Spot Phishing Emails Before You Click

This chapter of Manage IT Better is about the message that looks like work until it is not. Sean Pennington opens with a number he puts on the table: 90% of cyber attacks start with a phishing email. The rest of the talk is what that email actually is and what to do before anyone clicks.

Phishing is a scammer posing as a bank, a coworker, or a vendor you already use. The goal is information you would not hand a stranger, or a click on a bad link. The domain often looks close enough. Bank of America with an extra letter. A numeral in place of an L. A Cyrillic character that reads like a Latin A. That is a lookalike domain. That is a lookalike domain. Spoofing is mail that claims your real domain while it is sent from a server tha’t allowed to send it.

Grammar used to be the giveaway: “Dear user” instead of a name. AI has made those tells weaker. Sean notes a test where AI itself missed a phish next to a real message. Filters still help. Anti-spam and anti-phishing tools combine AI with other signals so most junk never reaches the inbox. They also get it wrong. A good service alerts you, and a fast MSP releases a real message after someone checks it. Users should not have a blanket “release anything” button. Expecting mail from John and opening mail from Johnny is how the first hook gets into the network.

Attachments are the other door. A PDF with a link inside. A zip or RAR with several files packed together. These formats help bypass mail filters. Hover is not enough. Call the sender on a number you look up yourself. Send the message to your MSP if it feels off. Scan the file.

Key takeaways

  • Sean states that 90% of cyberattacks start with a phishing email. Treat unexpected requests for data or clicks as hostile until proven otherwise.

  • Lookalike domains mimic a brand. Spoofing is different: mail that uses your real domain from an unauthorized server.

  • AI has made grammar and tone less reliable as the only test. Filters help and still miss or over-block.

  • Do not give users a blanket release from quarantine. Confirm the sender before a held message goes through.

  • Treat PDFs with embedded links and compressed files (zip, RAR) as high risk.

  • Verify on a channel you already know. Look up the phone number. Call. Or send the message to your MSP. Do not use contact details inside the suspect email.

Next
Next

Why Software Updates Matter