A phishing email impersonates a trusted person or organisation to trick you into handing over a password, payment or file. You can spot one by a display name that doesn't match the sender address, replies routed elsewhere, links whose text differs from their destination, and pressure to act fast. When two signs appear together, verify through an independent channel first.
No single sign is proof on its own. At the organisational level, the check should not rest on staff attention alone: the email platform should ask the same questions of every message automatically.
Why phishing is harder to recognise today
A few years ago, phishing emails gave themselves away with clumsy grammar, the wrong logo and a subject line like "Your account will be closed". Today's version is usually well written, uses the vocabulary of your sector and may even carry the signature block of a supplier you know. Keeping your own signatures standard makes an imitation easier for staff to notice; see corporate email signature management. Attackers study your website and social media to learn who does what, then send invoices to accounts, CVs to HR and quotes to purchasing.
Generative AI is a large part of that shift. ENISA's Threat Landscape 2025 cites reports that over 80% of phishing emails identified between September 2024 and February 2025 used AI to some extent. "Bad spelling means it's fake" is no longer a reliable rule.
Most emails are read and decided on within seconds, and phishing is built for exactly that habit.
What an unnoticed phishing email costs
Phishing remains the most common starting point for cyber attacks. Dismissing it as "someone clicked the wrong link" misses where the damage builds up: a stolen password opens the mailbox, and the mailbox opens customer correspondence, invoices and the password-reset links for every other system.
According to ENISA's Threat Landscape 2025, phishing (including vishing, malspam and malvertising) was the leading initial intrusion vector in the incidents analysed in Europe, at about 60%.
- The FBI IC3 2025 Internet Crime Report shows that phishing/spoofing was the most-reported crime type in the US in 2025, with 191,561 complaints.
- The UK government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses experienced a cyber breach or attack in the previous 12 months, with phishing by far the most common type (38% of businesses).
Türkiye is no exception. According to the Ministry of Transport and Infrastructure's January 2025 announcement, USOM, the national computer emergency response team, blocked 991 phishing domains and prevented 5,869 phishing attacks in that month alone. For companies operating in Türkiye there is also a legal angle: if a compromised mailbox holds personal data, the breach-notification duty under KVKK (Law No. 6698 on the Protection of Personal Data, Türkiye's equivalent of GDPR) may apply, so phishing belongs in your data protection compliance planning as well as your IT plan.
How to spot phishing emails: 9 warning signs
Use these as a checklist. None of them means "definitely fake" on its own, but two together are a reason to stop and verify.
- The display name and the real address don't match. A message showing "John Smith – Managing Director" but sent from a free webmail account or an unfamiliar domain deserves suspicion. Mobile apps often show only the display name, so open the full address.
- The domain looks familiar but is one character off.
company.combecomescornpany.com,company-uk.comor a version written with Cyrillic letters that look identical. We explain this technique in detail in our article on lookalike domain attacks. - Replies go to a different address. The message appears to come from the right sender, but when you press "Reply" a different address appears in the To field. The conversation is being diverted to the attacker.
- The link text and the destination differ. Hover over "View invoice" (or long-press on mobile). If the real address is not the domain you expect, don't click.
- An unexpected attachment, especially a risky type. Password-protected archives, office documents asking you to enable macros, or double extensions such as "invoice.pdf.exe". An unexpected attachment needs checking even from a familiar sender. The accounts-specific signs of invoice-themed mail are in our fake invoice email scams checklist.
- Pressure of urgency and secrecy. "By 3 pm today", "Keep this between us, I'm in a meeting". These phrases are designed to make you skip the check.
- A request outside the normal routine. Passwords, verification codes, gift cards, changes to bank details, or payments that bypass the usual approval. We cover the last case in our guide to bank detail change email fraud.
- Brand impersonation. Emails styled as a courier, bank, government portal or cloud service, with the right logo but a login page on a different domain.
- Failed authentication results. A failed SPF, DKIM or DMARC check in the message headers is a strong warning. The reverse is not a guarantee: an attacker writing from their own domain passes these checks. See SPF, DKIM and DMARC explained.
What to do when a message looks suspicious
| Situation | Do | Don't |
|---|---|---|
| Change of payment or account details | Call the contact on the number you already hold | Call the number in the email |
| Link to a login page | Type the site address yourself | Enter your password via the link |
| Unexpected attachment | Report it to IT | Enable macros |
| Urgent request from a manager | Confirm through another channel | Skip the process because it's "urgent" |
| You realise after clicking | Change the password and tell IT at once | Keep quiet out of embarrassment |
The last row matters most: damage usually grows in the hours after the click, so quick reporting should be rewarded, never punished.
An organisation-level control plan: don't rely on attention alone
Expecting a team that reads hundreds of messages a day to run nine checks on each one is unrealistic. An effective plan spreads the work across five steps:
- Protect your own domain. Configure SPF, DKIM and DMARC correctly and move DMARC in stages to
p=quarantineorp=reject. This makes it much harder to send fake mail in your name. - Assess inbound mail automatically. Besides authentication, software should check every message for lookalike domains, display-name impersonation, Reply-To mismatches and inconsistent links.
- Tie critical actions to a process. Payments, bank-detail changes and official replies sent on behalf of the organisation should need a second approval and leave a record. We show how to build this into email in the email approval workflow article.
- Protect accounts. A sound password policy, visibility of active sessions, and the ability to end a suspicious session remotely. More on the password side in business password security.
- Train briefly and often. Short, frequent sessions with real examples work better than one long annual presentation, and everyone should know how to report.
Test the plan against the scenarios of your own sector. In a freight business the attacker poses as an agent and tries to change a freight payment or a delivery instruction; we walk through that flow in logistics email fraud. For firms that bid for contracts, the target is the last-day "specification changed" email or the bid file itself; the controls are in our tender email security guide.
How we approach phishing at Digital Bridge
Within our cyber security consultancy we treat phishing as a process rather than a checklist:
- We map where you stand. We review the SPF, DKIM and DMARC records of your domains, how your current email platform assesses inbound mail, and who has access to shared addresses.
- We identify the risky workflows. With the teams phishing targets most (finance, purchasing and HR), we walk through how payment and information requests are handled today.
- We deliver practical awareness training. Using examples from your own sector, we cover the nine signs above and the reporting steps.
- We put the technical layer in place. Where needed, we move your business email to a platform that evaluates phishing signals on every message, planning the switch through our cloud migration and infrastructure consultancy. Our guide on how to choose business email sets out what to look for.
The aim is to make staff attention the second line of defence and hand the first line to software. For the basic controls beyond email, the SME cyber security checklist is a good starting point; every type of email fraud we cover is gathered in our Business Email & Documents guide.
How SmartMail evaluates phishing signals
SmartMail, the business email product in our own Smart360 family, runs most of the checks listed above on every inbound message, automatically. Each message is assessed against 12 signals: its own SPF/DKIM/DMARC and PTR verification, lookalike domains and international characters, display-name and brand impersonation, Reply-To and link mismatches, risky attachments, content assessment and comparison with known fraud techniques.
A concrete scenario: your accounts team receives a message with the display name "Managing Director", sent from a domain one letter away from yours, with replies routed to a third address. SmartMail does not just score it; it shows the result as a written report with the reasons: the display name impersonates an executive, the domain imitates yours, the Reply-To differs. If the message falls below the trust threshold your organisation sets, it is quarantined. The default threshold is 70, and before you change it SmartMail shows how many messages the change would affect. Who reviews and releases quarantined mail is set out in our email quarantine policy guide.
A few more details make a practical difference:
- Remote image protection: images inside a message are not loaded until you allow them, so tracking pixels cannot tell the sender you opened it.
- Core checks independent of AI: authentication and domain checks are run by software and keep working even if the AI usage allowance runs out.
- Account security: Smart360 Security uses human verification on sign-in screens, stopping password-guessing attacks before they reach the server. Sessions are listed with device details and can be ended remotely; changing a password closes every session.
- An audit trail in shared mailboxes: every message carries an activity log, and team notes and "flag for attention" let you point a colleague to a suspicious email.
Next step
The quickest win against phishing is to review your domain's authentication records together with the workflows of the teams attackers target most. You can book a short assessment with our cyber security team, explore SmartMail's security analysis on the Smart360 page, or contact us for a live demonstration using your own domain.