How to identify a phishing email before falling for the scam
Phishing is when someone pretends to be a trusted company or person (bank, postal service, tax authority, supplier) by email to trick you into clicking a malicious link or providing sensitive data, like a password or card number.
The most common warning signs
- Exaggerated urgency: "your account will be blocked in 24h", "click now or lose the benefit"
- Sender with a strange domain (e.g. @gmail.com instead of the company's official domain)
- Spelling errors or odd formatting in messages that should be professional
- A link that, when you hover over it (without clicking), shows a completely different address than expected
- A direct request for a password, banking details, or verification code by email
How to check before clicking
Never click directly on the link in a suspicious email. Instead, open the company's official site by typing the address manually in your browser, or call a phone number you already know (not the one in the email) to confirm.
PruPru Digital Security Checklist
Identifying phishing is one of the 10 steps in our free digital security checklist for small businesses.
See the security checklist →