How to Spot a Phishing Email
Phishing is still the most common way attackers get into a business, not by breaking through a firewall, but by getting one person to click. Here's what to watch for, what to do about it, and what's backing you up if you miss it.
Common Red Flags
- A sender that doesn't quite match. The display name looks right, but the actual email address is off, a wrong domain, extra characters, or a lookalike spelling.
- Urgency or pressure. "Your account will be suspended," "action required immediately," anything designed to make you act before you think.
- A generic greeting. "Dear Customer" or "Dear User" instead of your actual name, especially from a company that would normally know it.
- Requests for credentials, payment, or gift cards. Legitimate companies don't ask you to log in through a link in an email, and no executive is ever going to ask for gift card codes over email.
- Links and attachments you weren't expecting. Hover over a link before clicking it, if the URL doesn't match where it claims to go, don't click it.
What to Do If You Spot One
- Don't click, reply, or download anything.
- Submit a ticket or forward it to our team so we can confirm whether it's part of a wider campaign targeting your organization.
- If you're not sure whether something's legitimate, ask before you act. It takes thirty seconds and it's always the right call.
If You Click Anyway
Mistakes happen, that's exactly why we have Huntress running on every device. If a phishing email does lead to something malicious, Huntress is watching for the follow-up: unusual behavior, an attacker trying to gain a foothold, or ransomware activity. In most cases, the affected device is automatically isolated and our team is notified before it can spread any further.
That said, Huntress is a safety net, not a reason to let your guard down. The fastest, cheapest fix is still not clicking in the first place. If you did click, or entered a password somewhere it didn't belong, see I Think I Clicked Something Bad, Now What? for exactly what to do next.
Learn More
For a deeper walkthrough of what phishing looks like and how attackers use it, see CISA's guide on recognizing phishing.
Phishing Simulation & Training
Reading a guide like this one is a start, but the real test is what someone does in the moment an actual phishing email lands in their inbox. That's what our phishing simulation and training service is built around, available for $10/user/month.
Here's how it works:
- We send realistic, but harmless, simulated phishing emails to your team on an ongoing basis, the same tactics real attackers use.
- If someone clicks, they're automatically assigned a short training module targeted at whatever red flag they missed, no lecture, no wasted time for people who are already getting it right.
- You get visibility into how your team is actually doing over time, not a guess, an actual click rate you can watch improve.
It turns security awareness from a one-time onboarding checkbox into something that's continuously tested and reinforced. Ask your account manager to get your team enrolled.
Need Help?
If you run into any issues, reach out to the Triumphant support team:
- Email: [email protected]
- Phone: (404) 387-0435