How to Spot a Phishing Email: A Small Business Guide
Most business security incidents do not start with a sophisticated hack. They start with an email. A convincing message tricks someone into clicking a link, opening an attachment, or typing a password into a fake page, and from there an attacker is in. That is phishing, and it is the entry point for everything from infostealer malware to business email compromise. The good news: once you know the red flags, most phishing is easy to spot. Here is how to recognize it and train your team to do the same.
What is phishing?
Phishing is a message, usually email, designed to trick you into doing something that helps an attacker: revealing a password, opening malware, or sending money. It works by impersonating someone you trust, a vendor, your bank, a coworker, a familiar service, and creating a reason to act quickly without thinking. It is less a technical attack than a confidence trick delivered at scale.
Why it matters so much for small businesses
Phishing is the on-ramp to most other attacks. A single click can install an infostealer that copies every saved password, or lead to a fake login page that hands your credentials straight to an attacker. Small businesses are targeted heavily because they rarely have dedicated security, and one busy person clicking one bad link is all it takes.
The red flags to look for
- Urgency and pressure. "Your account will be closed in 24 hours," "immediate action required." Urgency is designed to stop you thinking.
- A mismatched sender. The display name looks right, but the actual email address is off, a public domain, or a lookalike with one changed letter.
- Links that do not match. Hover over a link before clicking. If the real destination is not the site it claims to be, do not click.
- Unexpected attachments, especially invoices, resumes, or shipping notices you were not expecting.
- Requests for credentials or payment. Legitimate companies do not email you to "confirm your password." Any request to change bank details deserves a phone call to verify.
- Generic greetings and odd wording. "Dear customer," awkward phrasing, or a tone that is slightly off for the supposed sender.
No single flag is proof, but two or more together is a strong signal to stop and verify.
The common types to know
- Credential harvesting: a link to a fake login page that captures whatever you type.
- Malware delivery: an attachment or "download" that installs an infostealer or other malware.
- Spear phishing: a targeted message using real details about you or your company to seem legitimate.
- Business email compromise: a message posing as the owner or a vendor requesting a wire or a change of payment details. (See our guide to business email compromise.)
How to verify a suspicious message
When something feels off, slow down and check through a separate channel. Do not reply to the email or call a number it provides. Instead, look up the company or person independently and contact them directly. For an internal request that seems unusual, a quick message or call to the real person settles it in seconds. The extra minute is always worth it.
What to do if someone clicks or enters a password
Mistakes happen, and speed limits the damage. If someone entered a password on a suspicious page, treat that credential as compromised: change it immediately, sign out of all sessions, turn on two-factor authentication, and change it anywhere it was reused. If someone opened an attachment, disconnect and scan the device for malware before logging back in, since an infostealer may have started copying saved passwords. Then tell whoever handles security so nothing slips.
How to protect your team
- Talk about it plainly. A short, jargon-free conversation about the red flags above does more than any policy document.
- Make "verify first" normal. Encourage people to double-check unusual requests without fear of looking overcautious.
- Turn on two-factor authentication, so a phished password alone is not enough to get in.
- Use a password manager, which will not autofill your login on a fake lookalike domain, a quiet but useful phishing check.
- Monitor for leaked credentials, so if a password is phished, you find out fast.
How GuardPilot helps
Even a well-trained team clicks the wrong thing eventually. GuardPilot is the safety net: we watch the dark web and infostealer logs for your team's logins, and the moment a phished or stolen credential shows up, we alert you with a plain-English explanation and a guided fix. You can start a free scan in about two minutes, or read how to protect your small business from credential theft.
The takeaway
Phishing is the front door to most business attacks, and it relies on you acting fast without checking. Teach your team the red flags, make verifying the norm, and back it up with two-factor authentication and monitoring. Slow down on the messages that pressure you, and you close the door most attacks try to walk through.
See what’s already exposed.
Run a free scan of your business email and domain. It takes about two minutes.
Start your free scan →