Skip to content
All posts
Phishing6 min read

7 Red Flags of Phishing Emails: Spot Them in 2 Seconds

The seven structural signals that give away almost every phishing email, why each one works psychologically, and how to train the check until it becomes automatic.

ClickSafe Team

Security awareness · ClickSafe ·

Roughly one in five employees will click a phishing email this year, according to the Verizon Data Breach Investigations Report. Training moves that number substantially, but only training that teaches a repeatable check rather than a general sense of unease.

This is that check. Seven signals, each with the psychology behind it, and a verification habit short enough that people will actually use it.

Why phishing still works

Phishing exploits how attention works, not how much someone knows about computers. A message arrives inside a familiar interface, in a familiar format, at a moment when the recipient is already busy. The decision to click happens in under two seconds, well before any deliberate reasoning starts.

That is why "be careful with emails" fails as advice. It asks for vigilance, which is a finite resource that runs out by mid-afternoon. What works instead is a small number of concrete checks that fire on specific triggers.

Red flag 1: the sender address does not match the display name

What it is. The display name says a colleague or a known supplier. The actual address underneath does not match: an extra character, a different top-level domain, or a free mail provider standing in for a corporate one.

Why it works. Email is a trust medium, and mail clients show the display name prominently while hiding the address. Attackers exploit the gap between what is displayed and what is real.

How to spot it. Hover over the sender name without clicking, or tap it on mobile, and read the full address. Watch for transposed letters, an inserted or missing character, .co where you expect .com, and a display name that matches your organisation attached to an address that does not.

Red flag 2: manufactured urgency

What it is. A deadline that exists only inside the email. "Before end of day." "Within the hour." "Your access will be revoked."

Why it works. Time pressure suppresses verification. There is no window in which to check, which is the entire point of inventing the window.

How to spot it. Treat urgency itself as the signal. A genuinely urgent request from a colleague survives a thirty-second phone call to confirm it. A fraudulent one does not.

Red flag 3: a request for secrecy

What it is. "Do not forward this." "Keep this between us until the announcement." "Do not discuss with the team yet."

Why it works. It isolates the target from exactly the people who would recognise the fraud immediately.

How to spot it. In legitimate organisations, confidential matters travel through named, established channels, not through instructions to conceal an email. Secrecy plus payment is close to conclusive.

What it is. The visible text reads like a familiar domain. The underlying URL points somewhere else entirely.

Why it works. People read link text as though it were the destination, because normally it is.

How to spot it. Hover to reveal the real URL in the status bar; long-press on mobile. Read the domain immediately before the first single slash, that is the actual host, and everything after it is decoration the attacker controls.

Red flag 5: an unexpected credential prompt

What it is. A link that leads to a login page you did not navigate to yourself.

Why it works. Login pages are so routine that typing a password into one barely registers as a decision.

How to spot it. Never sign in from an emailed link. Open a new tab and navigate to the service directly, or use the bookmark. If the request was genuine, the same task will be waiting for you there.

Red flag 6: a change to payment details

What it is. A supplier updates their bank details, often as a reply inside a real and lengthy email thread.

Why it works. Thread hijacking means the conversation history is genuine, and the request arrives in a context that has been legitimate for months. No amount of email scrutiny reliably catches this.

How to spot it. This one is not caught by looking harder. It is caught by process. Every change to payment details is verified by phoning a number you already hold, never a number supplied in the message, and every change requires a second approver.

Red flag 7: the tone is subtly wrong

What it is. A greeting a colleague never uses, unusual formality, an odd sign-off, or a request that sits slightly outside how that person normally works.

Why it works. It works less well than it used to. Generated text removed the spelling mistakes that once gave attacks away, so "bad English" is no longer a reliable tell.

How to spot it. Pay attention to process anomalies rather than language ones. The finance director who has never emailed you directly in three years is a stronger signal than an unusual comma.

The 30-second verification habit

Seven signals is too many to hold in working memory at speed. Compress them into one trigger and one action:

When an email asks me to click a link, open an attachment, move money, or enter a password, I stop and verify through a channel that did not come from the email.

Everything else is refinement. That single rule catches the overwhelming majority of what matters, and it is short enough that people retain it months later.

What good training looks like

Reading a list is not training. Behaviour changes when people practise under something resembling real conditions:

  1. Establish a baseline. Run a simulation before any training. The number will be higher than leadership expects, and that honest starting point is what makes later improvement meaningful.
  2. Train against real scenarios. Finance teams get payment fraud. Reception gets pretexting. Generic content is ignored by everyone equally.
  3. Retest after thirty days. Retention decays. One test tells you nothing about durability.
  4. Measure reporting, not just clicking. Click rate tells you where to focus training. Report rate tells you whether the programme is actually working. A team that reports quickly is defended; a team that silently avoids clicking is merely lucky.

The most common failure is not weak content. It is running the exercise punitively, so that people quietly stop reporting their own mistakes, which removes the early warning that made the programme worth running.


Every scenario described here exists as a ready-to-send template in the ClickSafe gallery, and the check itself is the subject of Phishing 101, a twelve-minute module.

ShareShare on LinkedIn#phishing#email security#training

Find out what your click rate actually is

We will run a baseline campaign against your own team and show you the real number, not the one you hope for. Most teams are surprised.

20 minutes · Live product · No obligation