Check the sender's actual address, hover over the link before you click, and be suspicious of urgency and unexpected attachments. Those few seconds catch most phishing emails before they cause trouble.
Firewalls, antivirus and endpoint protection all matter, but phishing is designed to go around them by fooling a person into clicking, opening or typing a password. It's one of the most common ways attackers get into business networks, which is why it's worth teaching everyone in the office how to spot it.
The good news is that phishing emails have tells, and anyone can learn them without a technical background. In this episode of NerdSquad Tech Tips, our CEO walks through a simulated phishing email and points out each red flag, using the same kind of test we send to client teams as part of security awareness training. It's short enough to share with your whole team.
A phishing email is a fraudulent message designed to trick you into revealing sensitive information, opening a malicious file or clicking a harmful link. It's built to look legitimate, often impersonating a well-known brand such as Microsoft, your bank or Meta, or even a colleague, and it usually creates a sense of urgency so you act before you think.
For financial advisers, medical and dental practices and other businesses that hold sensitive client data, the stakes are higher. One successful phishing email can lead to stolen credentials, ransomware, a breach notification or a regulatory inquiry. Phishing is also how many business email compromise (BEC) schemes begin.
Phishing emails usually lead with alarm: "Your account has been locked." "Immediate action required." "Unauthorized access detected." The goal is to get you acting before you're thinking. If a subject line makes your pulse jump, give it an extra few seconds before you do anything.
Awkward phrasing, odd grammar or language that feels slightly off are also signs, although well-written phishing emails are increasingly common, so don't rely on typos alone.
If you weren't expecting a file, treat it as suspicious no matter who it seems to come from. Files ending in .exe or .zip, and oddly named PDFs, are common ways to deliver malware. Even if the email appears to come from a coworker, confirm with them by phone or in person before opening it, because attackers often spoof internal addresses or send from compromised accounts. When in doubt, report it to your IT help desk.
This is one of the most reliable checks and takes about two seconds. The display name might say "Microsoft Support," but the address behind it tells the real story. Hover over the sender name, or tap it on a phone, to see the full address. Genuine Microsoft email comes from Microsoft's own domains; something like @microsoft-alerts.com or @ms-securityteam.net is not Microsoft.
The link text might say "Verify your account," but the destination is what matters. Hover over any link before clicking and read the full address that appears. Phishing links use tricks such as subdomains (in facebook.attacker-domain.com, the real domain is attacker-domain.com), look-alike spellings (rnicrosoftonline.com instead of microsoftonline.com) or extra characters. If the domain doesn't look exactly right, don't click. Go to the site directly instead.
Staff awareness is an important layer, but it shouldn't be the only one. Here's what we put underneath it for clients.
Security awareness training is a standard part of NerdSquad cybersecurity plans. It includes controlled phishing simulations: realistic test emails sent to your team without warning. If someone clicks, they land on a short training page instead of a malicious site. It's a low-stakes way to see who needs more coaching and to build the habit of checking before clicking, and the results let you track progress over time.
Our email security tools check links in incoming messages and check them again when they're clicked. Suspicious links are flagged or blocked, which catches many attacks that get past a busy person's judgment.
Beyond basic spam filtering, advanced email security looks at sender reputation, domain age, message headers and content patterns to catch phishing designed to look clean. It's a meaningful step up from the default filtering that comes with most email services, and it works alongside the security settings we manage as part of Microsoft 365 support.
Multi-factor authentication (MFA) makes a stolen password far less useful, and endpoint detection and response can spot and contain malicious activity on a computer if a file does get opened.
Pause before you click. Many phishing attacks succeed because someone reacted immediately. A deliberate two-second check of the sender address and the link destination, before taking any action, catches a large share of them. Make that pause a reflex across your team; it costs nothing and pays off every week.
More short videos like this one are collected in NerdSquad Tech Tips, and our blog has a companion post: How to spot a phishing email in under 10 seconds.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: Cybersecurity services