this yourself, CYBER904 can take it from here. Reach the team directly during business hours and we'll get it sorted.