Spot Phishing Emails Before You Click
This chapter of Manage IT Better is about the message that looks like work until it is not. Sean Pennington opens with a number he puts on the table: 90% of cyber attacks start with a phishing email. The rest of the talk is what that email actually is and what to do before anyone clicks.
Phishing is a scammer posing as a bank, a coworker, or a vendor you already use. The goal is information you would not hand a stranger, or a click on a bad link. The domain often looks close enough. Bank of America with an extra letter. A numeral in place of an L. A Cyrillic character that reads like a Latin A. That is a lookalike domain. That is a lookalike domain. Spoofing is mail that claims your real domain while it is sent from a server tha’t allowed to send it.
Grammar used to be the giveaway: “Dear user” instead of a name. AI has made those tells weaker. Sean notes a test where AI itself missed a phish next to a real message. Filters still help. Anti-spam and anti-phishing tools combine AI with other signals so most junk never reaches the inbox. They also get it wrong. A good service alerts you, and a fast MSP releases a real message after someone checks it. Users should not have a blanket “release anything” button. Expecting mail from John and opening mail from Johnny is how the first hook gets into the network.
Attachments are the other door. A PDF with a link inside. A zip or RAR with several files packed together. These formats help bypass mail filters. Hover is not enough. Call the sender on a number you look up yourself. Send the message to your MSP if it feels off. Scan the file.
Key takeaways
Sean states that 90% of cyberattacks start with a phishing email. Treat unexpected requests for data or clicks as hostile until proven otherwise.
Lookalike domains mimic a brand. Spoofing is different: mail that uses your real domain from an unauthorized server.
AI has made grammar and tone less reliable as the only test. Filters help and still miss or over-block.
Do not give users a blanket release from quarantine. Confirm the sender before a held message goes through.
Treat PDFs with embedded links and compressed files (zip, RAR) as high risk.
Verify on a channel you already know. Look up the phone number. Call. Or send the message to your MSP. Do not use contact details inside the suspect email.

