Phishing emails are no longer full of typos. Thanks to AI tools, they are now often linguistically flawless, personalised and visually almost indistinguishable from the original. Technology helps a lot – but in the end it is often a person who decides whether to click. Your whole team should know these seven warning signs.
1. Time pressure
“Your account will be blocked in 24 hours.” “The payment must go out today.” Pressure is meant to stop you from thinking calmly.
2. Unexpected payment requests
Particularly dangerous: emails that appear to come from your boss or a known supplier and state new bank details. Always verify such changes by phone using a known number.
3. Look closely at the sender
The display name means nothing. What matters is the address behind it. It often differs only slightly, such as an extra letter or a different ending.
4. Check links before clicking
Hovering over a link (without clicking) shows the real destination. If the address doesn’t match the supposed sender, stay away.
5. Unusual attachments
Invoices as ZIP files, Office documents asking you to enable macros or unexpected files from colleagues are classic entry points.
6. Requests to log in
“Please confirm your password.” Reputable providers don’t ask for this by email. When in doubt, open the website directly in your browser instead of using the link.
7. Your gut feeling
If something seems odd, it often is. Better to ask once too often than once too little.
What if someone clicked anyway?
Report it immediately – without fear of blame. The sooner IT knows, the smaller the damage. Change the password and have the affected device checked.
Technology as a safety net
An upstream mail gateway filters out most phishing emails before they reach the inbox. With SPF, DKIM and DMARC you also prevent fraudsters from abusing your own domain. More under email security.
Frequently asked questions
How do I recognise fake senders?
Look at the actual email address behind the display name and for minimal differences in the domain.
Do phishing trainings help?
Yes, especially when they are regular and practical. The goal is not fear, but a sharper eye and quick reporting.
What should I do after clicking a phishing link?
Inform IT immediately, change your password and have the device checked. The faster, the less damage.


