The five signs an email is not from who it says it is
24 July 2026 · 6 min read · Optimum IT Solutions

The advice most people were given about spotting a fake email is now out of date. Bad spelling and dodgy logos have largely gone. What gives these away today is different, and it is worth teaching your team the current version.
The emails that catch businesses out are no longer obvious. They are well written, correctly branded, sent from domains that look right at a glance, and increasingly they arrive inside a genuine conversation that has been going on for weeks. That last one is the shift that matters: when a supplier's mailbox is compromised, the attacker does not need to invent anything. They reply to a real thread with real history.
So the useful signs are not about presentation any more. They are about behaviour: what the message wants you to do, how quickly it wants you to do it, and whether it is trying to move you off the normal way of doing things.
One: the address does not match the name
The display name in an email is just a label. Anyone can set it to anything, including the name of your accountant, your bank or your managing director. The part that is harder to fake is the actual address behind it.
On a phone this is the single most missed check, because most mail apps show only the friendly name. Tap it. Look at the full address. Then look at it properly rather than at a glance, because the trick is usually one character: a domain with an extra letter, a swapped letter that reads the same in passing, or the right company name sitting in the wrong place, such as before an at sign rather than after it.
A genuine internal message from a colleague comes from your own domain. If a message that claims to be from someone in your own business arrives from an outside address, that is not a formatting quirk. That is the answer.
Two: it wants you to break a normal process
Almost every expensive email fraud comes down to this. The message asks you to do something that is within your power but outside your usual procedure, and it gives you a plausible reason why the usual procedure cannot be followed this time.
- A supplier's bank details have changed and this invoice needs paying to the new account.
- A director is in a meeting, cannot take a call, and needs a payment made urgently and quietly.
- Payroll needs your bank details updated through a link because the normal system is down.
- A customer needs an account changed and cannot get through on the phone today.
- Someone senior needs gift cards or vouchers bought at short notice, which is oddly common and still works.
Three: the urgency is doing the work
Pressure is the tool, not the detail. Real urgency in a business normally comes with context you already know about: a job you are aware of, a deadline you agreed, a person you have spoken to this week. Manufactured urgency arrives from nowhere and insists that thinking about it is the problem.
Watch for anything that combines a short deadline with a reason not to check: the sender is travelling, the phone line is down, the office is closed, do not mention it to anyone yet because it is confidential. Those are not the sentences of a colleague in a hurry. They are the sentences of someone removing your ability to verify.
The calmest defence in the world is a small delay. Almost nothing genuine is destroyed by an hour. Almost everything fraudulent is.
Four: the link does not go where it says
Link text is decoration. The actual destination is the thing, and you can see it without clicking: hover over the link on a computer and read the address that appears at the bottom of the window, or press and hold on a phone until the address is shown, then let go without opening it.
Read the address from the right. Find the main domain immediately before the first single slash, because that is where you are really going. Everything before it can be arranged to look reassuring, and often is.
Be especially careful with anything that ends up asking you to sign in. A login page reached through a link in an email is the single most productive trick in use, because the page can be a perfect copy and the only difference is the address bar. If you need to sign in to a service, go there the way you normally do, through your own bookmark or by typing the address, and see whether the message is waiting for you inside.
Five: it does not fit the pattern of the person
This is the one that catches the sophisticated attempts, and it relies on something no software has: knowing the person. People have habits. Your supplier always signs off the same way. Your colleague never sends attachments without a sentence explaining them. Your accountant does not ask for anything on a Sunday evening.
So the signal is a small wrongness. A reply that answers something nobody asked. A thread that has been dormant for months and suddenly resumes with an invoice attached. A tone that is slightly too formal, or slightly too casual, for the person whose name is on it. An attachment you were not expecting, particularly one that asks you to enable anything to view it.
If a message makes you pause for a reason you cannot immediately name, that pause is data. Treat it as a reason to check rather than something to talk yourself out of.
The habit that stops the expensive ones
All five signs collapse into one rule, and it is worth writing into your finance process rather than leaving to instinct: any change to bank details, and any unusual payment request, is verified by voice on a number you already hold. Not the number in the email. Not the number in the signature. A number you had before the message arrived.
It costs a minute and it defeats the entire category, including the versions where the sender's account really has been compromised and every technical check passes. It works because it moves the conversation onto a channel the attacker does not control.
Two supporting habits are worth having as well. Make reporting a suspicious message normal and quick, with somewhere obvious to send it, so people flag things instead of quietly deleting them. And make it clear that nobody is ever in trouble for asking. The moment staff fear looking foolish is the moment they stop checking, and that fear costs businesses far more than the occasional false alarm.
If someone has already clicked
Speed matters more than blame. Change the password for the affected account and sign the account out everywhere, not just on the one device. Check the mailbox for forwarding rules the person did not create, because a rule quietly copying every message to an outside address is a standard next step for an attacker and it is easy to miss.
If a payment has gone, tell the bank immediately rather than after an internal discussion. If customer data may be involved, get advice quickly, because reporting obligations in the UK have short clocks on them.
Then, when the immediate part is done, treat it as information rather than an embarrassment. One person clicking usually means the email was good, which means others would have clicked too. That is the argument for training the team rather than having a word with an individual, and it is why running safe simulated phishing against your own staff tends to change behaviour more than any policy document does.
Related
Want a straight answer on this?
Tell us the job that is costing you the most time. We will look at it and tell you honestly what, if anything, is worth doing about it. The first conversation is free.
Get a quote
