Check for signs that the message is trying to rush or mislead you, such as spelling mistakes, generic greetings, unexpected links, or requests for personal information. Verify the sender address carefully and avoid opening attachments or clicking links if anything feels off. If the message claims to be from a known brand, confirm it through the official website or customer support channel.
What makes a phishing email convincing before you interact with it?
A fake email usually tries to create urgency, authority, or curiosity so you act before thinking. The giveaway is often not a single flaw, but a pattern: mismatched sender details, awkward wording, a request that does not fit normal business practice, or a message that pushes you toward a link or attachment instead of a trusted channel.
Read the message as an attacker would design it. A convincing phish often borrows a real logo or brand name, but the visible display name is less important than the actual sending domain, reply-to address, and the destination behind any link. If those do not line up with the supposed sender, treat the message as suspicious.
One useful check is whether the email is asking for an exception to normal process. Phishing often works by bypassing routine verification, such as telling you to “review immediately,” “reset now,” or “confirm account details.” A legitimate organisation usually gives you a path to verify the request independently rather than demanding action inside the message itself.
Which message details should you inspect first?
Start with the sender, the subject, and the call to action. A trusted brand name in the display field can be misleading if the underlying address is unrelated, misspelled, or hosted on a free mail domain. Subject lines that imply payment problems, account lockouts, missed deliveries, or password resets deserve extra scrutiny because they are designed to trigger fast clicks.
Then inspect the wording. Poor grammar is a clue, but not a reliable test on its own because many fake messages are now polished. More useful is whether the tone feels generic, overly broad, or inconsistent with how that organisation normally communicates. A message that does not mention your actual name, account context, or recent activity is often trying to cast a wide net.
Attachments and embedded links deserve the most caution. A real organisation may use them, but a suspicious one often makes the attachment or link the primary path to the supposed fix. Before clicking, hover over the link to see the destination, and compare it with the claimed sender. If the address looks shortened, unrelated, or strangely formatted, do not trust it.
How do you verify a suspicious email without taking the bait?
The safest approach is to step outside the email and confirm the request through a channel you already trust. Open the organisation’s website yourself, use a saved bookmark, or call a known support number rather than following any contact details in the message. That separates verification from the potentially malicious content.
If the message claims there is a problem with an account, order, invoice, or password, log in through the official site directly and check for alerts there. If the issue is real, it should also appear in the organisation’s normal service channel. If it does not, that is a strong reason to treat the message as fraudulent.
When a message includes a request for credentials, payment details, or personal data, assume the request is suspect until proven otherwise. Legitimate organisations may request information, but they rarely demand it through an unexpected email that also creates urgency. Confirmation through the normal support or self-service process is the right control here.
Risk and Threat Considerations
Phishing is dangerous because it turns ordinary attention lapses into account compromise, malware delivery, or fraud. The email itself is often harmless until a user clicks, enters credentials, or opens an attachment, which is why early recognition matters more than post-click cleanup.
Failure mechanism: Attackers exploit urgency, trust in brands, and familiar communication patterns to bypass judgment. Once the user follows the message path, the attacker can capture credentials, redirect payments, or launch a secondary payload through a malicious link or file.
Impact: A single successful phish can lead to mailbox takeover, financial loss, unauthorized access to internal systems, or further impersonation of the victim to reach other people. In business settings, the downstream effect is often broader than the initial email because the compromised account can be used to send convincing follow-on messages.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-8 — Spam Protection | Phishing emails are a spam and malicious-content delivery problem. |
| IA-5 — Authenticator Management | Phishing often aims to steal credentials and tokens from email recipients. | |
| Recommendation — Filter suspicious mail before it reaches users and quarantine likely phishing messages. Use phishing-resistant authentication and rotate exposed credentials quickly. | ||
| CIS Controls v8 | CIS-9 — Email and Web Browser Protections | Email link and attachment inspection depends on browser and mail protections. |
| Recommendation — Harden mail and browser controls to block malicious links, downloads, and scripts. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | Users need clear, trustworthy warning signals when messages or destinations look suspicious. |
| Recommendation — Log suspicious-mail events and surface clear warnings for risky destinations. | ||
| MITRE ATT&CK | T1566 — Phishing | The subject is about recognising phishing emails before interaction. |
| Recommendation — Map observed lures to phishing techniques and tune detections for common pretext patterns. | ||
Practitioner Guidance
What to verify: Train yourself to verify the sender domain, the actual link destination, and whether the request matches the organisation’s normal process before you interact. If any one of those three looks off, stop and confirm through a separate channel.
Common mistake: People often look only for obvious spelling errors and miss better-crafted phish that rely on urgency or brand impersonation. A polished email is not a safe email, so the decision should rest on source verification and process fit, not just presentation quality.
Decision rule: If the message asks you to log in, pay, approve, or disclose information and it arrived unexpectedly, treat it as untrusted until you independently confirm the request. That rule is stricter than “does it look suspicious,” and it is much harder for attackers to bypass.
Practitioner takeaway: The safest habit is to separate verification from interaction, because a fake email only becomes effective when it persuades you to trust the message path itself.
Related resources from NHI Mgmt Group
- How should security teams train users to spot phishing URLs before they click?
- How should people verify whether a shipping or shopping email is legitimate before clicking anything?
- Should employees contact the cybersecurity team before they click on a questionable email or website?
- Why does identity matter more when vulnerabilities are discovered faster than they can be patched?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org