Auckland · North Shore · Manukau Portal Login
Security & Strategy · 5 min read

How to Spot and Stop Phishing Emails

Phishing is still the most common way businesses get caught out, so here is how to recognise it and what to do when one arrives.

Phishing is when someone sends a fake message pretending to be a person or company you trust, hoping to trick you into handing over a password, clicking a dangerous link, or paying a bogus invoice. It remains one of the most common ways businesses get caught out, largely because it targets people rather than technology. The good news is that once you know the signs, most phishing is easy to spot.

Common signs of a phishing email

No single clue proves an email is fake, but the more of these you see, the more suspicious you should be.

  • A sense of urgency. Messages that push you to act immediately, warn your account will be closed, or threaten a fine are trying to make you panic and skip your usual caution.
  • Unexpected links or attachments. If you were not expecting a file or a login link, treat it with care, even if it looks familiar.
  • An address that is almost right. Attackers use lookalike addresses with a swapped letter or an odd domain. Check the sender carefully, not just the display name.
  • Requests for passwords or payment details. Genuine organisations do not ask you to confirm your password by email.
  • Odd wording or formatting. Slightly off phrasing, unusual greetings or mismatched logos are all worth a second look.

The trickier ones to catch

Not all phishing is clumsy. Some messages are well written and highly targeted, especially those that impersonate a manager or supplier. A common example is a message that appears to come from the boss asking someone in accounts to urgently pay an invoice or buy gift cards. Another is an email that looks exactly like a shared document notification.

The defence here is a habit, not a checklist. If a message asks for money or sensitive information, confirm it through a separate channel before acting, such as phoning the person on a number you already have. A thirty-second phone call has saved many businesses a great deal of money.

What to do when one lands

If you receive a suspicious email, the safest path is simple.

  1. Do not click any links or open any attachments.
  2. Do not reply or forward it to colleagues as a warning, which only spreads the risk.
  3. Report it using your reporting button if you have one, or tell your IT provider.
  4. Delete it once it has been dealt with.

If you think you may have already clicked or entered a password, do not keep it to yourself out of embarrassment. Tell your IT support straight away. Changing a password quickly and turning on multi-factor authentication can shut an attacker out before they do any harm.

Training your staff

Technology filters catch a lot, but some messages always slip through, which makes your people the real front line. The aim is a calm, sceptical culture rather than fear.

Make it completely safe for staff to report a mistake. People who feel they will be blamed tend to stay quiet, and silence is exactly what an attacker is counting on.

Short, regular reminders work far better than a single annual lecture. Many businesses also run occasional simulated phishing exercises, where harmless test emails help staff practise spotting the real thing. Over time this builds an instinct to pause before clicking.

The takeaway

Phishing works by rushing you and impersonating someone you trust, so the best defence is to slow down and verify. Combine alert staff with good email filtering and multi-factor authentication, and you close off most of the risk. If you would like help setting up filtering or staff training, our team can point you in the right direction. Call Comsys IT on 0800 724 526.

Back to all articles
Let's talk

Ready for IT that just works?

Book a free, no-obligation chat. Local Auckland experts, plain-English advice, and support you can actually reach.

Call now Free quote
Free IT Assessment