Skip to content
Symmetric Metro Internet: equal download and upload up to 10 Gbps
Erbe Bilişim
Cyber Security

How to Spot a Phishing Email: 10 Warning Signs

Learn to spot phishing emails using 10 warning signs, recognize spear phishing and CEO fraud, and report suspicious messages before they spread.

  • Erbe Bilişim Uzman Ekibi
  • 6 min read
Cyber Security category cover — a shield icon on a dark navy background

It is late on a Friday. A short note lands in your finance officer's inbox, apparently from the managing director: an urgent supplier payment must go to a new IBAN today. The tone is formal and the signature familiar, but the sender address is a spoof, off by a single letter. One click and a large sum leaves for the wrong account. Phishing aims at exactly this moment: the tired, rushed employee who trusts the sender. This guide shows how to recognize it before it costs you.

What Phishing Is, and Why It Works

Phishing is when an attacker impersonates a trusted organization or person to make you act against your interest, usually to steal a password, card details, or a money transfer. Email is the main channel, though SMS (smishing) and voice calls (vishing) are rising. It exploits human psychology more than a technical flaw, triggering urgency, fear, authority, and curiosity, so even a current firewall cannot stop a deliberate click.

The stakes are high: one successful email is the entry to a much larger incident, since a stolen password can become ransomware or a months-long breach. Businesses building email defense end to end can start with our security systems solutions, which combine the email gateway, link filtering, and endpoint protection. Phishing is usually the first link in the wider chain we cover in our guide to social engineering attacks.

10 Warning Signs in a Phishing Email

Fake-email signs usually appear together. One should raise suspicion; several at once are a strong alarm. Use these ten as a quick checklist:

  1. Spoofed sender address: the domain is off by one letter, like "@bankka.com" for "@banka.com".
  2. Generic greeting: "Dear Customer" or "Valued User" instead of your name.
  3. Urgency and threats: a deadline like "Your account closes in 24 hours."
  4. Unexpected attachment: an unrequested invoice, receipt, or macro-enabled Office file.
  5. Misleading links: the visible text does not match the real address on hover.
  6. Spelling and grammar errors: clumsy translation, odd phrasing, and typos.
  7. Requests for information: a password, card number, or ID is never requested by email.
  8. Fake security alerts: panic messages like "Suspicious sign-in detected, verify now."
  9. Distorted branding: a familiar logo looks slightly off, or the domain is fake.
  10. Out-of-context timing: an unexpected topic at an odd hour from an unrelated department.

One rule never fits a checklist: your instinct. If an email feels wrong, it usually is, yet time pressure silences it.

How to Verify Links Without Clicking

To reveal a link's destination, hover and wait, or press and hold on mobile. A domain reads right to left, so "bank.secure-login.com" belongs to "secure-login.com", not "bank". For a suspicious request, type the address yourself instead of clicking.

Spear Phishing and CEO Fraud

Classic phishing is blasted to large groups; spear phishing is crafted for one person or department. The attacker studies social media, the company website, and leaked data, then builds a message around the victim's name, title, and a real project. Typos are rare and the signs far subtler.

CEO fraud, or BEC (Business Email Compromise), is the costliest form. Posing as a senior executive, the attacker sends finance an urgent transfer instruction, timed for a holiday eve or a trip, and discourages phone confirmation. It carries no attachment or link, so classic filters miss the pure-text message.

The most effective control is second-channel verification: every payment above a set amount confirmed by phone or in person, as a standard rule, not a sign of distrust. Layering access with the methods in our guide to multi-factor authentication (MFA) ensures a stolen password is not enough alone.

Reporting a Suspicious Email

Deleting a suspicious email quietly is the worst reaction; the same pattern can hit hundreds of colleagues. Define a clear reporting flow instead:

  1. Do not click or reply: no attachments, links, or responses.
  2. Report it: forward the email to your security address or IT team.
  3. The team investigates: an analyst reviews the headers and infrastructure and hunts for other samples.
  4. Blocking is applied: the malicious domain and sender are blocked at the gateway for everyone.
  5. Official notification: a widespread campaign is reported to the national cyber-incident channel.

In our 24/7 monitoring, one reported email often surfaces dozens of look-alike attacks early. In one customer environment, our deployment logged 262 attack attempts in 24 hours from 104 different IPs; peaking at 16 attempts per second, all records stayed local with 0 cloud transfer. Our Managed SOC / MDR service weighs email threats alongside network and endpoint events.

Turkish regulatory context: foreign companies operating in Turkey can report widespread phishing campaigns to USOM, the national cyber-incident center, at usom.gov.tr. Keeping logs on local infrastructure also supports the record-keeping obligations that apply to organizations based in Turkey.

SPF, DKIM, and DMARC Email Authentication

Warning signs are the human side; the technical side is three records that verify sender identity and cut spoofed mail in your name:

RecordWhat it doesQuestion it answers
SPFLists which servers may send for your domain"Is this server authorized?"
DKIMAdds a signature proving the message was not altered"Was the content tampered with?"
DMARCSets what to do when SPF or DKIM fails"Reject or quarantine the fake?"

SPF (Sender Policy Framework) lists authorized sending servers, DKIM (DomainKeys Identified Mail) verifies integrity with a digital signature, and DMARC (Domain-based Message Authentication) decides what happens when the first two fail: monitor, quarantine, or reject. Only all three together protect fully. For staged tightening of the DMARC policy, Microsoft's email authentication documentation is a reliable reference. Records left in "monitor" mode expose fakes but cannot block them.

Conclusion

Phishing targets human behavior more than technology, so its defense is two-layered: employees who recognize the ten warning signs, and correctly configured SPF, DKIM, and DMARC records. Address both and the organization resists a bad click and domain spoofing alike. To plan email security end to end and close weak links, explore our security systems solutions and talk to Erbe Bilişim about a tailored review.

Frequently Asked Questions

I accidentally clicked a link in a phishing email, what should I do?

Do not panic; a click alone often causes no harm. If you entered no data, close the page. If you entered a password or card details, change it from a different device, enable multi-factor authentication, and report it to your IT team. Call your bank if you shared card details.

What is the difference between phishing and spear phishing?

Classic phishing sends one generic message to large groups, relying on volume. Spear phishing is crafted for a single person, using their name, title, and a real project. It is far more convincing, contains no typos, and often slips past classic filters, so second-channel verification matters.

Which technical measures reduce phishing in corporate email?

The base layer is correct SPF, DKIM, and DMARC records, with the DMARC policy raised gradually to "reject." Add an email gateway that scans malicious links, multi-factor authentication on critical accounts, and regular awareness training. Together, controls and training drop the phishing success rate noticeably.

Tags

  • phishing
  • email security
  • spear phishing