2. Spotting phishing emails
When phishing looks professional
A generation of security advice taught people to look for bad spelling, clumsy grammar, and blurry logos. That advice has aged badly, and relying on it now will get you caught.
The polished phish
Modern phishing kits reproduce the exact branding of Microsoft 365, banks, delivery firms, and HR platforms, pixel for pixel. Attackers copy the genuine email template and change only the link. AI writing tools have removed the language barrier that once made foreign-run campaigns easy to spot, so fluent, well-structured, error-free English is now the norm in serious attacks, not the exception.
Some campaigns go further still. Attackers can send phishing from genuinely compromised accounts at real companies, insert themselves into existing email threads, and even reference real conversations. The email is authentic in every technical sense. Only the intent is malicious.
Branded does not mean safe
A perfect Microsoft logo proves only that someone can copy an image. Familiar branding is precisely what attackers rely on: you have seen a thousand real notification emails, so the thousand-and-first gets processed on autopilot. Slow down exactly when an email asks you to do something with your account, your credentials, or money, no matter how legitimate it looks.
So what actually works
Since appearance can be faked, judge messages on things that are harder to fake:
- The request itself. Is it normal for this sender to ask this, in this way, through this channel?
- The destination. Where does the link really go, checked safely as covered earlier?
- Independent verification. Can you confirm the request by going direct to the website, the app, or the person through a channel you already trust?
Notice that none of these depends on how the email looks. That is the point. Presentation is fully under the attacker's control, but they cannot control what the real organisation's website says when you visit it yourself, and they cannot answer your colleague's actual phone.
A useful mindset: assume any email could be dressed up perfectly, and let requests earn trust through verification rather than appearance. It sounds cynical, but it takes seconds in practice, and it is the single most reliable habit this course can give you.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting