IT securityPublished on · 5 min read· Author: WSV Redaktion

Spotting Phishing Emails: A Checklist for Employees

How to recognize phishing emails, which scams are currently in circulation, and how to react correctly if you suspect one – a checklist for your employees.

Phishing remains one of the most common ways attackers gain access to company networks. A single email click can be enough to steal credentials or plant malware. The most effective protection consists of two building blocks: technical filtering and alert employees who recognize suspicious messages before any damage is done.

How to recognize phishing emails

The sender doesn't add up

Check not just the displayed name but the actual email address. Common warning signs:

  • The domain deviates slightly from the known sender (for example, swapped letters or an extra ending).
  • An internal contact suddenly writes from an external address.
  • The display name sounds trustworthy, but the address behind it doesn't.

Links lead somewhere other than what they claim

Hover over a link without clicking and look at the actual target URL. If it doesn't match the displayed text or the expected domain, be cautious. On a smartphone, a long press on the link shows the address without opening it.

Artificial pressure and urgency

Phishing emails want you to act quickly and without thinking. Typical wording includes account lockouts, supposedly outstanding payments, threatened consequences, or a very tight deadline. Legitimate senders rarely rely on this kind of pressure.

Unexpected attachments

Invoices, payment reminders, or supposed delivery documents in formats such as ZIP, EXE, or Office files with macros enabled are a classic trick. If the attachment wasn't expected or doesn't fit an ongoing business relationship, it shouldn't be opened.

Common scams

  • Invoice fraud: fake invoices with a slightly altered payment recipient or a malicious attachment.
  • Fake job applications: supposed application documents in the attachment, often sent to HR departments or general mailboxes.
  • CEO fraud: a supposedly urgent instruction from management to trigger a transfer or hand over data.
  • Supplier or bank emails: a request to enter credentials on a fake login page.

Fake login pages

A popular target of phishing links are cloned sign-in pages that look deceptively similar to those of Microsoft 365, banks, or other well-known services. Before entering credentials, always check the address bar: does the domain match the expected address exactly? Missing encryption, or a page that looks slightly different from usual, are further warning signs. When in doubt, it's safer to type the service's address into the browser yourself rather than following a link.

QR codes as a new tactic

QR codes are increasingly used for phishing too, for example in emails or on printed flyers. Since the destination of a QR code isn't visible before scanning, extra caution is warranted: if the code leads to a login prompt or a file download, the same checks apply as for a regular link.

Checklist for suspected phishing

If an email seems suspicious, a simple rule applies: don't click, don't download, don't reply.

  • Don't click links and don't open attachments.
  • Inform your IT department or service provider – when in doubt, once too often is better than not at all.
  • Don't delete the email before it has been checked, so it can be analyzed.
  • If you've already clicked a link or entered credentials, change the affected password immediately and inform colleagues.
  • Report anomalies such as unusual senders or spelling mistakes to your team so others are warned.

Why everyone in the company is a potential target

Phishing is no longer aimed only at management or accounting. Attackers send broad, mass-distributed campaigns while also running targeted attacks against individual people, gathering details about their role and tasks from publicly available information such as social media profiles or the company website. The more precisely an email is tailored to its recipient, the harder it becomes to recognize it as fake. That's why everyone in the company – regardless of position or department – should know the basic warning signs.

Why training and technical protection belong together

No filter catches every phishing email, because attackers constantly adapt their methods. At the same time, no employee can maintain one hundred percent vigilance permanently – a brief lapse in a stressful moment is enough. That's why both layers complement each other:

  • A reliable spam and phishing filter keeps most malicious emails away from the inbox before employees even come into contact with them.
  • Regular awareness training ensures that the emails which still get through are recognized and reported correctly.

Conclusion

Phishing can't be reliably fended off by technology alone or training alone – only the combination of both protects your company. With our anti-spam protection we reliably filter out suspicious emails before they reach your employees' inboxes. Find out more about securing your IT overall in our IT security section. Feel free to reach out via our contact page if you need support securing your mail infrastructure or training your team.

Start remote support

Privacy settings

We use technically necessary storage for operating this website. Optional services (statistics, marketing, external media) are only loaded after your consent.

Privacy settings