Skip to main content
← Back to all posts
email security··6 min read·By Quantm Security Team

How to Spot a Phishing Email at Work

Check the sender, destination, request, timing, and verification path. A polished message can still be phishing, while one warning sign alone is not proof.

To spot a phishing email at work, check five things: who really sent it, where it wants you to go, what action it requests, whether the timing and context make sense, and how you can verify it without using the message itself. A polished message with a familiar logo can still be malicious.

If anything is unusual, pause and report it. Do not reply, call a number in the message, or use its link to verify the request.

1. Inspect the real sender

Expand the sender details and compare the full address with the person or service being represented. Look for a different reply-to address, a lookalike domain, an unexpected consumer mailbox, or a sender that has never contacted you this way.

A real address is not proof of safety. A legitimate account can be compromised.

2. Check the destination before opening it

On a managed computer, hover over a link where the email client supports it. On a phone, use caution because the destination may be harder to inspect. Avoid scanning an unexpected QR code simply to discover where it goes.

Ask whether the destination matches the service and workflow you normally use. A shared document should not unexpectedly send you to a different identity provider or ask for credentials after you are already signed in.

3. Identify the requested action

Phishing is designed around action. Common requests include signing in, approving MFA, opening a file, scanning a QR code, changing payment details, buying gift cards, sharing confidential information, or bypassing a normal process.

Urgency, secrecy, authority, and convenience can all be used to suppress verification. Treat the request itself as a signal, even when the writing is professional.

4. Compare it with normal business context

Check whether the person, timing, amount, project, and channel fit the normal process. A supplier may be real but the bank-detail change may not be. A colleague may be travelling, but that does not remove the approval requirement.

CISA recommends using a known contact method rather than replying or using a phone number provided in a suspicious message.

5. Verify outside the message

Open the service from a saved bookmark, contact the person using the company directory, or use the approved finance or HR workflow. Do not let the sender choose the verification channel.

Quick decision guide

Situation Safer next step
Unexpected sign-in request Open the service from a known bookmark
Payment or bank change Verify through the approved contact record
MFA prompt you did not start Deny it and report immediately
Unexpected file or QR code Use the report-phishing process
Message from a known person feels wrong Contact them through a separate known channel
You already interacted Stop, report exactly what happened, and follow response instructions

What to do after a click

Report the event immediately and describe whether you opened a link, entered a password, approved MFA, downloaded or ran a file, scanned a QR code, or sent information or money. Do not hide the mistake or wait to see what happens.

The response owner may need to revoke sessions, reset credentials, inspect authentication methods and inbox rules, trace related messages, isolate a device, contact a financial institution, or preserve evidence. The exact action depends on what occurred.

Use this method inside a recurring phishing training program. The common email threats guide explains how phishing differs from spoofing, BEC, and account takeover. Quantm's email security program guide connects these employee actions to technical controls. Quantm's M365 Posture Review can also test whether reporting and containment paths are ready.