How to Spot a Phishing Email: 7 Red Flags With Real Examples

You get dozens of emails a day, and most of them are fine. But somewhere in that pile, sooner or later, there will be one that is not. It will look like it came from Microsoft, your bank, a vendor you actually pay, or even your boss. Phishing emails work because they look normal at a glance, and a glance is all most of us give our inbox.

The good news is that almost every phishing email gives itself away if you know where to look. Attackers reuse the same handful of tricks because those tricks work on people who have never been shown them. Once you have seen the patterns, they are hard to unsee.

This article walks through the seven red flags we teach in security awareness sessions, dissects a realistic example piece by piece, and covers the part most articles skip: exactly what to do in the first few minutes after you realize you clicked.

Red flags 1 through 4: the sender and the setup

Most phishing emails fail the sniff test before you even read the body. These first four flags show up in the sender line and the opening words.

  • Mismatched sender domain. The display name says Microsoft Support, but the actual address behind it is something like alerts@notice-mail-347.com. Mail apps, especially on phones, show only the friendly name by default, so tap or hover on the sender to reveal the real address. If the domain after the @ does not match the company the email claims to be from, stop right there.
  • Lookalike domains. Attackers register domains built to survive a quick glance: rnicrosoft.com (that is an r and an n, not an m), paypa1.com with a number one, or yourbank-security-center.com. The real brand name is in there somewhere, which is exactly the point. Read the domain slowly and pay attention to what sits just before the .com.
  • Generic greetings. Dear Customer, Dear Account Holder, Hello User. Your bank knows your name, and so do Microsoft, your payroll provider, and every vendor you pay. A message about your account that cannot manage to use your name was almost certainly sent to thousands of people at once.
  • Urgency and threats. Your account will be suspended in 24 hours. Failure to verify will result in permanent deletion. Real companies rarely talk this way, and they never resolve it through a single email with a button in it. Urgency exists for one reason: to make you act before you think.

Red flags 5 through 7: the ask

The next three flags are about what the email wants you to do. This is where a message goes from suspicious to dangerous.

  • Unexpected attachments and links. An invoice from a company you have never dealt with, a shared document you were not expecting, a voicemail notification in your inbox. If you were not expecting it, verify through another channel before opening anything. Call the person, or start a fresh email to the address you already have on file. Never just reply to the message itself.
  • Gift card and wire requests. The classic version is a short note that appears to come from your boss: are you at your desk, I need a favor, it is urgent, buy five gift cards and send me the codes. No legitimate manager, vendor, or government agency will ever ask for payment in gift cards, and wire instructions that arrive by email should always be confirmed by phone using a number you already had.
  • MFA fatigue prompts. This one hits your phone, not your inbox. If your authenticator app pops up a sign-in approval you did not trigger, someone already has your password and is hammering your second factor hoping you approve just to make it stop. Deny it, change that password, and tell IT.

Walk through a fake one with me

Picture an email with the subject line Action required: unusual sign-in activity. The display name is Microsoft 365 Security Team. The body says a sign-in was detected from an unfamiliar location, your account has been temporarily limited, and you must verify your identity within 24 hours or lose access to your files. There is a big blue button labeled Review Activity. The logo looks right, the formatting looks right, and the footer even has an unsubscribe link.

Now slow down. Tap the sender name and the address behind Microsoft 365 Security Team turns out to be security-alert@m365-account-notices.com, which is not a Microsoft domain. The greeting is Dear User. The deadline is 24 hours. Press and hold the Review Activity button (or hover on a computer) and the link preview shows a domain that has nothing to do with Microsoft at all.

That is four of the seven flags in one message: mismatched sender, generic greeting, manufactured urgency, and a link that does not go where it claims. A real Microsoft alert would use your name and tell you to sign in yourself at the address you already know, not through a button in the email.

You clicked anyway. Here is your next 30 minutes

It happens, including to IT professionals. What matters now is speed, not blame.

One more thing if you run a business: make it loudly, explicitly safe for people to report their own clicks. The person who says they think they just did something dumb within five minutes is the hero of that story. Many breaches start with a phishing email, and the damage usually comes from how long the click went unreported, not from the click itself.

  • Change your password immediately, from a different device if you can, and change it anywhere else you reused it. This is the moment a password manager like 1Password or Bitwarden earns its keep, because unique passwords mean one compromised account stays one compromised account.
  • Turn on multi-factor authentication if it is not already on, ideally with an app like Microsoft Authenticator rather than text messages.
  • Tell IT right away. A stolen password reported in ten minutes is a non-event. One reported next Tuesday is an incident.
  • Do not delete the email. Your IT team needs it to find out who else received the same message.

How businesses build the reflex: phishing simulations

Reading about red flags builds knowledge. Simulations build the reflex. Companies that take this seriously send their own staff fake phishing emails on a regular schedule, using the exact tricks above, and measure what happens.

Done well, it looks like this: anyone who clicks the simulated link lands on a short, friendly teaching page instead of getting a lecture, click rates are tracked as a team trend over months rather than posted as a wall of shame, and a report button in the mail client makes doing the right thing take one click. Over time the click rate falls and the report rate climbs, and that pair of numbers is what actually tells you your team is getting harder to fool.

You do not need enterprise software to start. CISA publishes free phishing guidance and awareness resources, and even a monthly ten-minute huddle reviewing one real phishing email that reached your team will do more good than an annual slideshow.

Key Takeaways

  • Check the real sender address, not the display name, before trusting any email that asks you to act.
  • Urgency is a tactic, not a coincidence, so treat every act-now email as a reason to slow down.
  • No legitimate boss, vendor, or bank will ever ask for gift cards, and you should never approve an MFA prompt you did not start.
  • If you click a bad link, changing your password and telling IT within minutes turns a crisis into a non-event.
  • Regular phishing simulations with a no-blame reporting culture are the most reliable way to keep a team sharp.

If you want your whole team practicing these red flags, book our free 30-minute remote security awareness session (delivered over video call in English, Spanish, or Portuguese, no obligation) at logicsystemiq.com/free-training/.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top