Skip to main content
New: free AI Readiness Assessment, see where your business stands
bdManagedIT
All articles

Cybersecurity

Phishing Email Examples: 7 Red Flags Before You Click

Modern phishing emails often look polished and arrive in a familiar workflow. Learn the seven warning signs that matter, see five common business examples, and know exactly what to do next.

By Wil Gibson August 21, 2026 9 min read
Phishing Email Examples: 7 Red Flags Before You Click

A phishing email is an unexpected message designed to make you click, open, reply, pay, or sign in before you stop to verify the request. The modern versions are often polished. They may use a real logo, copy a genuine Microsoft notification, or continue an existing invoice conversation after an attacker compromises one mailbox. The strongest warning is no longer bad spelling. It is a request that changes the normal process: a new bank account, an urgent password reset, a document you were not expecting, or a manager asking for secrecy. When the request involves money, credentials, or sensitive data, verify it through a separate channel before doing anything inside the message.

What are the seven red flags of a phishing email?

The seven signals that matter are an unexpected request, artificial urgency, a sender address that does not match the person or company, a link that points somewhere different from its label, an attachment you were not expecting, a request for credentials or payment, and pressure to bypass a normal approval step. One signal alone may have an innocent explanation. Two or three together are enough to stop. A well-written message can still be malicious, and a poorly written message can still be legitimate, so grammar should never be the main test.

The Federal Trade Commission recommends contacting the company through a phone number or website you already know instead of using the details inside the message.

Example 1: the Microsoft 365 password-expiry email

The message says your password expires today, your mailbox is over quota, or unusual activity requires immediate verification. The button leads to a page that looks like Microsoft sign-in. The giveaway is the destination: the link is not on a Microsoft domain, or it passes through an unfamiliar file-sharing or form service first. Another clue is timing. Microsoft 365 does not normally ask an employee to confirm a password through an unsolicited email. Open a fresh browser window, go to the Microsoft 365 portal yourself, and check the account there. Never use the button as your route to the truth.

Example 2: changed bank details on a real invoice

This version is dangerous because the invoice, supplier name, and conversation may all be real. An attacker who controls a vendor mailbox waits for an active payment thread, then replies with revised banking details or a reason the payment must move today. Nothing looks obviously fake. The control is procedural: any change to payment instructions requires a call to a known number already held in your records and a second-person approval. Do not call the number in the email, and do not accept a reply in the same thread as verification. If the mailbox is compromised, the attacker is reading that reply too.

Example 3: the shared document or voicemail notification

The subject says someone shared a document, sent a secure file, left a voicemail, or invited you to review a proposal. The message may copy the design of SharePoint, OneDrive, DocuSign, or a phone system. The link eventually asks for a Microsoft 365 password. Ask one question before opening it: were you expecting this item from this person? If yes, message the sender through Teams or call them using a known number. If no, report it. A real business workflow can survive a thirty-second verification; an attack depends on preventing one.

Example 4: the executive gift-card or wire request

A message appears to come from an owner or director who is in a meeting and needs a private favor. It asks for gift cards, a wire, a payroll change, or a list of employee tax details. The tone may be casual because the attacker has copied language from public posts or previous email. The pressure to keep the request quiet is the clearest signal. Seniority should increase the verification requirement, not remove it. Call the person on a number you already have, and require the normal finance approval even when the message says the request is urgent.

Example 5: the fake security alert or MFA reset

The message warns that your account was breached, your multi-factor authentication is about to be disabled, or a sign-in needs approval. It may be paired with a real flood of MFA prompts or a phone call from someone claiming to be IT support. The attacker wants you to approve a prompt, reveal a one-time code, or register a new authentication method. Legitimate support should never ask for your password or an MFA code. If you did not start the sign-in, deny it, report it, and contact your actual support team using the route you normally use.

How can you check a suspicious email safely?

Start outside the message. Check the full sender address, not just the display name. On a desktop, hover over links without clicking and read the destination. Confirm that the domain belongs to the organization and is spelled exactly right. Ask whether the request fits the sender, the timing, and your normal process. Then verify through a known channel: a saved phone number, an existing Teams conversation, or a website you type yourself. Do not forward the suspicious message to a colleague with the live link intact. Use your report-phishing button or send it to the security team as an attachment so the headers are preserved.

CISA advises people to recognize, report, and delete suspicious messages rather than using a link, attachment, or phone number supplied by the sender.

What should you do after someone clicks?

Report it immediately, even if nothing obvious happened. Fast reporting gives the security team a chance to revoke sessions, reset credentials, remove mailbox rules, isolate a device, block the sender, and search for the same message across the company. If a password was entered, change it from a known-clean device and revoke active sessions; a password change alone may not remove an attacker who already holds a session token. If money or bank details were involved, call the bank and the affected vendor immediately. Do not spend the first hour deciding who is at fault. Preserve the message and act.

Why email security and employee training need each other

Email filtering blocks known malicious senders, attachments, impersonation patterns, and unsafe links before they reach an inbox. Training covers the messages that contain no detectable payload: a plain-text payment request, a convincing reply from a compromised account, or a phone call that follows the email. The two controls are not substitutes. Good filtering reduces the number of decisions employees must make, and good training makes the remaining decisions safer. The reporting button connects them by turning one employee warning into protection for everyone else.

See how managed email security filters threats before they reach your team.

Build the human layer with managed security awareness training.

Check your current controls with the cybersecurity self-assessment.

Frequently asked questions

What are common signs of a phishing email?
An unexpected request, urgency, a mismatched sender address, an unfamiliar link, an unplanned attachment, a request for credentials or money, and pressure to bypass normal approval steps are the strongest signs.
What are the seven red flags of phishing?
Unexpected contact, urgency, sender mismatch, suspicious link destination, unexpected attachment, a sensitive request, and an attempt to bypass the normal process. Several signs together should stop the action.
What happens if you open a phishing email?
Simply reading most messages does not compromise an account. The risk increases when you click a link, open an attachment, enter credentials, approve an MFA prompt, reply with information, or send money.
What should I do if I clicked a phishing link?
Report it immediately. If you entered a password, change it from a clean device and have IT revoke active sessions. If you opened an attachment, disconnect the device from the network and contact support.
Can a phishing email come from a real address?
Yes. Attackers often compromise a real supplier or employee mailbox and reply inside genuine conversations. That is why payment and credential requests need verification outside the email thread.
How should employees report phishing?
Use the organization report-phishing button or send the message to the security team as an attachment so the original headers are preserved. Do not forward a live malicious link around the business.

Want a straight answer for your business?

Book a first appointment with a bdManagedIT strategist. No sales script, no obligation.

Book your first appointment