Appearance
How to Identify a Phishing Email
Applies to: Microsoft 365 (Outlook), any email client
Article Type: Informational
Last Updated: 2026-03-08
Summary
Phishing emails impersonate trusted senders to trick you into clicking malicious links, opening infected attachments, or revealing sensitive information. This article explains the five most common red flags and what to do when you spot one.
Prerequisites
- None. These steps apply to all users.
Instructions
1. Check the Sender Address
Phishing emails often use addresses that look similar to a legitimate sender but contain slight differences.
- Look at the From field in the email header — not the display name.
- Compare the domain (the part after the
@sign) to the organization's real domain. - Watch for misspellings, extra characters, or unusual domains (e.g.,
[email protected]instead of[email protected]).
2. Look for Urgency or Threats
Attackers use pressure tactics to make you act before you think.
- Be suspicious of language like "Your account will be suspended," "Immediate action required," or "You have 24 hours to respond."
- Legitimate organizations rarely threaten account closure over a single email.
3. Inspect Links Before Clicking
Malicious links are the primary weapon in most phishing emails.
- Hover your mouse over any link in the email — do not click it.
- A tooltip or status bar will show the actual URL the link points to.
- Look for mismatched domains (e.g., the email says "Microsoft" but the link goes to
login-verify.xyz). - Be cautious of shortened URLs (e.g.,
bit.ly/xxxxx) — these hide the real destination.
4. Be Wary of Unexpected Attachments
Attachments can contain malware that runs when opened.
- If you did not expect a file from the sender, do not open it.
- Common dangerous file types include
.exe,.zip,.html, and macro-enabled Office files (.xlsm,.docm). - Even PDFs can contain malicious links — remain cautious.
5. Spot Poor Grammar and Generic Greetings
Many phishing emails are poorly written or overly generic.
- Look for spelling mistakes, awkward phrasing, or inconsistent formatting.
- Generic greetings like "Dear Customer" or "Dear User" instead of your name can be a red flag.
- Note that AI-generated phishing is improving — poor grammar alone does not guarantee safety, and good grammar does not guarantee legitimacy.
6. What to Do If You Suspect Phishing
- Do not click any links or open any attachments.
- Do not reply to the email or forward it to others.
- Report the email using Outlook's built-in Report button (see related article below).
- Delete the email from your inbox after reporting.
- If you already clicked a link or entered credentials, change your password immediately, then tell IT security exactly what happened: what you clicked, whether you typed your password or any other details, and roughly when. Forward the original message to them as an attachment so its headers survive, or use the Report button if your Outlook has one.
Troubleshooting
DANGER
If you clicked a phishing link or entered your password on a suspicious site, change your password immediately, then report it to your IT helpdesk and state plainly that you entered credentials. That one sentence is what tells them to sign your account out everywhere and check it for activity that was not you. Time is critical — the faster you act, the less damage can occur.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Legitimate email flagged as junk | Aggressive spam filter | Check the sender address carefully. If legitimate, drag the email to your Inbox and click Not Junk. |
| Suspicious email from a known contact | Compromised account | Do not reply. Contact the person through a different channel (phone, Teams) to confirm they sent it. |
| Report button missing in Outlook | Add-in not enabled | See the related article below for alternative reporting methods, or contact IT to enable the Report Message add-in. |