Tech Tips · September 15, 2026

How to spot a phishing email in 30 seconds

Most cyberattacks on small businesses start with one convincing email. These quick checks will catch the vast majority of them.

Phishing emails pretend to be from someone you trust — your bank, Microsoft, Canada Post, a supplier, even your own boss — to get you to click a link, open an attachment or send money. They are the most common way small businesses get hacked.

The 30-second check

  • Look at the real sender address, not just the display name. "Microsoft Support" sending from a random Gmail address is a red flag.
  • Hover over links before clicking. If the address that appears doesn't match the company's real website, don't click.
  • Watch for urgency. "Your account will be closed today", "Payment overdue", "Final notice" — pressure is the scammer's main tool.
  • Be suspicious of unexpected attachments, especially invoices, shipping notices or "scanned documents" you weren't expecting.
  • Never change payment details by email alone. If a supplier says their bank account changed, call them on a number you already have.

What to do if you clicked

Don't panic, and don't ignore it. Change the password for the account involved right away, turn on multi-factor authentication if it isn't already, and contact us. The sooner we look, the less damage is possible.

Protecting your whole team

Good email filtering, multi-factor authentication and short, regular staff training stop most phishing before it becomes a problem. We set all three up for businesses across Huron County.

Book a Free IT Checkup Ask a Question