Guide · Updated September 2026

How to Spot a Phishing Email: A Plain-English Staff Guide

Phishing emails are still the number one way scammers get into small business systems. Here's a plain-English guide your whole team can use to spot the warning signs before it's too late.

Why phishing still works

Phishing is when someone sends you an email pretending to be a person or company you trust — your bank, the ATO, a supplier, or even your own boss — hoping you'll click a dodgy link, hand over a password, or pay a fake invoice. It's cheap, fast, and it works, which is why it remains the most common way small businesses across The Hills and Greater Sydney get caught out.

The good news? You don't need to be technical to spot most phishing attempts. You just need to know what to look for and to slow down for a few seconds before you click. This guide is written for everyday staff, not IT specialists.

The seven red flags to check

No single sign is proof on its own, but if an email trips two or three of these, treat it with real suspicion.

1. It creates urgency or fear

"Your account will be suspended in 24 hours." "Unpaid invoice — final notice." "Unusual sign-in detected, act now." Scammers want you panicked so you react before you think. Legitimate organisations rarely threaten you with a countdown clock.

2. The sender address doesn't match the name

The display name might say "Commonwealth Bank" but the actual address could be something like service@secure-cba-alerts.co. Hover over (or tap and hold) the sender name to reveal the real address. Look closely for subtle misspellings — micros0ft.com, paypa1.com, or an extra word bolted onto a familiar brand.

3. Links that don't go where they say

Before clicking any link, hover your mouse over it (on a phone, press and hold) to preview the real destination. If the text says "myob.com" but the preview shows a random string of characters or a country code you don't recognise, don't click. When in doubt, open a new browser tab and type the website address in yourself.

4. Unexpected attachments

Invoices, receipts, delivery notices and "scanned documents" you weren't expecting are classic bait — especially ZIP files, or Office documents that ask you to "enable content" or "enable macros". If you weren't expecting a file, verify it before opening.

5. Generic or odd greetings

"Dear Valued Customer" or "Dear user" from a company that normally knows your name is a warning sign. So is language that's slightly off — awkward phrasing, strange grammar, or a tone that doesn't sound like the person supposedly writing.

6. It asks for something sensitive

Passwords, credit card numbers, bank details, your date of birth, or a request to "confirm" your login. No reputable organisation asks you to send these by email or enter them via an email link.

7. It's a payment or bank-detail change request

This is the big-money one for small businesses. An email that appears to come from a supplier or your manager asking you to pay a new account, change bank details, or buy gift cards should always be verified by phone using a number you already have — never a number in the email itself.

The sneaky ones: business email compromise

The most damaging attacks we see aren't the obvious "Nigerian prince" emails — they're targeted ones that look completely normal. A scammer studies a business, then emails the accounts person pretending to be the director: "Hi, can you process this payment today? I'm in a meeting, just reply here." The email address might be a near-perfect fake, or a genuine account that's already been hacked.

The defence is simple and human: any request to move money or change payment details gets verified through a second channel. Pick up the phone. Walk over to their desk. A ten-second check has saved businesses tens of thousands of dollars.

What to do if an email looks suspicious

  • Stop. Don't click links, open attachments, or reply.
  • Don't unsubscribe. On a phishing email, the unsubscribe link can be just as dangerous as any other.
  • Verify independently. Contact the supposed sender using a phone number or website you already trust — not the details in the email.
  • Report it. Tell your manager or IT support so they can warn the rest of the team. If it's targeting your business, others may have received it too.
  • If you clicked — don't panic, but act fast. Disconnect nothing on your own; instead tell IT straight away. The sooner passwords are changed and access is checked, the less damage is done.

What to do if you've already entered a password

Change that password immediately, and change it anywhere else you've reused it (which is exactly why you shouldn't reuse passwords). Then let your IT support know so they can review account activity. This is also where multi-factor authentication earns its keep — even if a scammer has your password, MFA can stop them getting in.

Building a team that doesn't get caught

Technology filters out a huge amount of junk before it ever reaches your inbox, and it should. A properly configured Microsoft 365 environment with good spam and threat protection, combined with MFA on every account, blocks the overwhelming majority of attacks. But no filter is perfect, and the last line of defence is always the person reading the email.

That's why we're big believers in awareness over blame. Staff who feel safe to say "I think I clicked something" report problems faster, and speed is everything with phishing. Regular, short refreshers keep everyone sharp — the tactics change, but the red flags above stay remarkably consistent.

At Commit-IT we help Hills and Greater Sydney businesses lock down email, roll out MFA, and give staff practical training that sticks — as part of our managed IT support. We're not about scaremongering or cookie-cutter checklists; we're about setting your team up so the right instinct kicks in automatically.

If a suspicious email ever leaves you unsure, that instinct — to pause and check — is worth more than any piece of software. Trust it.

Free, no-obligation

Talk to a local IT partner

Book a 15-minute call — we'll give you a clear, jargon-free picture of where your IT stands.